Aggregator
ZDI-CAN-26231: Adobe
中电安科|万事俱备,“职”等你来
微软:黑客在设备代码钓鱼攻击中窃取电子邮件
CVE-2017-2460 | Apple iOS up to 10.2 WebKit memory corruption (HT207617 / EDB-41811)
CVE-2008-0298 | Apple Safari 2.0/2.0.1/2.0.2/2.0.3/2.0.4 input validation (EDB-31021 / XFDB-39635)
Microsoft Text Services Framework Exploited for Stealthy Persistence
A novel persistence mechanism exploiting Microsoft’s Text Services Framework (TSF) has been uncovered by researchers at Praetorian Labs, revealing a sophisticated method for maintaining long-term access to compromised systems. While requiring administrative privileges for initial deployment, this technique enables stealthy code execution across dozens of critical Windows processes through aboriginal system components designed for text […]
The post Microsoft Text Services Framework Exploited for Stealthy Persistence appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2014-9464 | Microweber up to 0.94 Category.php parent_id sql injection (EDB-35720)
CVE-2007-1452 | PHP up to 5.2.0 Filters format string (EDB-3452 / Nessus ID 24907)
Balancing cloud security with performance and availability
Your business can’t realize the many benefits of cloud computing without ensuring performance and availability in its cloud environments. Let’s look at some examples. Scalability: To scale your business’s cloud computing services, you need those services to be available and to perform according to your business’s requirements. Otherwise, your business might miss out on opportunities or end up paying for resources it doesn’t use. Disaster recovery: In the event of a disaster, you might need … More →
The post Balancing cloud security with performance and availability appeared first on Help Net Security.
CVE-2024-11427 | maheshmaharjan Catch Popup Plugin up to 1.4.4 on WordPress Shortcode catch-popup cross site scripting
CVE-2024-12461 | zoan WP-Revive Adserver Plugin up to 2.2.1 on WordPress Shortcode wprevive_async cross site scripting
CVE-2024-12258 | shivtiwari WP Service Payment Form With Authorize.net Plugin up to 2.6.3 on WordPress page cross site scripting
CVE-2024-12338 | websitetoolbox Website Toolbox Community Plugin up to 2.0.1 on WordPress websitetoolbox_username cross site scripting
XCSSET信息窃取恶意软件卷土重来,针对macOS用户和开发者
Cybercriminals Exploit Onerror Event in Image Tags to Deploy Payment Skimmers
LibreOffice Vulnerabilities Allow Attackers to Write to Files and Extract Data
Two critical vulnerabilities in LibreOffice (CVE-2024-12425 and CVE-2024-12426) expose millions of users to file system manipulation and sensitive data extraction attacks. These flaws affect both desktop users opening malicious documents and server-side systems using LibreOffice for headless document processing. CVE-2024-12425: Path Traversal Enables Arbitrary File Writes The first vulnerability stems from improper path sanitization when […]
The post LibreOffice Vulnerabilities Allow Attackers to Write to Files and Extract Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.