Aggregator
CVE-2007-1355 | Apache Tomcat up to 4.0.0 hello.jsp test cross site scripting (EDB-30052 / Nessus ID 25289)
Microsoft to Boost M365 Bounty Program With New Products & Rewards Up to $27,000
A significant extension of Microsoft’s Microsoft 365 (M365) Bounty Program has been announced. The program now includes new Viva products under its scope for identifying vulnerabilities, with rewards reaching up to $27,000 for critical submissions. This update underscores Microsoft’s commitment to enhancing the security of its software ecosystem and encouraging global collaboration in vulnerability detection. […]
The post Microsoft to Boost M365 Bounty Program With New Products & Rewards Up to $27,000 appeared first on Cyber Security News.
D-Link Routers Vulnerability Let Attackers Gain Full Router Control Remotely
A critical unauthenticated Remote Code Execution (RCE) vulnerability has been affecting DSL-3788 routers, allowing attackers to acquire complete control over the router remotely. The flaw has been detected in firmware versions v1.01R1B036_EU_EN and below. This vulnerability was reported by Max Bellia of SECURE NETWORK BVTECH. The vulnerability resides in the webproc CGI component of the […]
The post D-Link Routers Vulnerability Let Attackers Gain Full Router Control Remotely appeared first on Cyber Security News.
CVE-2015-4181 | phpMyBackupPro 2.1/2.2/2.3/2.4/2.5 Incomplete Fix get_file.php view path traversal (EDB-10169)
Authorities Take Down Cracked & Nulled Hacking Forums Used by 10 Million Users
In a law enforcement operation dubbed “Operation Talent,” an international coalition of law enforcement agencies led by Germany’s Bundeskriminalamt (BKA) and Europol has dismantled two of the world’s largest cybercrime forums: Cracked.io and Nulled.to. These platforms, which collectively hosted over 10 million users, served as hubs for illicit activities, including selling stolen data, malware, hacking […]
The post Authorities Take Down Cracked & Nulled Hacking Forums Used by 10 Million Users appeared first on Cyber Security News.
关于 DeepSeek R 部署的说明 --- A Note on DeepSeek R Deployment
CVE-2024-13530 | zia-imtiaz Custom Login Page Styler Plugin up to 7.1.1 on WordPress lps_handle_delete_all_logs authorization
CVE-2020-35754 | Opensolution Quick.CMS/Quick.Cart up to 6.6 Language Tab code injection (EDB-49494)
CVE-2024-13530 | zia-imtiaz Custom Login Page Styler Plugin up to 7.1.1 on WordPress lps_handle_delete_all_logs authorization
CVE-2017-2992 | Adobe Flash Player up to 24.0.0.194 memory corruption (APSB17-04 / EDB-41420)
CVE-2023-0092 | Juju path traversal
CVE-2022-1736 | GNOME Control Center Network Service access control
Question about using an old abandoned program.
CVE-2024-1211 | GitLab Community Edition/Enterprise Edition up to 16.9.6/16.10.4/16.11.1 cross-site request forgery (Issue 440313 / Nessus ID 214826)
MSP Case Study: Hubelia Simplified Client Domain Security Management with PowerDMARC
Hubelia, a Canada-based MSP, automated DMARC, SPF & DKIM with PowerDMARC, improving security, compliance, and deliverability.
The post MSP Case Study: Hubelia Simplified Client Domain Security Management with PowerDMARC appeared first on Security Boulevard.