Aggregator
How Phished Data Turns into Apple & Google Wallets
1 year 4 months ago
Carding -- the underground business of stealing, selling and swiping stolen payment card data -- has long been the dominion of Russia-based hackers. Happily, the broad deployment of more secure chip-based payment cards in the United States has weakened the carding market. But a flurry of innovation from cybercrime groups in China is breathing new life into the carding industry, by turning phished card data into mobile wallets that can be used online and at main street stores.
BrianKrebs
CVE-2025-24928 | xmlsoft libxml2 up to 2.12.9/2.13.5 valid.c xmlSnprintfElements stack-based overflow (Issue 847)
1 year 4 months ago
A vulnerability was found in xmlsoft libxml2 up to 2.12.9/2.13.5. It has been classified as critical. This affects the function xmlSnprintfElements of the file valid.c. The manipulation leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2025-24928. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-56171 | xmlsoft libxml2 up to 2.12.9/2.13.5 /xmlschemas.c xmlSchemaIDCFillNodeTables use after free (Issue 828)
1 year 4 months ago
A vulnerability was found in xmlsoft libxml2 up to 2.12.9/2.13.5 and classified as critical. Affected by this issue is the function xmlSchemaIDCFillNodeTables of the file /xmlschemas.c. The manipulation leads to use after free.
This vulnerability is handled as CVE-2024-56171. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
PCI DSS 4: 6.4.3/11.6.1 – A Guide to SAQ A-EP Compliance using Feroot PaymentGuard AI
1 year 4 months ago
The post PCI DSS 4: 6.4.3/11.6.1 – A Guide to SAQ A-EP Compliance using Feroot PaymentGuard AI appeared first on Feroot Security.
The post PCI DSS 4: 6.4.3/11.6.1 – A Guide to SAQ A-EP Compliance using Feroot PaymentGuard AI appeared first on Security Boulevard.
mykola myroniuk
CVE-2024-50609 | Fluent Bit 3.1.9 opentelemetry_prot.c process_payload_traces_proto_ng null pointer dereference
1 year 4 months ago
A vulnerability has been found in Fluent Bit 3.1.9 and classified as problematic. Affected by this vulnerability is the function process_payload_traces_proto_ng of the file opentelemetry_prot.c. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2024-50609. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-50608 | Fluent Bit 3.1.9 prom_rw_prot.c process_payload_metrics_ng null pointer dereference
1 year 4 months ago
A vulnerability, which was classified as problematic, was found in Fluent Bit 3.1.9. Affected is the function process_payload_metrics_ng of the file prom_rw_prot.c. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2024-50608. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-56882 | Sage DPW 2020_06_002 Kurzinfo cross site scripting
1 year 4 months ago
A vulnerability, which was classified as problematic, has been found in Sage DPW 2020_06_002. This issue affects some unknown processing of the component Kurzinfo. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-56882. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-39327 | Atos Eviden IDRA up to 2.6.0 CA Signing access control
1 year 4 months ago
A vulnerability classified as critical was found in Atos Eviden IDRA up to 2.6.0. This vulnerability affects unknown code of the component CA Signing. The manipulation leads to improper access controls.
This vulnerability was named CVE-2024-39327. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-4028 | Red Hat Keycloak/Single Sign-On 7 Admin Console cross site scripting
1 year 4 months ago
A vulnerability classified as problematic has been found in Red Hat Keycloak and Single Sign-On 7. This affects an unknown part of the component Admin Console. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-4028. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-51505 | Atos Eviden IDRA up to 2.7.0 race condition
1 year 4 months ago
A vulnerability was found in Atos Eviden IDRA up to 2.7.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to race condition.
This vulnerability is handled as CVE-2024-51505. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-26058 | Webkul QloApps 1.6.1 information disclosure
1 year 4 months ago
A vulnerability was found in Webkul QloApps 1.6.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2025-26058. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-55460 | BoardRoom Dividend Distribution Tax Election System 2.0 sql injection
1 year 4 months ago
A vulnerability was found in BoardRoom Dividend Distribution Tax Election System 2.0. It has been classified as critical. Affected is an unknown function. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2024-55460. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-49589 | Palantir com.palantir.artifacts:artifacts authorization
1 year 4 months ago
A vulnerability was found in Palantir com.palantir.artifacts:artifacts and classified as problematic. This issue affects some unknown processing. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2024-49589. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-39328 | Atos Eviden IDRA/Eviden IDCA up to 2.6.x Configuration permission
1 year 4 months ago
A vulnerability has been found in Atos Eviden IDRA and Eviden IDCA up to 2.6.x and classified as problematic. This vulnerability affects unknown code of the component Configuration Handler. The manipulation leads to permission issues.
This vulnerability was named CVE-2024-39328. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-26620 | DuendeSoftware foss up to 3.1.x HttpContext.GetClientAccessTokenAsync toctou
1 year 4 months ago
A vulnerability, which was classified as problematic, was found in DuendeSoftware foss up to 3.1.x. This affects the function HttpContext.GetClientAccessTokenAsync. The manipulation leads to time-of-check time-of-use.
This vulnerability is uniquely identified as CVE-2025-26620. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-56883 | Sage DPW 2020_06_002 User Interface id access control
1 year 4 months ago
A vulnerability, which was classified as critical, has been found in Sage DPW 2020_06_002. Affected by this issue is some unknown functionality of the component User Interface. The manipulation of the argument id leads to improper access controls.
This vulnerability is handled as CVE-2024-56883. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-25300 | ain smartbanner.js up to 1.14.0 cross site scripting
1 year 4 months ago
A vulnerability classified as problematic was found in ain smartbanner.js up to 1.14.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-25300. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Chinese hackers abuse Microsoft APP-v tool to evade antivirus
1 year 4 months ago
The Chinese APT hacking group "Mustang Panda" has been spotted abusing the Microsoft Application Virtualization Injector utility as a LOLBIN to inject malicious payloads into legitimate processes to evade detection by antivirus software. [...]
Bill Toulas
Randall Munroe’s XKCD ‘Hardwood’
1 year 4 months ago
via the comic humor & dry wit of Randall Munroe, creator of XKCD
The post Randall Munroe’s XKCD ‘Hardwood’ appeared first on Security Boulevard.
Marc Handelman