Aggregator
DrayTek Devices Vulnerability Let Attackers Arbitrary Commands Remotely
The DrayTek Gateway devices, more specifically the Vigor2960 and Vigor300B models, are susceptible to a critical command injection vulnerability. Exploitable via the /cgi-bin/mainfunction.cgi/apmcfgupload endpoint, attackers can inject arbitrary commands into the system by manipulating the session parameter within a crafted HTTP request. The vulnerability impacts over 66,000 internet-connected devices, potentially allowing attackers to gain remote […]
The post DrayTek Devices Vulnerability Let Attackers Arbitrary Commands Remotely appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2013-7057 | Axway SecureTransport 5.1 cross-site request forgery (EDB-35046 / XFDB-98320)
New Stealthy Malware Leveraging SSH Over TOR Attacking Ukrainian Military
Researchers recently discovered a malicious campaign targeting Ukrainian military personnel through fake “Army+” application websites, which host a malicious installer that, upon execution, extracts the legitimate application alongside the Tor browser. The installer includes a PowerShell script that indicates the Tor browser’s inclusion is not for legitimate use, suggesting it’s likely intended for covert communication […]
The post New Stealthy Malware Leveraging SSH Over TOR Attacking Ukrainian Military appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
U.S. Treasury sanctions Russian and Iranian entities for interfering in the presidential election
U.S. Treasury sanctions Russian and Iranian entities for interfering in the presidential election
CVE-2013-6017 | Atmail up to 7.1.6 cross site scripting (VU#204950 / EDB-39015)
How a Malicious Update Brought Crypto Mining to Lottie Player Users
CVE-2020-8605 | Trend Micro InterScan Web Security Virtual Appliance 6.5 os command injection (EDB-48667)
New "DoubleClickjacking" Exploit Bypasses Clickjacking Protections on Major Websites
New "DoubleClickjacking" Exploit Bypasses Clickjacking Protections on Major Websites
CVE-2000-0711 | Netscape Navigator ServerSocket privileges management (EDB-20139 / BID-1545)
CVE-1999-0209 | Sun SunOS up to 4.1.1 Suntools privileges management (EDB-16326 / XFDB-123)
CVE-2009-1839 | Mozilla Firefox up to 3.1 Access Restriction access control (EDB-10544 / Nessus ID 43755)
CVE-2011-0512 | Jikaka Teams Structure module 3.0 team.php team_id sql injection (EDB-16004 / XFDB-64727)
Debugging memory corruption: Who wrote ‘2’ into my stack?!
CVE-2001-0403 | Sun Solaris 2.0 GUI /opt/JSparm/bin/perfmon privileges management (EDB-20715 / XFDB-6267)
CVE-2003-1520 | FuzzyMonkey My Classifieds 2.11 email sql injection (EDB-23269 / BID-8863)
CVE-2011-5103 | Alurian Prismotube Video Script index.php id sql injection (EDB-18156 / XFDB-71481)
Combatting the Security Awareness Training Engagement Gap
Despite years of security awareness training, close to half of businesses say their employees wouldn’t know what to do if they received a phishing email. According to a US government-backed study, one of the main reasons for the lack of impact of cyber security training is “waning engagement and growing indifference.” Why are traditional security […]
The post Combatting the Security Awareness Training Engagement Gap appeared first on CybeReady.
The post Combatting the Security Awareness Training Engagement Gap appeared first on Security Boulevard.