CVE-2024-43167

A NULL pointer dereference flaw was found in the ub_ctx_set_fwd function in Unbound. This issue could allow an attacker who can invoke specific sequences of API calls to cause a segmentation fault. Wh ...

Continue Reading
CVE-2024-42473

OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses but not and from expressions and a userset ...

Continue Reading
Ongoing Social Engineering Campaign Refreshes Payloads

Executive Summary On June 20, 2024, Rapid7 identified multiple intrusion attempts by threat actors utilizing techniques, tactics, and procedures (TTPs) that are consistent with an ongoing social engi ...

Continue Reading
Researchers Uncover Vulnerabilities in Solarman and Deye Solar Systems

Cybersecurity researchers have identified a number of security shortcomings in photovoltaic system management platforms operated by Chinese companies Solarman and Deye that could enable malicious acto ...

Continue Reading
Industrial Remote Access Tool Ewon Cosy+ Vulnerable to Root Access Attacks

Security vulnerabilities have been disclosed in the industrial remote access solution Ewon Cosy+ that could be abused to gain root privileges to the devices and stage follow-on attacks. The elevated a ...

Continue Reading
EastWind Attack Deploys PlugY and GrewApacha Backdoors Using Booby-Trapped LNK Files

The Russian government and IT organizations are the target of a new campaign that delivers a number of backdoors and trojans as part of a spear-phishing campaign codenamed EastWind. The attack chains ...

Continue Reading
Malicious code in cargo-hub-ui-api-internal (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (e070c9cd3f55352f0f37ae637e976e04cf4ebf83d1f086afb219eea4ec701c73) The OpenSSF Package Analysis project identified & ...

Continue Reading
Malicious code in cargo-hub-ui-api (npm)

-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (a2fe1dd42b4e4bd52c1713cd1e40e619b15ef3e3d65cd9795082b2afb9fdc1ae) The OpenSSF Package Analysis project identified & ...

Continue Reading

Back to Main

Subscribe for the latest news: