Aggregator
CVE-2019-13118 | Apple iTunes up to 12.9.5 on Windows libxslt type confusion (HT210356)
CVE-2019-15213 | Linux Kernel up to 5.2.2 USB Device dvb-usb-init.c use after free
CVE-2019-16168 | SQLite up to 3.29.0 sqlite3.c whereLoopAddBtreeIndex divide by zero (USN-4205-1 / Nessus ID 236583)
CVE-2019-16168 | Oracle Communications Design Studio 7.3.4.3.0/7.3.5.5.0/7.4.0.4.0 divide by zero (Nessus ID 236583)
CVE-2019-16168 | Oracle Java SE 8u231 JavaFX divide by zero (Nessus ID 236583)
CVE-2019-13118 | Oracle Java SE 8u231 JavaFX type confusion
Physical Infiltration: The FBI Warns of Silent Ransom Group’s New Tactics
Evolution of the Adversarial Vector The Federal Bureau of Investigation recently issued an urgent advisory regarding the Silent Ransom Group. Notably, this sophisticated threat actor also operates under the corporate aliases Luna Moth, Chatty...
The post Physical Infiltration: The FBI Warns of Silent Ransom Group’s New Tactics appeared first on Information Security News.
蓝色起源的新格伦火箭在测试中发生爆炸
«Ненависть? Не видим». TikTok, Instagram и Facebook делают вид, что у них все в порядке с модерацией — и что из этого вышло
Building a risk-based vulnerability management program that scales
In this Help Net Security video, Shankar Somasundaram, CEO at Asimily, explains how to build a risk-based vulnerability program. He notes that vulnerabilities are exploding by an order of magnitude in the age of AI-driven attacks, with one customer finding a thousand vulnerabilities for every one they knew about. Patching everything is not workable, and relying on CVSS scores fails because two-thirds of published CVEs are marked high risk. Shankar walks through a better approach. … More →
The post Building a risk-based vulnerability management program that scales appeared first on Help Net Security.
CVE-2021-41800 | MediaWiki up to 1.36.1 Special:Contributions resource consumption (EUVD-2022-3541)
CVE-2022-30256 | MaraDNS Deadwood up to 3.5.0021 Domain Name access control (EUVD-2022-35461)
CVE-2022-30257 | Technitium DNS Server up to 8.0.2 Domain Name Resolution name resolution (EUVD-2022-35462)
Termite
You must login to view this content
VS Code Remote-SSH RCE Lets Attackers Pivot From Developer Machines to Cloud Servers
A newly disclosed vulnerability in Visual Studio Code’s Remote-SSH extension exposes a critical post-compromise attack path that allows threat actors to pivot from infected developer machines into cloud and production environments. Given the extension’s widespread adoption across modern development workflows, the issue poses a significant risk to organizations that rely on remote infrastructure access. VS […]
The post VS Code Remote-SSH RCE Lets Attackers Pivot From Developer Machines to Cloud Servers appeared first on Cyber Security News.