A NULL pointer dereference flaw was found in the ub_ctx_set_fwd function in Unbound. This issue could allow an attacker who can invoke specific sequences of API calls to cause a segmentation fault. Wh ...
Continue ReadingAugust 12, 2024
OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when calling Check API with a model that uses but not and from expressions and a userset ...
Continue ReadingAugust 12, 2024
Executive Summary On June 20, 2024, Rapid7 identified multiple intrusion attempts by threat actors utilizing techniques, tactics, and procedures (TTPs) that are consistent with an ongoing social engi ...
Continue ReadingAugust 12, 2024
Cybersecurity researchers have identified a number of security shortcomings in photovoltaic system management platforms operated by Chinese companies Solarman and Deye that could enable malicious acto ...
Continue ReadingAugust 12, 2024
Security vulnerabilities have been disclosed in the industrial remote access solution Ewon Cosy+ that could be abused to gain root privileges to the devices and stage follow-on attacks. The elevated a ...
Continue ReadingAugust 12, 2024
The Russian government and IT organizations are the target of a new campaign that delivers a number of backdoors and trojans as part of a spear-phishing campaign codenamed EastWind. The attack chains ...
Continue ReadingAugust 12, 2024
-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (e070c9cd3f55352f0f37ae637e976e04cf4ebf83d1f086afb219eea4ec701c73) The OpenSSF Package Analysis project identified & ...
Continue ReadingAugust 11, 2024
-= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (a2fe1dd42b4e4bd52c1713cd1e40e619b15ef3e3d65cd9795082b2afb9fdc1ae) The OpenSSF Package Analysis project identified & ...
Continue ReadingAugust 11, 2024
Back to Main