Aggregator
Threat Assessment: Repellent Scorpius, Distributors of Cicada3301 Ransomware
1 year 6 months ago
Executive SummaryRepellent Scorpius is a new ransomware-as-a-service (RaaS) group
Mustang Panda Deploys Advanced Malware to Spy on Asia-Pacific Governments
1 year 6 months ago
The threat actor tracked as Mustang Panda has refined its malware arsenal to include new tools in o
3 Blog Post CTAs That Are MUCH More Effective Than “Buy Now”
1 year 6 months ago
So you want people to take action when they read a blog post.But how do you get them to actually do
CVE-2024-34831 | Gibbon Core 26.0.00 library_manage_catalog_editProcess.php imageLink cross site scripting
1 year 6 months ago
A vulnerability was found in Gibbon Core 26.0.00. It has been rated as problematic. This issue affects some unknown processing of the file library_manage_catalog_editProcess.php. The manipulation of the argument imageLink leads to cross site scripting.
The identification of this vulnerability is CVE-2024-34831. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-43492 | Microsoft AutoUpdate on macOS access control
1 year 6 months ago
A vulnerability was found in Microsoft AutoUpdate on macOS. It has been classified as critical. This affects an unknown part. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2024-43492. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43482 | Microsoft Outlook on iOS information disclosure
1 year 6 months ago
A vulnerability, which was classified as problematic, was found in Microsoft Outlook on iOS. Affected is an unknown function. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-43482. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Windows 11 KB5043076 cumulative update released with 19 changes
1 year 6 months ago
Microsoft has released the mandatory Windows 11 23H2 KB5043076 cumulative update to fix security vulnerabilities and make 19 improvements. [...]
Lawrence Abrams
CVE-2024-43495 | Microsoft Windows 11 22H2/11 23H2/Server 2022 23H2 libarchive integer overflow
1 year 6 months ago
A vulnerability was found in Microsoft Windows 11 22H2/11 23H2/Server 2022 23H2. It has been declared as critical. This vulnerability affects unknown code of the component libarchive. The manipulation leads to integer overflow.
This vulnerability was named CVE-2024-43495. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43492 | Microsoft AutoUpdate on macOS access control
1 year 6 months ago
A vulnerability was found in Microsoft AutoUpdate on macOS. It has been classified as critical. This affects an unknown part. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2024-43492. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43491 | Microsoft Windows 10 Update use after free
1 year 6 months ago
A vulnerability was found in Microsoft Windows 10 and classified as very critical. Affected by this issue is some unknown functionality of the component Update. The manipulation leads to use after free.
This vulnerability is handled as CVE-2024-43491. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43487 | Microsoft Windows up to Server 2019 Mark of the Web protection mechanism
1 year 6 months ago
A vulnerability has been found in Microsoft Windows up to Server 2019 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Mark of the Web. The manipulation leads to protection mechanism failure.
This vulnerability is known as CVE-2024-43487. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43482 | Microsoft Outlook on iOS information disclosure
1 year 6 months ago
A vulnerability, which was classified as problematic, was found in Microsoft Outlook on iOS. Affected is an unknown function. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-43482. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43479 | Microsoft Power Automate for Desktop access control
1 year 6 months ago
A vulnerability, which was classified as critical, has been found in Microsoft Power Automate for Desktop. This issue affects some unknown processing. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2024-43479. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Linux reverse shell that (almost) always works.
1 year 6 months ago
Windows reverse shell that (almost) always works.
1 year 6 months ago
CVE-2024-43476 | Microsoft Dynamics 365 cross site scripting
1 year 6 months ago
A vulnerability classified as problematic was found in Microsoft Dynamics 365. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-43476. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43475 | Microsoft Windows Server 2008 SP2 Admin Center buffer over-read
1 year 6 months ago
A vulnerability classified as critical has been found in Microsoft Windows Server 2008 SP2. This affects an unknown part of the component Admin Center. The manipulation leads to buffer over-read.
This vulnerability is uniquely identified as CVE-2024-43475. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43474 | Microsoft SQL Server null termination
1 year 6 months ago
A vulnerability was found in Microsoft SQL Server Microsoft SQL Server 2017/Microsoft SQL Server 2019. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper null termination.
This vulnerability is handled as CVE-2024-43474. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Optimal Ethical Hacker Setup for Penetration Testing
1 year 6 months ago