Aggregator
Ticketmaster boss who repeatedly hacked rival firm sentenced
1 year 6 months ago
A former boss of Ticketmaster has been sentenced after pleading guilty to illegally accessing comp
All Smoke, no Fire: The Bizarre Trend of Fake Data Breaches and How to Protect Against Them
1 year 6 months ago
You settle at your desk and sip your morning coffee, and then a flurry of notifications catches you
Joint cyber security advisory: People’s Republic of China-linked actors compromise routers and Internet-connected devices for botnet
1 year 6 months ago
Canadian Centre for Cyber Security
CVE-2007-2816 | olbookmarks themes/test4.php root code injection (EDB-3962 / XFDB-34402)
1 year 6 months ago
A vulnerability, which was classified as critical, was found in olbookmarks. Affected is an unknown function of the file themes/test4.php. The manipulation of the argument root leads to code injection.
This vulnerability is traded as CVE-2007-2816. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Санкции бьют по Android: что ждет российских пользователей?
1 year 6 months ago
Депутат Госдумы предупредил о проблемах с ОС.
英特尔计划将芯片代工业务变成独立子公司
1 year 6 months ago
英特尔计划将芯片代工业务变成独立子公司,有自己的董事会,接受外部资本。芯片巨人还在探索剥离代工业务、暂停部分欧洲芯片厂项目,撤回马来西亚工厂项目,扩大与亚马逊 AWS 在 AI 芯片生产方面的合作。这些都是 CEO Pat Gelsinger 扭转困境的努力的一部分。英特尔还计划出售可编程芯片业务 Altera 的部分股份。英特尔将通过正在建造的俄亥俄州工厂制造 AWS 的 AI 芯片。
CVE-2014-6806 | Intellegere Thanodi - Setswana Translator 1.0.0 X.509 Certificate cryptographic issues (VU#582497)
1 year 6 months ago
A vulnerability was found in Intellegere Thanodi - Setswana Translator 1.0.0. It has been rated as critical. This issue affects some unknown processing of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
The identification of this vulnerability is CVE-2014-6806. The attack can only be done within the local network. There is no exploit available.
vuldb.com
2024-09-16 - Snake KeyLogger (VIP Recovery) infection, SMTP exfil
1 year 6 months ago
Taking Control Online: Ensuring Awareness of Data Usage and Consent
1 year 6 months ago
Taking Control Online: Ensuring Awareness of Data Usage and Consent Pierluigi Paganini Septemb
Part 1: Can Just Anyone Access Your ServiceNow Articles?
1 year 6 months ago
What if I told you that thousands of companies (30% of the accounts we reviewed) are leaving a backdoor open to their ServiceNow databases for anyone with limited programming skills? This is a story of how a simple misconfiguration in one of the world’s most used SaaS applications sitting at the core of a company’s […]
The post Part 1: Can Just Anyone Access Your ServiceNow Articles? appeared first on Adaptive Shield.
The post Part 1: Can Just Anyone Access Your ServiceNow Articles? appeared first on Security Boulevard.
Dan Meged
ICO Acts Against Sky Betting and Gaming Over Cookies
1 year 6 months ago
Online gambling site, Sky Betting and Gaming, found to have “unlawfully” processed data through advertising cookies
CVE-2024-8951 | SourceCodester Resort Reservation System 1.0 manage_fee.php toview cross site scripting
1 year 6 months ago
A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file manage_fee.php. The manipulation of the argument toview leads to cross site scripting.
This vulnerability is known as CVE-2024-8951. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-38860 | Checkmk up to 2.2.0p33/2.3.0p15 Link cross site scripting
1 year 6 months ago
A vulnerability classified as problematic has been found in Checkmk up to 2.2.0p33/2.3.0p15. Affected is an unknown function of the component Link Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-38860. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-22303 | favethemes Houzez Plugin up to 3.2.4 on WordPress privileges assignment
1 year 6 months ago
A vulnerability was found in favethemes Houzez Plugin up to 3.2.4 on WordPress. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to incorrect privilege assignment.
The identification of this vulnerability is CVE-2024-22303. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-7788 | Document Foundation LibreOffice up to 24.2.4 Zip Repair Mode signature verification
1 year 6 months ago
A vulnerability was found in Document Foundation LibreOffice up to 24.2.4. It has been declared as critical. This vulnerability affects unknown code of the component Zip Repair Mode. The manipulation leads to improper verification of cryptographic signature.
This vulnerability was named CVE-2024-7788. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47049 | czim file-handling package up to 1.4.x/2.2.x makeFromUrl/makeFromAny server-side request forgery
1 year 6 months ago
A vulnerability was found in czim file-handling package up to 1.4.x/2.2.x. It has been classified as critical. This affects the function makeFromUrl/makeFromAny. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2024-47049. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Submit #409586: SourceCodester Resort Reservation System 1.0 Cross Site Scripting [Accepted]
1 year 6 months ago
Submit #409586 / VDB-277777
guru
Submit #409578: SourceCodester house rental management system 1.0 SQL Injection [Duplicate]
1 year 6 months ago
Submit #409578 / VDB-266275
zonesec
CVE-2022-22587 | Apple iOS/iPadOS up to 15.2.1 IOMobileFrameBuffer memory corruption (HT213053)
1 year 6 months ago
A vulnerability classified as critical has been found in Apple iOS and iPadOS up to 15.2.1. This affects an unknown part of the component IOMobileFrameBuffer. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2022-22587. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com