Aggregator
CVE-2024-52429 | Anton Hoelstad WP Quick Setup Plugin up to 2.0 on WordPress unrestricted upload
CVE-2024-52435 | W3 Eden Premium Packages Plugin up to 5.9.3 on WordPress sql injection
CVE-2024-28058 | RSA NetWitness up to 12.5.0 improper authorization
CVE-2024-52427 | Saso Nikolov Event Tickets with Ticket Scanner Plugin up to 2.3.11 on WordPress special elements used in a template engine
CVE-2024-52428 | Ads Pro Scripteo Ads Booster Plugin up to 1.12 on WordPress filename control
CVE-2012-0200 | IBM solidDB up to 6.5.0.8 denial of service (EDB-36869 / Nessus ID 58106)
华盛顿州圣胡安县推行 32 小时工作制一周年
黑客在瑞士发放纸质钓鱼邮件来传播恶意软件
CISA Adds Two Critical Palo Alto Networks Vulnerabilities to Known Exploited Catalog
‘ClickFix’ Cyber-Attacks for Malware Deployment on the Rise
Attackers are exploiting 2 zero-days in Palo Alto Networks firewalls (CVE-2024-0012, CVE-2024-9474)
Palo Alto Networks has released fixes for two vulnerabilities (CVE-2024-0012 and CVE-2024-9474) in its next-generation firewalls that have been exploited by attackers as zero-days. About the vulnerabilities (CVE-2024-0012, CVE-2024-9474) CVE-2024-0012 stems from missing authentication for a critical function and allows unauthenticated attackers with network access to the management web interface “to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474,” according to Palo … More →
The post Attackers are exploiting 2 zero-days in Palo Alto Networks firewalls (CVE-2024-0012, CVE-2024-9474) appeared first on Help Net Security.
CVE-2024-39205 | pyload-ng up to 0.5.0b3.dev85 HTTP Request Privilege Escalation (GHSA-r9pp-r4xf-597r)
CVE-2024-28397 | js2py up to 0.74 API Call js2py.disable_pyimport Privilege Escalation
The Elephant in AppSec Talks Highlight: Reinventing API Security
Highlights from Escape's talks at The Elephant in AppSec Conference on the challenges of API security and how Escape is overcoming these
The post The Elephant in AppSec Talks Highlight: Reinventing API Security appeared first on Security Boulevard.
研究人员曝光利用 Microsoft Visio 文件的两步式网络钓鱼技术
研究发现 X 算法偏爱共和党和马斯克
$25,5 млн снова на базе: как криптоплатформа Thala вернула похищенные средства?
Major security audit of critical FreeBSD components now available
The FreeBSD Foundation, in partnership with the Alpha-Omega Project, has released the results of an extensive security audit of two critical FreeBSD components: the bhyve hypervisor and the Capsicum sandboxing framework. The audit, conducted by the offensive security firm Synacktiv, provides insights into potential vulnerabilities and highlights the importance of proactive security measures in open-source software. The security audit, carried out in June and July 2024, aimed to identify vulnerabilities in these subsystems’ user-mode and … More →
The post Major security audit of critical FreeBSD components now available appeared first on Help Net Security.