matrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessions

### Impact An attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but ...

Continue Reading
matrix-js-sdk subject to impersonated messages due to permissive key forwarding

## Impact An attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but ...

Continue Reading
[SECURITY] Fedora 35 Update: libofx-0.10.7-2.fc35

This is the LibOFX library. It is a API designed to allow applications to very easily support OFX command responses, usually provided by financial institutions. See https://www.ofx.net/ofx/default.as ...

Continue Reading
matrix-js-sdk subject to impersonated messages due to permissive key forwarding

## Impact An attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but ...

Continue Reading
Fast Company hacked to send obscene and racist messages

Yesterday, Apple News [announced]() it had disabled the channel of [Fast Company](), a US-based business magazine, after surprised Twitter users reported it was tweeting offensive comments. > An in ...

Continue Reading
Optus data breach “attacker” says sorry, it was a mistake

Since Australian telecoms company Optus disclosed a security breach on September 22, 2022, a lot has been happening. Much of it reads like a movie script. ## Prologue A hacker acting under the pseudon ...

Continue Reading
CVE-2022-36068

Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, a moderator can create new and e ...

Continue Reading
CVE-2022-39266

isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior, if the untrusted v8 cached data is passed to the API through CachedDataOptions, ...

Continue Reading

Back to Main

Subscribe for the latest news: