Aggregator
CVE-2022-2603 | Google Chrome up to 103.0.5060.134 Omnibox use after free (Nessus ID 211177)
CVE-2021-42751 | ThingsBoard 3.3.1 Rule Engine description cross site scripting (ID 167999 / EDB-51004)
CVE-2022-2604 | Google Chrome up to 103.0.5060.134 Safe Browsing 10000 use after free (Nessus ID 211177)
CVE-2022-2605 | Google Chrome up to 103.0.5060.134 Dawn out-of-bounds (Nessus ID 211177)
CVE-2022-2606 | Google Chrome up to 103.0.5060.134 Managed Devices API use after free (Nessus ID 211177)
CVE-2022-2607 | Google Chrome up to 103.0.5060.134 Tab Strip use after free (Nessus ID 211177)
CVE-2022-2608 | Google Chrome up to 103.0.5060.134 Overview Mode use after free (Nessus ID 211177)
CVE-2022-2609 | Google Chrome up to 103.0.5060.134 Nearby Share use after free (Nessus ID 211177)
Researchers Exploit OAuth Misconfigurations to Gain Unrestricted Access to Sensitive Data
A security researcher has uncovered a serious vulnerability resulting from incorrectly configured OAuth2 credentials in a startling discovery from a recent YesWeHack bug reward engagement. This discovery, made during an in-depth analysis of a target’s web application, highlights the severe risks posed by seemingly minor oversights in authentication frameworks. By leveraging exposed OAuth client IDs […]
The post Researchers Exploit OAuth Misconfigurations to Gain Unrestricted Access to Sensitive Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
前苏联失败的金星探测器即将坠落回地面
AWS Defaults Open Stealthy Attack Paths Enabling Privilege Escalation and Account Compromise
A recent investigation by security researchers has exposed critical vulnerabilities in the default IAM roles of several Amazon Web Services (AWS) offerings, including SageMaker, Glue, and EMR, as well as open-source projects like Ray. These roles, often automatically created or recommended during service setup, come with overly permissive policies such as AmazonS3FullAccess. This broad access, […]
The post AWS Defaults Open Stealthy Attack Paths Enabling Privilege Escalation and Account Compromise appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2004-1724 | PHP-Fusion 4.0 fusion_admin/db_backups Backup information disclosure (EDB-24384 / Nessus ID 14356)
Skyhigh Security adds data protection solutions for Microsoft Copilot and ChatGPT Enterprise
Skyhigh Security announced the expansion of its Skyhigh AI offering to include additional data protection solutions for Copilot for Microsoft 365 and ChatGPT Enterprise. This development follows the company’s earlier introduction of Skyhigh AI, an advanced suite of AI-powered capabilities designed to mitigate risks associated with AI applications while enhancing security operations, and expansion of data protection capabilities to secure Microsoft Copilot. While the capabilities of AI applications like Microsoft Copilot and ChatGPT are revolutionizing … More →
The post Skyhigh Security adds data protection solutions for Microsoft Copilot and ChatGPT Enterprise appeared first on Help Net Security.
China-Linked Hackers Targeting Organizational Infrastructure and High-Value Clients
A leading U.S.-based cybersecurity firm, sophisticated cyber-espionage campaigns attributed to Chinese state-sponsored actors have come to light. Tracked as the PurpleHaze activity cluster, these adversaries have targeted SentinelOne’s infrastructure alongside high-value organizations associated with its business ecosystem. Uncovering the PurpleHaze Threat Cluster SentinelLabs, the research arm of SentinelOne, identified this threat during a 2024 intrusion […]
The post China-Linked Hackers Targeting Organizational Infrastructure and High-Value Clients appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
PowerDNS DNSdist Vulnerability Let Attackers Cause Denial of Service Condition
A high-severity vulnerability (CVE-2025-30194) in PowerDNS DNSdist, a widely used DNS load balancer and security tool, enables remote attackers to trigger denial-of-service (DoS) conditions by exploiting flaws in its DNS-over-HTTPS (DoH) implementation. The vulnerability, disclosed in PowerDNS Security Advisory, affects DNSdist versions 1.9.0 through 1.9.8 when configured to use the nghttp2 library for DoH processing. […]
The post PowerDNS DNSdist Vulnerability Let Attackers Cause Denial of Service Condition appeared first on Cyber Security News.