Aggregator
CVE-2024-9189 | EU UK VAT Manager for WooCommerce Plugin up to 2.12.12 on WordPress authorization
The TechCrunch Cyber Glossary
US, Microsoft Seize Domains Used in Russian Spear-Phishing
The U.S. Department of Justice and Microsoft seized more than 100 websites allegedly used by a Russian intelligence cyberespionage operation with a fondness for spear phishing. Targets include the national security apparatus and journalists, think tanks, and non-governmental organizations.
600,000 Prison Inmates to Share in $6.49M Breach Settlement
A misconfigured web server and the exposure of sensitive information for nearly 600,000 prison inmates in 2022 will cost medical claims processing company CorrectCare $6.49 million to settle a consolidated proposed class action lawsuit, according to court records.
Breach Roundup: AI 'Nudify' Sites Serve Malware
This week, AI nudify sites spread malware, BEC scammers head to prison, London man charged with hacking, and a Spanish insurance company with a breach. Also, a North Korean hacking group and a West African crackdown on online scammers. And, a Schrödinger Windows vulnerability: Is it real?
CISA Preparing to Assess Federal Zero Trust Progress
A top official from the U.S. Cybersecurity and Infrastructure Security Agency said Thursday the agency is planning to review updated federal implementation plans and ensure agencies are aligning with zero trust security objectives and addressing any funding gaps or technical challenges.
CVE-2014-7368 | Creatingahaven Compassion Satisfaction 0.75.13440.35155 X.509 Certificate cryptographic issues (VU#582497)
CVE-2016-4190 | Adobe Flash Player prior 11.2.202.632/18.0.0.366/22.0.0.209 memory corruption (APSB16-25 / Nessus ID 92309)
CVE-2006-6927 | Grandora Rialto 1.6 searchin sql injection (EDB-29107 / XFDB-30424)
CVE-2007-4737 | SpeedTech PHP Library stphpbtnimage.php STPHPLIB_DIR code injection (EDB-4358 / XFDB-36416)
USP: Establishes persistence on a Linux system
USP Establishes persistence on a Linux system by creating a udev rule that triggers the execution of a specified payload (binary or script) Feature This Go program establishes persistence on a Linux system by...
The post USP: Establishes persistence on a Linux system appeared first on Penetration Testing Tools.
Lil Pwny: auditing Active Directory passwords using Python
Lil Pwny Lil Pwny is a Python application to perform an offline audit of NTLM hashes of users’ passwords, recovered from Active Directory, against known compromised passwords from Have I Been Pwned. The usernames...
The post Lil Pwny: auditing Active Directory passwords using Python appeared first on Penetration Testing Tools.
lunar: UNIX security auditing tool
The lunar script generates a scored audit report of a Unix host’s security. It is based on the CIS and other frameworks. Where possible there are references to the CIS and other benchmarks in...
The post lunar: UNIX security auditing tool appeared first on Penetration Testing Tools.