Chinese Cybercrime Groups Ran Operations in Rented Hotels and Guest Houses Sri Lankan authorities have arrested more than 200 Chinese nationals who they say overstayed their visitor visas and engaged in large-scale financial scam operations targeting victims across Asia. The Chinese Embassy in Colombo says it supports the law enforcement crackdown.
A vulnerability was found in Dovecot up to 2.2.x/2.3.19. It has been rated as critical. Affected by this issue is some unknown functionality of the component passdb Configuration Handler. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2022-30550. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in util-linux and classified as problematic. Affected by this issue is some unknown functionality of the component FUSE Filesystem Handler. The manipulation leads to files or directories accessible.
This vulnerability is handled as CVE-2021-3996. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as critical has been found in Simple Cold Storage Management System 1.0. This affects an unknown part of the file /csms/admin/storages/view_storage.php. The manipulation of the argument id leads to sql injection.
This vulnerability is uniquely identified as CVE-2022-42249. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability has been found in ARM Mali GPU Kernel Driver and classified as critical. This vulnerability affects unknown code. The manipulation leads to use after free.
This vulnerability was named CVE-2022-42716. The attack needs to be initiated within the local network. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, has been found in Google Chrome. This issue affects some unknown processing of the component DevTools. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2023-1216. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Google Chrome and classified as critical. Affected by this vulnerability is an unknown functionality of the component WebRTC. The manipulation leads to use after free.
This vulnerability is known as CVE-2023-1218. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Microsoft Edge. It has been rated as critical. This issue affects some unknown processing of the component DevTools. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2023-1216. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as critical was found in Microsoft Edge. Affected by this vulnerability is an unknown functionality of the component WebRTC. The manipulation leads to use after free.
This vulnerability is known as CVE-2023-1218. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability, which was classified as critical, was found in innopage GIGA HOBBY 1.0.6. This affects an unknown part of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is uniquely identified as CVE-2014-7715. The attack needs to be done within the local network. There is no exploit available.
This article uncovers a Golang ransomware abusing Amazon S3 for data theft, and masking as LockBit to further pressure victims. The discovery of hard-coded AWS credentials in these samples led to AWS account suspensions.
This article uncovers a Golang ransomware abusing AWS S3 for data theft, and masking as LockBit to further pressure victims. The discovery of hard-coded AWS credentials in these samples led to AWS account suspensions.
A vulnerability, which was classified as critical, has been found in Freedesktop libdbus up to 1.5.12. Affected by this issue is some unknown functionality. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2012-3524. Attacking locally is a requirement. Furthermore, there is an exploit available.
A vulnerability classified as critical has been found in PostHog. This affects the function database_schema. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2024-9710. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Moodle. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to information exposure through error message.
This vulnerability is handled as CVE-2024-48896. The attack may be launched remotely. There is no exploit available.