Aggregator
Architectural Vulnerabilities in Notepad++: Arbitrary Code Execution Risks Unmasked
The Scale of the Exposure Security analysts discovered multiple critical vulnerabilities within the ubiquitous Notepad++ text editor. Consequently, one flaw permits arbitrary code execution through native software features. This structural issue endangers millions of...
The post Architectural Vulnerabilities in Notepad++: Arbitrary Code Execution Risks Unmasked appeared first on Information Security News.
Hackers Exploit Microsoft Teams’ Collaboration Features to Impersonate IT Helpdesk Staff
A growing wave of vishing (voice phishing) campaigns in which threat actors abuse Microsoft Teams’ external collaboration features to impersonate IT helpdesk personnel and investigators is now turning to the Microsoft 365 Unified Audit Log (UAL) as a critical forensic data source to reconstruct attack timelines. The attack chain begins when a threat actor operating […]
The post Hackers Exploit Microsoft Teams’ Collaboration Features to Impersonate IT Helpdesk Staff appeared first on Cyber Security News.
CVE-2019-6129 | libpng 1.6.36 png.c png_create_info_struct resource management (Issue 269)
CVE-2019-6109 | OpenSSH 7.9 Encoding progressmeter.c refresh_progress_meter access control (RHSA-2019:3702 / Nessus ID 121296)
CVE-2019-7317 | libpng 1.6.36 png.c png_image_free use after free (RHSA-2019:1265 / ID 237254)
CVE-2019-7317 | Oracle Java SE 7u221/8u212/11.0.3/12.0.1 libpng use after free (ID 371797 / BID-108098)
CVE-2019-6109 | Oracle Fujitsu M10-1 OpenSSH access control (Nessus ID 247820 / ID 351584)
CVE-2017-12626 | Oracle Retail Xstore Point of Service 7.1 Xenvironment infinite loop (BID-102879)
CVE-2017-12626 | Oracle Utilities Network Management System 1.12.0.3/2.3.0.1/2.3.0.2/2.4.0.0 Upload infinite loop (BID-102879)
CVE-2017-12626 | Oracle Insurance Policy Administration J2EE 10.2.0/10.2.4 Architecture infinite loop
CVE-2017-12626 | Oracle Retail Fusion Platform 5.5 Retail Portal Framework infinite loop
CVE-2017-12626 | Oracle Enterprise Data Quality 11.1.1.9.0/12.2.1.3.0 General denial of service (BID-102879)
CVE-2019-7317 | Oracle MySQL Workbench up to 8.0.23 denial of service (ID 371797 / BID-108098)
CVE-2017-12626 | Oracle Retail Sales Audit 14.0 Sales Audit Maintenance denial of service (BID-102879)
Зарегистрировался, создал репозиторий, взломал сервер. Новая атака на Gogs не требует ни помощников, ни особых прав
CALIF: An AI audit of FreeBSD
Digital Scorched-Earth: The Destructive Campaign of Ababil of Minab
Theoretical Origin and Campaign Overview The Iranian cyber collective known as Ababil of Minab recently claimed responsibility for a series of devastating cyberattacks. Specifically, these targeted incursions crippled transportation enterprises and commercial businesses across...
The post Digital Scorched-Earth: The Destructive Campaign of Ababil of Minab appeared first on Information Security News.
The Stealth Emergence of FROST: Tracking Users via SSD Latency Side-Channels
Websites possess a novel, obscured mechanism to monitor online visitors. Crucially, this approach completely bypasses traditional hardware peripherals like cameras, microphones, or weaponized browser extensions. Instead, it merely utilizes standard JavaScript code to detect...
The post The Stealth Emergence of FROST: Tracking Users via SSD Latency Side-Channels appeared first on Information Security News.