Aggregator
CVE-2022-31629 | PHP up to 7.4.30/8.0.23/8.1.10 Cookie input validation (Bug 81727 / Nessus ID 211146)
Windows Backdoor Targets Members of Exiled Uyghur Community
CVE-2022-40959 | Mozilla Firefox up to 104 FeaturePolicy access control (Bug 1782211 / Nessus ID 208611)
CVE-2022-40960 | Mozilla Firefox up to 104 URL Parser use after free (Bug 1787633 / Nessus ID 208611)
CVE-2022-40958 | Mozilla Firefox up to 104 Cookie session fixiation (Bug 1779993 / Nessus ID 208611)
CVE-2019-5797 | Google Chrome up to 72.0.3626.121 DOMStorage double free (EDB-46565 / ID 237168)
CVE-2022-40962 | Mozilla Firefox up to 104 memory corruption (Nessus ID 208611)
CVE-2022-40956 | Mozilla Firefox up to 104 Content-Security-Policy injection (Bug 1770094 / Nessus ID 208611)
CVE-2022-40957 | Mozilla Firefox up to 104 on ARM64 denial of service (Bug 1777604 / Nessus ID 208611)
CVE-2022-3033 | Mozilla Thunderbird up to 91.13.0 HTML Email information disclosure (Bug 1784838 / Nessus ID 208639)
CVE-2022-3032 | Mozilla Thunderbird up to 91.13.0 HTML Email information disclosure (Bug 1783831 / Nessus ID 208589)
Google Chrome Vulnerability Let Attackers Escape Payload from Sandbox – Technical Details Disclosed
A critical vulnerability in Google Chrome has recently been discovered that allows malicious actors to break out of the browser’s protective sandbox environment, potentially giving attackers access to the underlying operating system. The flaw, identified as CVE-2025-2783, affects Chrome versions prior to 134.0.6998.142 across Windows, macOS, and Linux platforms. This vulnerability represents a significant security […]
The post Google Chrome Vulnerability Let Attackers Escape Payload from Sandbox – Technical Details Disclosed appeared first on Cyber Security News.
Europol Creates Operational Taskforce to Tackle Violence-as-a-Service
In response to the concerning rise of “violence-as-a-service” (VaaS) and the exploitation of youth by organized crime, Europol has announced the formation of a new Operational Task Force (OTF), codenamed GRIMM. This multinational initiative, led by Sweden, brings together law enforcement agencies from Belgium, Denmark, Finland, France, Germany, the Netherlands, and Norway. Europol provides operational […]
The post Europol Creates Operational Taskforce to Tackle Violence-as-a-Service appeared first on Cyber Security News.
Bitwarden Access Intelligence defends against credential risks and phishing
Bitwarden launched Access Intelligence, a set of new capabilities that enables enterprises to proactively defend against internal credential risks and external phishing threats. Access Intelligence introduces two core functionalities: Risk Insights, which allows IT teams to identify, prioritize, and remediate at-risk credentials; and Advanced Phishing Blocker, which alerts and redirects users away from known phishing sites in real-time, using a continuously updated open source blocklist of malicious domains. This approach enables better protection for users … More →
The post Bitwarden Access Intelligence defends against credential risks and phishing appeared first on Help Net Security.
CVE-2000-0665 | GAMSoft Telsrv 1.4/1.5 Username denial of service (EDB-16816 / Nessus ID 10474)
Google Warns of 75 Zero-Day Vulnerabilities Exploited in the Wild
Google’s Threat Intelligence Group (GTIG) has revealed that 75 zero-day vulnerabilities were exploited in the wild during 2024, highlighting both evolving attacker tactics and shifting targets in the global cybersecurity landscape. While this figure decreases from the 98 zero-days observed in 2023, it still represents a significant increase from the 63 tracked in 2022, underscoring […]
The post Google Warns of 75 Zero-Day Vulnerabilities Exploited in the Wild appeared first on Cyber Security News.
ExtraHop strenghtens network detection and response
ExtraHop launched all-in-one sensor designed to unify network traffic collection that scales across a number of security use cases. This further advances ExtraHop’s vision to consolidate NDR, network performance monitoring (NPM), intrusion detection (IDS), and full packet forensics into an integrated, powerful, and adaptable security solution for the modern hybrid enterprise. According to IDC, tool consolidation can save 16% of total tool costs and nearly 20% of analyst time on average. With the ExtraHop all-in-one … More →
The post ExtraHop strenghtens network detection and response appeared first on Help Net Security.