Aggregator
CVE-2017-2440 | Apple watchOS up to 3.1 Kernel integer overflow (HT207602 / EDB-40961)
10 months 2 weeks ago
A vulnerability classified as critical was found in Apple watchOS up to 3.1. This vulnerability affects unknown code of the component Kernel. The manipulation leads to integer overflow.
This vulnerability was named CVE-2017-2440. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Recurring Windows Flaw Could Expose User Credentials
10 months 2 weeks ago
Now a zero-day, the vulnerability enables NTLM hash theft, an issue that Microsoft has already fixed twice before.
Jai Vijayan, Contributing Writer
ANONYMOUS MUSLIMS Targeted the Website of Astronautics C.A Ltd
10 months 2 weeks ago
ANONYMOUS MUSLIMS Targeted the Website of Astronautics C.A Ltd
Dark Web Informer
【情报实战】你的随手一拍,就暴露了军事机密
10 months 2 weeks ago
上述分析报告反映出开源情报分析可以利用社交媒体等公开信息分析出高度保密的军事机密。你的好奇和随手一拍就暴露我军的军事机密了。
【祝贺】新华社也报道了第四届全国开源情报技术大会在武汉召开
10 months 2 weeks ago
2024年10月26日至27日,第四届全国开源情报技术大会在武汉隆重举行。此次大会由中国中文信息学会开源情报技术专业委员会主办,湖北大学和北京中科闻歌科技股份有限公司联合承办。
CVE-2023-32261 | Micro Focus Dimensions Plugin on Jenkins permission
10 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Micro Focus Dimensions Plugin on Jenkins. Affected by this issue is some unknown functionality. The manipulation leads to permission issues.
This vulnerability is handled as CVE-2023-32261. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-37440 | Aruba EdgeConnect SD-WAN Orchestrator Web-based Management Interface server-side request forgery (ARUBA-PSA-2023-012)
10 months 2 weeks ago
A vulnerability was found in Aruba EdgeConnect SD-WAN Orchestrator. It has been rated as critical. Affected by this issue is some unknown functionality of the component Web-based Management Interface. The manipulation leads to server-side request forgery.
This vulnerability is handled as CVE-2023-37440. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-20264 | Google Android 14 Usage Stats Service information disclosure
10 months 2 weeks ago
A vulnerability was found in Google Android 14. It has been rated as problematic. This issue affects some unknown processing of the component Usage Stats Service. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2022-20264. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2017-2440 | Apple iOS up to 10.2 Kernel integer overflow (HT207617 / EDB-40961)
10 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Apple iOS up to 10.2. This affects an unknown part of the component Kernel. The manipulation leads to integer overflow.
This vulnerability is uniquely identified as CVE-2017-2440. An attack has to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
International law enforcement operation dismantled RedLine and Meta infostealers
10 months 2 weeks ago
A global law enforcement operation disrupted RedLine and Meta infostealers, seizing their infrastructure and making arrests. The Dutch police announced it has dismantled infrastructure used by RedLine and Meta infostealers as part of an international law enforcement operation led by Eurojust that was code-named Operation Magnus. RedLine and META targeted millions of victims worldwide, according to Eurojust […]
Pierluigi Paganini
An Introduction to Operational Relay Box (ORB) Networks – Unpatched, Forgotten, and Obscured
10 months 2 weeks ago
Although not a new concept, Operational Relay Box (ORB) networks—often referred to as "covert," "mesh," or "obfuscated" networks—are...
The post An Introduction to Operational Relay Box (ORB) Networks – Unpatched, Forgotten, and Obscured appeared first on Security Boulevard.
S2 Research Team
CVE-2017-2440 | Apple macOS up to 10.12.3 Kernel integer overflow (HT207615 / EDB-40961)
10 months 2 weeks ago
A vulnerability was found in Apple macOS up to 10.12.3. It has been classified as critical. Affected is an unknown function of the component Kernel. The manipulation leads to integer overflow.
This vulnerability is traded as CVE-2017-2440. An attack has to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
China's 'Evasive Panda' APT Debuts High-End Cloud Hijacking
10 months 2 weeks ago
A professional-grade tool set, appropriately dubbed "CloudScout," is infiltrating cloud apps like Microsoft Outlook and Google Drive, targeting sensitive info for exfiltration.
Tara Seals, Managing Editor, News, Dark Reading
CVE-2004-2626 | Siemens Phone Local Privilege Escalation (EDB-24065 / XFDB-15995)
10 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in Siemens Phone. Affected is an unknown function. The manipulation leads to Local Privilege Escalation.
This vulnerability is traded as CVE-2004-2626. Local access is required to approach this attack. Furthermore, there is an exploit available.
vuldb.com
从目录浏览分析幽盾攻击组织
10 months 2 weeks ago
阿对对对
从目录浏览分析幽盾攻击组织
10 months 2 weeks ago
阿对对对
从目录浏览分析幽盾攻击组织
10 months 2 weeks ago
阿对对对
从目录浏览分析幽盾攻击组织
10 months 2 weeks ago
阿对对对
What Is Secrets Management? Best Practices and Challenges
10 months 2 weeks ago
Modern apps require hundreds of secrets to function (API keys, cloud credentials, etc.). However, poor management of these secrets can expose sensitive information publicly or to malicious actors.
The post What Is Secrets Management? Best Practices and Challenges appeared first on Security Boulevard.
Legit Security