Aggregator
RansomHub
10 months 4 weeks ago
cohenido
Understand these seven password attacks and how to stop them
10 months 4 weeks ago
Hackers are always looking for new ways to crack passwords and gain access to your organization's data and systems. In this post, Specops Software discusses the seven most common password attacks and provide tips on how to defend against them. [...]
Sponsored by Specops Software
CVE-2024-49253 | James Park Analyse Uploads Plugin up to 0.5 on WordPress path traversal
10 months 4 weeks ago
A vulnerability was found in James Park Analyse Uploads Plugin up to 0.5 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to relative path traversal.
This vulnerability is uniquely identified as CVE-2024-49253. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-47637 | LiteSpeed Technologies LiteSpeed Cache Plugin up to 6.4.1 on WordPress path traversal
10 months 4 weeks ago
A vulnerability was found in LiteSpeed Technologies LiteSpeed Cache Plugin up to 6.4.1 on WordPress and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to relative path traversal.
This vulnerability is handled as CVE-2024-47637. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-48028 | Boyan Raichev IP Loc8 Plugin up to 1.1 on WordPress deserialization
10 months 4 weeks ago
A vulnerability has been found in Boyan Raichev IP Loc8 Plugin up to 1.1 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to deserialization.
This vulnerability is known as CVE-2024-48028. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-49254 | Sunjianle ajax-extend Plugin up to 1.0 on WordPress code injection
10 months 4 weeks ago
A vulnerability, which was classified as critical, has been found in Sunjianle ajax-extend Plugin up to 1.0 on WordPress. This issue affects some unknown processing. The manipulation leads to code injection.
The identification of this vulnerability is CVE-2024-49254. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-47649 | THATplugin Iconize Plugin up to 1.2.4 on WordPress unrestricted upload
10 months 4 weeks ago
A vulnerability, which was classified as problematic, was found in THATplugin Iconize Plugin up to 1.2.4 on WordPress. Affected is an unknown function. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2024-47649. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
ExtraHop RevealX enhancements accelerate investigation workflows
10 months 4 weeks ago
ExtraHop unveiled new network-based file analysis capabilities in ExtraHop RevealX to detect malware, combat ransomware, and help prevent data loss. According to the 2024 Global Ransomware Trends Report, organizations experience an average of eight ransomware incidents per year. To carry out these attacks, adversaries often rely on the disparate tools and disjointed workflows deployed in the SOC, ensuring malicious files stay under the radar and go undetected. In response to the rapidly growing threat ransomware … More →
The post ExtraHop RevealX enhancements accelerate investigation workflows appeared first on Help Net Security.
Industry News
网易有道QAnything应用SQL注入漏洞(CVE-2024-7099)
10 months 4 weeks ago
网易有道QAnything应用SQL注入漏洞(CVE-2024-7099)
Oracle WebLogic Server 反序列化漏洞(CVE-2024-21216)
10 months 4 weeks ago
Oracle WebLogic Server 反序列化漏洞(CVE-2024-21216)
What Cybersecurity Leaders Can Learn From the Game of Golf
10 months 4 weeks ago
As in golf, security requires collaboration across the entire organization, from individual contributors in each department to the executive level and the board.
Jeff Shiner
Microsoft 在 Windows Server 中弃用 PPTP 和 L2TP VPN 协议
10 months 4 weeks ago
Windows RRAS Server 的未来版本将不再接受使用 PPTP 和 L2TP 协议的传入连接。
尽快提交!2024年网络安全“金帽子”年度评选活动报名进行中
10 months 4 weeks ago
望各企业单位尽快填写相关材料进行报名!
CVE-2024-48026 | Grayson Robbins Disc Golf Manager Plugin up to 1.0.0 on WordPress deserialization
10 months 4 weeks ago
A vulnerability classified as critical was found in Grayson Robbins Disc Golf Manager Plugin up to 1.0.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to deserialization.
This vulnerability was named CVE-2024-48026. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Malicious ads exploited Internet Explorer zero day to drop malware
10 months 4 weeks ago
The North Korean hacking group ScarCruft launched a large-scale attack in May that leveraged an Internet Explorer zero-day flaw to infect targets with the RokRAT malware and exfiltrate data. [...]
Bill Toulas
Joint cyber security advisory: Iranian cyber actors using brute force to compromise critical infrastructure organizations
10 months 4 weeks ago
Canadian Centre for Cyber Security
CVE-2024-48027 | xaraartech External Featured Image from Bing Plugin up to 1.0.2 on WordPress unrestricted upload
10 months 4 weeks ago
A vulnerability classified as critical has been found in xaraartech External Featured Image from Bing Plugin up to 1.0.2 on WordPress. This affects an unknown part. The manipulation leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2024-48027. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-49242 | Shafiq Digital Lottery Plugin up to 3.0.5 on WordPress unrestricted upload
10 months 4 weeks ago
A vulnerability was found in Shafiq Digital Lottery Plugin up to 3.0.5 on WordPress. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to unrestricted upload.
This vulnerability is known as CVE-2024-49242. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-48035 | Takayuki Imanishi ACF Images Search and Insert Plugin up to 1.1.4 on WordPress unrestricted upload
10 months 4 weeks ago
A vulnerability was found in Takayuki Imanishi ACF Images Search and Insert Plugin up to 1.1.4 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to unrestricted upload.
This vulnerability is handled as CVE-2024-48035. The attack may be launched remotely. There is no exploit available.
vuldb.com