Aggregator
AI Rise: Can We Still Trust What We See?
1 year 5 months ago
AI-Powered Social Engineering and Deepfake Threats in 2025
Security researchers predict threat actors will use artificial intelligence and large language models to enhance phishing attacks and create convincing fake personas, while defensive AI enters a new phase of semiautonomous operations.
Security researchers predict threat actors will use artificial intelligence and large language models to enhance phishing attacks and create convincing fake personas, while defensive AI enters a new phase of semiautonomous operations.
Still-Lucrative Ransomware's Profits Plunged 35% Last Year
1 year 5 months ago
Collapse of LockBit and BlackCat/ALPHV Tied to Ongoing Decline in Big-Game Hunting
Ransomware may still be raking in massive cryptocurrency profits for practitioners, but 2024 turned out to be less of a banner year than predicted, with blockchain researchers reporting that the sum total of known ransom payments to ransomware groups in 2024 plummeted by 35%.
Ransomware may still be raking in massive cryptocurrency profits for practitioners, but 2024 turned out to be less of a banner year than predicted, with blockchain researchers reporting that the sum total of known ransom payments to ransomware groups in 2024 plummeted by 35%.
Cryptohack Roundup: Critical Ethereum Vulnerability
1 year 5 months ago
Also: Conviction in £1.5M Fraud, Sentencing in Torture and Theft Case
This week's stories include a critical Ethereum vulnerability, conviction in a £1.5M fraud, sentencing in a torture and crypto theft case, SEC's new roadmap, Jan crypto stats, Coinbase social engineering victims, and U.S. lawmakers' digital assets working group.
This week's stories include a critical Ethereum vulnerability, conviction in a £1.5M fraud, sentencing in a torture and crypto theft case, SEC's new roadmap, Jan crypto stats, Coinbase social engineering victims, and U.S. lawmakers' digital assets working group.
Microsoft says attackers use exposed ASP.NET keys to deploy malware
1 year 5 months ago
Microsoft warns that attackers are deploying malware in ViewState code injection attacks using static ASP. NET machine keys found online. [...]
Sergiu Gatlan
DeepSeek Phishing Sites Pursue User Data, Crypto Wallets
1 year 5 months ago
Riding the wave of notoriety from the Chinese company's R1 AT chatbot, attackers are spinning up lookalike sites for different malicious use cases.
Jai Vijayan, Contributing Writer
CVE-2021-20016 | SonicWall SSLVPN SMA100 10.x sql injection (SNWLID-2021-0001)
1 year 5 months ago
A vulnerability has been found in SonicWall SSLVPN SMA100 10.x and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection.
This vulnerability is known as CVE-2021-20016. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2021-20021 | SonicWALL Email Security 10.0.9.x HTTP Request privileges management (SNWLID-2021-0007)
1 year 5 months ago
A vulnerability was found in SonicWALL Email Security 10.0.9.x. It has been declared as critical. This vulnerability affects unknown code of the component HTTP Request Handler. The manipulation leads to improper privilege management.
This vulnerability was named CVE-2021-20021. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2021-20023 | SonicWall Email Security 10.0.9.x path traversal (SNWLID-2021-0010)
1 year 5 months ago
A vulnerability has been found in SonicWall Email Security 10.0.9.x and classified as critical. This vulnerability affects unknown code. The manipulation leads to path traversal.
This vulnerability was named CVE-2021-20023. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2022-23748 | Audinate Dante mDNSResponder.exe process control
1 year 5 months ago
A vulnerability was found in Audinate Dante. It has been rated as critical. This issue affects some unknown processing of the file mDNSResponder.exe. The manipulation leads to process control.
The identification of this vulnerability is CVE-2022-23748. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2022-4668 | Easy Appointments Plugin up to 3.10.7 Shortcode cross site scripting
1 year 5 months ago
A vulnerability classified as problematic has been found in Easy Appointments Plugin up to 3.10.7. This affects an unknown part of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2022-4668. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-28091 | HPE OneView Migrate Server Hardware information disclosure
1 year 5 months ago
A vulnerability classified as problematic was found in HPE OneView. Affected by this vulnerability is an unknown functionality of the component Migrate Server Hardware Handler. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2023-28091. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2021-36260 | Hikvision Product Message command injection (EDB-50441)
1 year 5 months ago
A vulnerability classified as critical was found in Hikvision Product. Affected by this vulnerability is an unknown functionality of the component Message Handler. The manipulation leads to command injection.
This vulnerability is known as CVE-2021-36260. The attack can only be done within the local network. Furthermore, there is an exploit available.
vuldb.com
CVE-2021-36742 | Trend Micro Apex One access control (ID 000287819)
1 year 5 months ago
A vulnerability has been found in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security and classified as critical. This vulnerability affects unknown code. The manipulation leads to improper access controls.
This vulnerability was named CVE-2021-36742. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2017-15812 | Easy Appointments Plugin up to 1.11.x on WordPress Admin Panel cross site scripting (ID 100908)
1 year 5 months ago
A vulnerability was found in Easy Appointments Plugin up to 1.11.x on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Admin Panel. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2017-15812. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-18187 | Trend Micro OfficeScan 11.0/12.0 ZIP File path traversal
1 year 5 months ago
A vulnerability was found in Trend Micro OfficeScan 11.0/12.0. It has been rated as critical. Affected by this issue is some unknown functionality of the component ZIP File Handler. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2019-18187. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2019-7481 | SonicWALL SMA100 up to 9.0.0.3 sql injection
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in SonicWALL SMA100 up to 9.0.0.3. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2019-7481. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2019-7483 | SonicWALL SMA100 CGI Script handleWAFRedirect path traversal
1 year 5 months ago
A vulnerability classified as problematic has been found in SonicWALL SMA100. This affects an unknown part of the file handleWAFRedirect of the component CGI Script. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2019-7483. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2020-8467 | Trend Micro Apex One/OfficeScan XG Migration Tool privileges management
1 year 5 months ago
A vulnerability was found in Trend Micro Apex One and OfficeScan XG. It has been classified as critical. This affects an unknown part of the component Migration Tool. The manipulation leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2020-8467. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2020-8468 | Trend Micro Apex One code download
1 year 5 months ago
A vulnerability was found in Trend Micro Apex One, OfficeScan XG and Worry-Free Business Security. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to download of code without integrity check.
This vulnerability was named CVE-2020-8468. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com