Aggregator
Lynx
Иногда лучший ответ на атаку — это вежливый 200 OK… и бомба внутри архива
CISA Issues Alert on Actively Exploited Apache HTTP Server Escape Vulnerability
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding a newly discovered and actively exploited vulnerability in the widely used Apache HTTP Server. The flaw, catalogued as CVE-2024-38475, affects the server’s mod_rewrite module and poses significant risks to organizations worldwide. Details of the Vulnerability CVE-2024-38475 is classified as an “improper escaping […]
The post CISA Issues Alert on Actively Exploited Apache HTTP Server Escape Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Загадка, перед которой отступили Ньютон и Галуа — и которую внезапно решил профессор из Сиднея
Phone theft is turning into a serious cybersecurity risk
Phone theft is a rising issue worldwide, and it’s more than just a property crime. It’s a serious cybersecurity threat. In the UK alone, the Metropolitan Police seizes 1,000 phones each week. Stolen phones don’t just go to local black markets. They often get funneled into larger criminal operations. For example, stolen phones can be used to bypass security features or be reprogrammed and resold. In 2024, Europol uncovered a massive phishing network that affected … More →
The post Phone theft is turning into a serious cybersecurity risk appeared first on Help Net Security.
sessionless: Burp Suite extension for editing, signing, verifying various signed web tokens
Sessionless Sessionless is a Burp Suite extension for editing, signing, verifying, and attacking signed tokens: Django TimestampSigner, ItsDangerous Signer, Express cookie-session middleware, OAuth2 Proxy, and Tornado’s signed cookies. It provides automatic detection and in-line editing of tokens within HTTP...
The post sessionless: Burp Suite extension for editing, signing, verifying various signed web tokens appeared first on Penetration Testing Tools.
Ты верил этим постам, а их написал ИИ: политические боты захватили соцсети
SentryPeer: distributed list of bad IP addresses and phone numbers
SentryPeer A distributed list of bad IP addresses and phone numbers was collected via a SIP Honeypot. This is basically a fraud detection tool. It lets bad actors try to make phone calls and...
The post SentryPeer: distributed list of bad IP addresses and phone numbers appeared first on Penetration Testing Tools.
CVE-2021-45425 | Libraryvideocompany SAFARI Montage 8.3/8.5 cross site scripting (EDB-50626)
CVE-2021-4181 | Wireshark up to 3.4.10/3.6.0 Sysdig Event Dissector denial of service (Nessus ID 207910)
CVE-2021-4186 | Wireshark up to 3.4.10 Gryphon Dissector denial of service (ID 17737 / Nessus ID 207910)
CVE-2021-29454 | Smarty up to 3.1.41/4.0.1 Template code injection (GHSA-29gp-2c3m-3j6m / Nessus ID 211188)
CVE-2022-22265 | Samsung NPU Driver SMR JUN-2021 Release 1 improper check or handling of exceptional conditions
CVE-2021-35247 | SolarWinds Serv-U Login Screen input validation
CVE-2022-21840 | Microsoft Office up to LTSC 2021 Remote Code Execution
Disney Hacker Admits Guilt After Stealing 1.1TB of Internal Data
A 25-year-old man from Santa Clarita, California, has agreed to plead guilty to hacking into the personal computer of a Walt Disney Company employee and stealing a massive amount of sensitive internal data last year. Ryan Mitchell Kramer faces charges related to unauthorized computer access and threats to damage a protected computer, marking a significant […]
The post Disney Hacker Admits Guilt After Stealing 1.1TB of Internal Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.