Aggregator
Why Hackers Love Weekend and Holiday Attacks (Jeff Wichman)
1 year 5 months ago
About 75% of healthcare sector entities that suffered a ransomware attack over the past year were targeted on a weekend or holiday, highlighting the need for organizations to bolster staffing and related strategies during these vulnerable times, said Jeff Wichman of security firm Semperis.
North Korean Hackers Tied to $1.3B in Stolen Crypto in 2024
1 year 5 months ago
Researchers Trace 61% of Known Losses This Year to Pyongyang-Backed Hackers
Hackers tied to North Korea's cash-strapped totalitarian dictatorship this year stole a record amount of cryptocurrency, totaling $1.34 billion across 47 incidents, or about double their known haul for 2023, reported blockchain analytics firm Chainalysis.
Hackers tied to North Korea's cash-strapped totalitarian dictatorship this year stole a record amount of cryptocurrency, totaling $1.34 billion across 47 incidents, or about double their known haul for 2023, reported blockchain analytics firm Chainalysis.
Turmoil Besets Phishing-as-a-Service Toolkit Rockstar 2FA
1 year 5 months ago
Infrastructure Problems Blamed; Users Appear to Move to Similar FlowerStorm Service
As the end of the year approaches, it's out with the old and in with the new as researchers report that Rockstar 2FA, which once facilitated prolific phishing-as-a-service hits, has crashed and burned, apparently leading many one-time users to move to rival FlowerStorm.
As the end of the year approaches, it's out with the old and in with the new as researchers report that Rockstar 2FA, which once facilitated prolific phishing-as-a-service hits, has crashed and burned, apparently leading many one-time users to move to rival FlowerStorm.
Models Can Strategically Lie, Finds Anthropic Study
1 year 5 months ago
AI Can Fake Alignment to New Instructions to Avoid Retraining
Advanced artificial intelligence models can feign alignment with new training goals while secretly adhering to their original principles, a study shows. Alignment faking isn't likely to cause immediate danger but may pose a challenge as AI systems grow more capable.
Advanced artificial intelligence models can feign alignment with new training goals while secretly adhering to their original principles, a study shows. Alignment faking isn't likely to cause immediate danger but may pose a challenge as AI systems grow more capable.
US Considers TP-Link Ban After Volt Typhoon Hacking Campaign
1 year 5 months ago
Major Chinese Router Manufacturer Facing Increased Scrutiny After Chinese Espionage
U.S. authorities have launched multiple investigations while reportedly considering banning the widely popular Chinese-manufactured TP-Link routers amid ongoing security risks linked to Chinese cyberespionage and hacking campaigns targeting American critical infrastructure sectors.
U.S. authorities have launched multiple investigations while reportedly considering banning the widely popular Chinese-manufactured TP-Link routers amid ongoing security risks linked to Chinese cyberespionage and hacking campaigns targeting American critical infrastructure sectors.
DEF CON 32 – Disenshittify Or Die! How Hackers Can Seize The Means Of Computation
1 year 5 months ago
Authors/Presenters: Cory Doctorow
Our sincere appreciation to DEF CON, and the Authors/Presenters for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel.
The post DEF CON 32 – Disenshittify Or Die! How Hackers Can Seize The Means Of Computation appeared first on Security Boulevard.
Marc Handelman
Adobe warns of critical ColdFusion bug with PoC exploit code
1 year 5 months ago
Adobe has released out-of-band security updates to address a critical ColdFusion vulnerability with proof-of-concept exploit code. [...]
Sergiu Gatlan
CVE-2013-5918 | Platinum SEO plugin up to 1.2.8 platinum_seo_pack.php cross site scripting (ID 12754 / XFDB-87525)
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in Platinum SEO plugin up to 1.2.8. This affects an unknown part of the file platinum_seo_pack.php. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2013-5918. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-5952 | Codologic Com Freichat up to 9.4 toname cross site scripting (ID 125737 / ID 12893)
1 year 5 months ago
A vulnerability classified as problematic was found in Codologic Com Freichat up to 9.4. Affected by this vulnerability is an unknown functionality. The manipulation of the argument toname leads to cross site scripting.
This vulnerability is known as CVE-2013-5952. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2013-5951 | eXtplorer 2.1.3 application.js.php cross site scripting (Nessus ID 73139 / ID 12886)
1 year 5 months ago
A vulnerability was found in eXtplorer 2.1.3 and classified as problematic. Affected by this issue is some unknown functionality of the file application.js.php. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2013-5951. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2013-5961 | Danny Morris Lazy SEO 1.1.9 File Upload lazyseo.php Remote Code Execution (Exploit 123349 / EDB-28452)
1 year 5 months ago
A vulnerability, which was classified as critical, has been found in Danny Morris Lazy SEO 1.1.9. Affected by this issue is some unknown functionality of the file lazyseo.php of the component File Upload. The manipulation leads to Remote Code Execution.
This vulnerability is handled as CVE-2013-5961. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2013-5977 | Cart66 Cart66 Lite plugin up to 1.5.0.0 Cart66Product.php cross-site request forgery (Bug 123587 / EDB-28959)
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in Cart66 Cart66 Lite plugin up to 1.5.0.0. This affects an unknown part of the file Cart66Product.php. The manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2013-5977. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-5972 | VMware Workstation/Player 5.0.3/9.0.2 Shared Libraries access control (Nessus ID 71054 / ID 121587)
1 year 5 months ago
A vulnerability was found in VMware Workstation and Player 5.0.3/9.0.2. It has been classified as critical. Affected is an unknown function of the component Shared Libraries. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2013-5972. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-5999 | Kingsoft KDrive 1.21.0.1878 Certificates cryptographic issues (ID 121618 / SBV-42490)
1 year 5 months ago
A vulnerability classified as critical has been found in Kingsoft KDrive 1.21.0.1878. Affected is an unknown function of the component Certificates. The manipulation leads to cryptographic issues.
This vulnerability is traded as CVE-2013-5999. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-5953 | Codepeople Com Multicalendar up to 4.8.5 paletteDefault cross site scripting (ID 125738 / ID 12887)
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in Codepeople Com Multicalendar up to 4.8.5. Affected by this issue is some unknown functionality. The manipulation of the argument paletteDefault leads to cross site scripting.
This vulnerability is handled as CVE-2013-5953. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2013-5955 | Purplebeanie Com Pbbooking 2.4 manage.php arbitrary cross site scripting (ID 125734 / ID 12885)
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in Purplebeanie Com Pbbooking 2.4. This affects an unknown part of the file manage.php. The manipulation of the argument arbitrary leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2013-5955. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2013-6014 | Juniper Junos up to 13.2 ARP information disclosure (JSA10595 / Nessus ID 70480)
1 year 5 months ago
A vulnerability has been found in Juniper Junos up to 13.2 and classified as critical. Affected by this vulnerability is an unknown functionality of the component ARP Handler. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2013-6014. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-6013 | Juniper Junos up to 12.1x45 memory corruption (JSA10594 / Nessus ID 70479)
1 year 5 months ago
A vulnerability was found in Juniper Junos. It has been declared as very critical. This vulnerability affects unknown code. The manipulation leads to memory corruption.
This vulnerability was named CVE-2013-6013. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Non-Human Identities Gain Momentum, Requires Both Management, Security
1 year 5 months ago
The number of Non-Human Identities (NHIs) in many organizations has exploded. Key trends, drivers, and market landscape in this fast-developing area are explored.
Don Tait