Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 9 / 13
255 résultats taggé vulnerability  ✕
7 December 2023 - Apache Struts version 6.3.0.2 General Availability https://struts.apache.org/announce-2023?is=e4f6b16c6de31130985364bb824bcb39ef6b2c4e902e4e553f0ec11bdbefc118#a20231207-1
18/12/2023 11:21:46
QRCode
archive.org

7 December 2023 - Apache Struts version 6.3.0.2 General Availability

The Apache Struts group is pleased to announce that Apache Struts version 6.3.0.2 is available as a “General Availability” release. The GA designation is our highest quality grade.

The Apache Struts is an elegant, extensible framework for creating enterprise-ready Java web applications. The framework has been designed to streamline the full development cycle, from building, to deploying, to maintaining applications over time.

This version addresses a potential security vulnerability identified as CVE-2023-50164 and described in S2-066 - please read the mentioned security bulletins for more details. This is a drop-in replacement and upgrade should be straightforward.

apache.org EN 2023 CVE-2023-50164 Apache Struts annonce Vulnerability
QNAP VioStor NVR vulnerability actively exploited by malware botnet https://www.bleepingcomputer.com/news/security/qnap-viostor-nvr-vulnerability-actively-exploited-by-malware-botnet/
16/12/2023 17:25:37
QRCode
archive.org
thumbnail

A Mirai-based botnet named 'InfectedSlurs' is exploiting a remote code execution (RCE) vulnerability in QNAP VioStor NVR (Network Video Recorder) devices to hijack and make them part of its DDoS (distributed denial of service) swarm.
#Actively #Botnet #Computer #Exploited #FXC #InfectedSlurs #InfoSec #Malware #QNAP #Router #Security #Vulnerability

bleepingcomputer EN 2023 FXC QNAP InfectedSlurs Actively Botnet Malware Exploited Computer Router Vulnerability
Exploiting GOG Galaxy XPC service for privilege escalation in macOS https://securityintelligence.com/x-force/exploiting-gog-galaxy-xpc-service-privilege-escalation-macos/
16/12/2023 01:04:00
QRCode
archive.org
thumbnail

Unpack the analysis of a GOG Galaxy XPC service vulnerability. More from IBM X-Force Red.

securityintelligence 2023 EN macos GOG client XPC vulnerability
Imperva Uncovers CVE-2023-22524, A RCE Vulnerability https://www.imperva.com/blog/cve-2023-22524-rce-vulnerability-in-atlassian-companion-for-macos/
16/12/2023 01:01:43
QRCode
archive.org
thumbnail

Learn about a RCE vulnerability, discovered by the Imperva Red Team, identified as CVE-2023-22524, in Atlassian Companion for macOS.

imperva EN 2023 RCE vulnerability CVE-2023-22524 Atlassian macOS
GitHub - yunuscadirci/DIALStranger: details about DIAL protocol vulnerabilities https://github.com/yunuscadirci/DIALStranger
20/11/2023 06:41:06
QRCode
archive.org
thumbnail

details about DIAL protocol vulnerabilities . Contribute to yunuscadirci/DIALStranger development by creating an account on GitHub.

yunuscadirci EN 2023 Netflix YouTube Sony Samsung DIAL DIALStranger protocol vulnerability
In a first, cryptographic keys protecting SSH connections stolen in new attack | Ars Technica https://arstechnica.com/security/2023/11/hackers-can-steal-ssh-cryptographic-keys-in-new-cutting-edge-attack/
16/11/2023 07:15:01
QRCode
archive.org
thumbnail

An error as small as a single flipped memory bit is all it takes to expose a private key.
The vulnerability occurs when there are errors during the signature generation that takes place when a client and server are establishing a connection. It affects only keys using the RSA cryptographic algorithm, which the researchers found in roughly a third of the SSH signatures they examined. That translates to roughly 1 billion signatures out of the 3.2 billion signatures examined. Of the roughly 1 billion RSA signatures, about one in a million exposed the private key of the host.

arstechnica EN 2023 SSH RSA cryptographic algorithm error vulnerability
CVE-2023-38548 https://attackerkb.com/topics/UPt5tpYK2Y/cve-2023-38548/rapid7-analysis?
10/11/2023 21:28:37
QRCode
archive.org
thumbnail

On November 6, 2023, Veeam published an advisory for several vulnerabilities affecting Veeam ONE, an IT monitoring and analytics platform for enterprises. One …

attackerkb CVE-2023-38548 EN 2023 VeeamONE Veeam vulnerability
SysAid On-Prem Software CVE-2023-47246 Vulnerability Disclosure https://profero.io/posts/sysaidonpremvulnerability/
10/11/2023 08:45:17
QRCode
archive.org

On Nov 2nd, our security team received reports regarding a potential vulnerability in our on-premise software which was being actively exploited. We immediately initiated our incident response protocol and began proactively communicating with our on-premise customers to ensure they could implement a mitigation solution we had identified. We engaged Profero, a cyber security incident response company, to assist us in our investigation. The investigation determined that there was a zero-day vulnerability in the SysAid on-premises software. We urge all customers with SysAid on-prem server installations to ensure that your SysAid systems are updated to version 23.3.36, which remediates the identified vulnerability, and conduct a comprehensive compromise assessment of your network to look for any indicators further discussed below. Should you identify any indicators, take immediate action and follow your incident response protocols.

profero EN 2023 CVE-2023-47246 disclosure vulnerability SysAid
SysAid On-Prem Software CVE-2023-47246 Vulnerability https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification
09/11/2023 06:44:07
QRCode
archive.org
thumbnail

On Nov 2nd, a potential vulnerability in our on-premise software came to our security team’s attention. We immediately initiated our incident response protocol and began proactively communicating with our on-premise customers to ensure they could implement a mitigation solution we had identified. We engaged Profero, a cyber security incident response company, to assist us in our investigation. The investigation determined that there was a zero-day vulnerability in the SysAid on-premises software.

sysaid EN 2023 CVE-2023-47246 SysAid On-Prem Vulnerability
Common Vulnerability Scoring System https://www.first.org/cvss/v4-0/
08/11/2023 12:17:41
QRCode
archive.org
thumbnail

CVSS version 4.0 is the next generation of the Common Vulnerability Scoring System standard.

first EN 2023 Common Vulnerability Scoring System v4-0 CVSS
FIRST Announces CVSS 4.0 - New Vulnerability Scoring System https://thehackernews.com/2023/11/first-announces-cvss-40-new.html
02/11/2023 18:22:13
QRCode
archive.org
thumbnail

FIRST announces CVSS v4.0, the latest version of the Common Vulnerability Scoring System. Discover how this update addresses critical vulnerabilities.

thehackernews EN 2023 CVSS CVSS4.0 Vulnerability Scoring System
HackerOne paid ethical hackers over $300 million in bug bounties https://www.bleepingcomputer.com/news/security/hackerone-paid-ethical-hackers-over-300-million-in-bug-bounties/
28/10/2023 23:07:20
QRCode
archive.org
thumbnail

HackerOne has announced that its bug bounty programs have awarded over $300 million in rewards to ethical hackers and vulnerability researchers since the platform's inception.

bleepingcomputer EN 2023 Bug-Bounty Ethical-Hacking HackerOne Vulnerability Vulnerability-Disclosure-Program Vulnerability-Rewards-Program White-Hat-Hacker
Compromising F5 BIGIP with Request Smuggling | CVE-2023-46747 https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/
27/10/2023 13:43:18
QRCode
archive.org
thumbnail

Our team identified a request smuggling vulnerability that led to complete compromise of an F5 system with the TMUI exposed.

praetorian EN F5 BIGIP Request Smuggling vulnerability CVE-2023-46747
Winter Vivern exploits zero-day vulnerability in Roundcube Webmail servers https://www.welivesecurity.com/en/eset-research/winter-vivern-exploits-zero-day-vulnerability-roundcube-webmail-servers/
27/10/2023 08:24:41
QRCode
archive.org

ESET Research discover campaigns by the Winter Vivern APT group that exploit a zero-day XSS vulnerability in the Roundcube Webmail server and target governmental entities and a think tank in Europe.

welivesecurity ESET 2023 EN WinterVivern APT zero-day XSS vulnerability Roundcube
VMSA-2023-0023 https://www.vmware.com/security/advisories/VMSA-2023-0023.html
25/10/2023 23:47:03
QRCode
archive.org
thumbnail

VMware vCenter Server updates address out-of-bounds write and information disclosure vulnerabilities

vmware EN 2023 vulnerability VMSA-2023-0023 CVE-2023-34048 advisory
CVE-2023-4911: Looney Tunables - Local Privilege Escalation in the glibc’s ld.so https://blog.qualys.com/vulnerabilities-threat-research/2023/10/03/cve-2023-4911-looney-tunables-local-privilege-escalation-in-the-glibcs-ld-so#potential-impact-of-looney-tunables
04/10/2023 09:33:44
QRCode
archive.org
thumbnail

The Qualys Threat Research Unit (TRU) has discovered a buffer overflow vulnerability in GNU C Library's dynamic loader's processing of the GLIBC_TUNABLES…

qualys EN 2023 GLIBC_TUNABLES CVE-2023-4911 buffer overflow vulnerability
Qualcomm says hackers exploit 3 zero-days in its GPU, DSP drivers https://www.bleepingcomputer.com/news/security/qualcomm-says-hackers-exploit-3-zero-days-in-its-gpu-dsp-drivers/
03/10/2023 17:31:45
QRCode
archive.org
thumbnail

Qualcomm is warning of three zero-day vulnerabilities in its GPU and Compute DSP drivers that hackers are actively exploiting in attacks.

bleepingcomputer EN 2023 Actively-Exploited Android Mobile Qualcomm Vulnerability Zero-Day GPU Adreno
Vulnerability in popular ‘libwebp’ code more widespread than expected https://therecord.media/libwebp-vulnerability-more-widespread-than-expected
28/09/2023 21:11:47
QRCode
archive.org
thumbnail

Initial alerts about a bug in the obscure but widely used libwebp library have expanded into concerns that it affects not only web browsers like Chrome, but also many other common pieces of software.

therecord EN 2023 libwebp vulnerability CVE-2023-4863
GPU.zip https://www.hertzbleed.com/gpu.zip/
27/09/2023 19:23:47
QRCode
archive.org

On the Side-Channel Implications of Hardware-Based Graphical Data Compression

hertzbleed EN 2023 vulnerability Side-Channel Graphical-Data-Compression GPU.zip
Can't Be Contained: Finding a Command Injection Vulnerability in Kubernetes https://www.akamai.com/blog/security-research/kubernetes-critical-vulnerability-command-injection
15/09/2023 16:34:42
QRCode
archive.org
thumbnail

Akamai researchers discover a critical vulnerability in Kubernetes that can lead to remote code execution.

akamai EN 2023 Kubernetes command-injection vulnerability YAML rce remote-code-execution
page 9 / 13
4858 links
Shaarli - Le gestionnaire de marque-pages personnel, minimaliste, et sans base de données par la communauté Shaarli - Theme by kalvn