Aggregator
Ransomware rakes in record-breaking $450 million in first half of 2024
1 year 7 months ago
error code: 1106
CVE-2024-35538 | Typecho 1.3.0 Handler X-Forwarded-For unknown vulnerability
1 year 7 months ago
A vulnerability was found in Typecho 1.3.0. It has been rated as problematic. This issue affects some unknown processing of the component Handler Handler. The manipulation of the argument X-Forwarded-For leads to an unknown weakness.
The identification of this vulnerability is CVE-2024-35538. The attack may be initiated remotely. There is no exploit available.
vuldb.com
IBM security advisory (AV24-466)
1 year 7 months ago
Canadian Centre for Cyber Security
Microsoft Will Require MFA for Azure Services
1 year 7 months ago
Multifactor authentication enforcement for Azure portal, Microsoft Entrata admin center, and Intune admin center will begin October.
The 4 Components of Top AI Model Ecosystems
1 year 7 months ago
Table of ContentsThe ModelPost-trainingInternal toolingAgentsSummary I have been thinking a lot abou
CVE-2024-42813 | TRENDnet TEW-752DRU 1.03B01 gena.cgi service buffer overflow
1 year 7 months ago
A vulnerability was found in TRENDnet TEW-752DRU 1.03B01. It has been declared as critical. This vulnerability affects unknown code of the file gena.cgi. The manipulation of the argument service leads to buffer overflow.
This vulnerability was named CVE-2024-42813. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Ransomware rakes in record-breaking $450 million in first half of 2024
1 year 7 months ago
Ransomware victims have paid $459,800,000 to cybercriminals in the first half of 2024, setting the stage for a new record this year if ransom payments continue at this level. [...]
Bill Toulas
Crypto enthusiasts flood npm with more than 281,000 bogus packages overnight
1 year 7 months ago
Crypto enthusiasts have lately been flooding software registries like npm and PyPI with thousan
Crypto enthusiasts flood npm with more than 281,000 bogus packages overnight
1 year 7 months ago
Crypto enthusiasts have lately been flooding software registries like npm and PyPI with thousands of bogus packages that add no functional value and instead put a strain on the entire open source ecosystem.
A single instance, recorded by Sonatype in July 2024, saw 281,512 distinct packages appearing on the npmjs.com registry overnight — each package named a gibberish Latin phrase akin to Lorem Ipsum.
The post Crypto enthusiasts flood npm with more than 281,000 bogus packages overnight appeared first on Security Boulevard.
Ax Sharma
test
1 year 7 months ago
New AI technologies are advancing cyberattacks and wreaking havoc on traditional identity verificat
CVE-2024-5576 | Tutor LMS Elementor Addons Plugin up to 2.1.4 on WordPress Course Carousel Widget cross site scripting
1 year 7 months ago
A vulnerability was found in Tutor LMS Elementor Addons Plugin up to 2.1.4 on WordPress. It has been classified as problematic. This affects an unknown part of the component Course Carousel Widget. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-5576. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-43317 | Metagauss User Registration Team RegistrationMagic Plugin up to 6.0.1.0 on WordPress cross site scripting
1 year 7 months ago
A vulnerability was found in Metagauss User Registration Team RegistrationMagic Plugin up to 6.0.1.0 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-43317. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-43311 | Geek Code Lab Login As Users Plugin up to 1.4.2 on WordPress privileges management
1 year 7 months ago
A vulnerability has been found in Geek Code Lab Login As Users Plugin up to 1.4.2 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper privilege management.
This vulnerability is known as CVE-2024-43311. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-43354 | myCred Plugin up to 2.7.2 on WordPress deserialization
1 year 7 months ago
A vulnerability, which was classified as critical, was found in myCred Plugin up to 2.7.2 on WordPress. Affected is an unknown function. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2024-43354. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-43326 | Jamie Bergen Plugin Notes Plus Plugin up to 1.2.7 on WordPress authorization
1 year 7 months ago
A vulnerability, which was classified as problematic, has been found in Jamie Bergen Plugin Notes Plus Plugin up to 1.2.7 on WordPress. This issue affects some unknown processing. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2024-43326. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-23729 | ColorOS Internet Browser 45.10.3.4.1 on Android com.android.browser.RealBrowserActivity cross site scripting
1 year 7 months ago
A vulnerability classified as problematic was found in ColorOS Internet Browser 45.10.3.4.1 on Android. This vulnerability affects unknown code of the component com.android.browser.RealBrowserActivity. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-23729. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-42812 | D-Link DIR-860L 2.03 gena.cgi SID buffer overflow
1 year 7 months ago
A vulnerability classified as critical has been found in D-Link DIR-860L 2.03. This affects an unknown part of the file gena.cgi. The manipulation of the argument SID leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2024-42812. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-43345 | PluginOps Landing Page Builder Plugin up to 1.5.2.0 on WordPress path traversal
1 year 7 months ago
A vulnerability was found in PluginOps Landing Page Builder Plugin up to 1.5.2.0 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2024-43345. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-42815 | TP-LINK RE365 V1_180213 /usr/bin/httpd USER_AGENT buffer overflow
1 year 7 months ago
A vulnerability was found in TP-LINK RE365 V1_180213. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /usr/bin/httpd. The manipulation of the argument USER_AGENT leads to buffer overflow.
This vulnerability is known as CVE-2024-42815. The attack can be launched remotely. There is no exploit available.
vuldb.com