BeaverTail Malware Resurfaces in Malicious npm Packages Targeting Developers

Three malicious packages published to the npm registry in September 2024 have been found to contain a known malware called BeaverTail, a JavaScript downloader and information stealer linked to an ongo ...

Continue Reading
(RHSA-2024:8494) Important: pki-servlet-engine security update

Tomcat is the servlet engine that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are deve ...

Continue Reading
(RHSA-2024:8497) Important: pki-deps:10.6 security update

The Public Key Infrastructure (PKI) Core contains fundamental packages required by Red Hat Certificate System. Security Fix(es): tomcat: Denial of Service in Tomcat (CVE-2024-38286) For more details ...

Continue Reading
(RHSA-2024:8528) Important: pki-servlet-engine security update

Tomcat is the servlet engine that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are deve ...

Continue Reading
CVE-2024-50575

In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget...Read More ...

Continue Reading
CVE-2024-50487 WordPress MaanStore API plugin <= 1.0.1 – Account Takeover vulnerability

Authentication Bypass Using an Alternate Path or Channel vulnerability in MaanTheme MaanStore API allows Authentication Bypass.This issue affects MaanStore API: from n/a through...Read More ...

Continue Reading
CVE-2024-50486 WordPress Acnoo Flutter API plugin <= 1.0.5 – Account Takeover vulnerability

Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API allows Authentication Bypass.This issue affects Acnoo Flutter API: from n/a through...Read More ...

Continue Reading
pyLoad vulnerable to remote code execution by download to /.pyload/scripts using /flashgot API

Summary The folder /.pyload/scripts has scripts which are run when certain actions are completed, for e.g. a download is finished. By downloading a executable file to a folder in /scripts and performi ...

Continue Reading

Back to Main

Subscribe for the latest news: