Aggregator
Threat Actors Exploit Government Website Vulnerabilities for Phishing Campaigns
Threat Actors Exploit Government Website Vulnerabilities for Phishing Campaigns
Cofense Intelligence has continually observed the abuse or usage of legitimate domain service exploitation. This report highlights observed phishing threat actor abuse of .gov top-level domains (TLDs) for different countries over two years from November 2022 to November 2024.
The post Threat Actors Exploit Government Website Vulnerabilities for Phishing Campaigns appeared first on Security Boulevard.
Снял номер, но остался за дверью: хакеры взломали популярную систему онлайн-бронирования
JVN: 複数のSchneider Electric製品における複数の脆弱性
CVE-2023-28128 | Ivanti Avalanche FileStoreConfig unrestricted upload (ID 172398)
CVE-2023-28127 | Ivanti Avalanche getLogFile path traversal
CVE-2023-31974 | yasm 1.3.0 /nasm/nasm-pp.c error use after free (Issue 208)
CVE-2023-30083 | libming 0.4.8 swftophp util/decompile.c newVar_N weak iv (Issue 266)
CVE-2023-28316 | Rocket.Chat 2FA session fixiation
CVE-2023-28318 | Rocket.Chat Message improper authorization
CVE-2023-28317 | Rocket.Chat Message Edit improper authorization
CVE-2023-30056 | FICO Origination Manager Decision Module 4.8.1 session fixiation (ID 172192)
CVE-2023-29791 | kodbox up to 1.37 Debug Information cross site scripting
UAC-0063 Expands Cyber Attacks to European Embassies Using Stolen Documents
UAC-0063 Expands Cyber Attacks to European Embassies Using Stolen Documents
Vulnerability in Airline Integration Service enables A Hacker to Gain Entry To User Accounts
A recent security vulnerability in a widely used airline integration service has exposed millions of users to account takeovers, raising concerns over the safety of online travel services. Security researchers from Salt Labs discovered the flaw, which enabled hackers to access user accounts without authorization, potentially compromising sensitive information and airline loyalty points. The Exploit […]
The post Vulnerability in Airline Integration Service enables A Hacker to Gain Entry To User Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.