Aggregator
Вирус с легальной подписью. DigiCert взломали, и теперь «проверено антивирусом» — это не гарантия
Wiz ZeroDay.Cloud Event Reveals 20-Year-Old PostgreSQL Vulnerabilities
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
Microsoft Defender Research observed a large-scale credential theft campaign that exemplifies this trend, using code of conduct-themed lures, a multi-step attack chain, and legitimate email services to distribute fully authenticated messages from attacker-controlled domains.
The post Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise appeared first on Microsoft Security Blog.
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
Microsoft Defender Research observed a large-scale credential theft campaign that exemplifies this trend, using code of conduct-themed lures, a multi-step attack chain, and legitimate email services to distribute fully authenticated messages from attacker-controlled domains.
The post Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise appeared first on Microsoft Security Blog.
FlowCarp Identifies Protocols
CVE-2010-0843 | Sun JRE 1.3.1 27/1.4.2 25/1.5.0/1.6.0 Libraries integer memory corruption (Nessus ID 46807 / ID 165594)
CVE-2010-0844 | Sun JRE 1.6.0 Remote Code Execution (Nessus ID 46807 / ID 165594)
CVE-2010-0845 | Sun JRE 1.5.0/1.6.0 Hotspot memory corruption (Nessus ID 46873 / ID 118429)
CVE-2010-0846 | Sun JRE 1.6.0 heap-based overflow (Nessus ID 46807 / ID 165210)
CVE-2010-0847 | Sun JRE 1.6.0 heap-based overflow (Nessus ID 46873 / ID 165210)
CVE-2010-0848 | Sun JRE 1.6.0 memory corruption (Nessus ID 46873 / ID 118429)
CVE-2010-0849 | Sun JRE 1.6.0 heap-based overflow (Nessus ID 46807 / ID 165210)
CVE-2010-0850 | Sun JRE up to 1.3.1 27 Remote Code Execution (Nessus ID 46807 / ID 117435)
CVE-2009-2277 | VMware ESX Server 3.5 WebAccess cross site scripting (EUVD-2009-2273 / Nessus ID 45414)
CVE-2010-0686 | VMware ESX Server 2.0.0 WebAccess input validation (ID 117372 / SBV-25319)
CVE-2010-0768 | IBM WebSphere Application Server up to 6.1.0.10 Administration Console cross site scripting (Nessus ID 45431 / ID 86876)
Сценарий написал робот? Оставьте его себе. Американская киноакадемия поставила точку в большом споре о творчестве
Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia
New xlabs_v1 Botnet Targets Minecraft Servers Through ADB-Exposed Android Devices
A newly identified botnet called xlabs_v1 has been found targeting Minecraft game servers by exploiting Android devices with the Android Debug Bridge (ADB) port left open and exposed to the internet. The botnet is a modified version of the well-known Mirai malware, sold as a DDoS-for-hire service that lets paying customers flood game servers with […]
The post New xlabs_v1 Botnet Targets Minecraft Servers Through ADB-Exposed Android Devices appeared first on Cyber Security News.