2023 OWASP Top-10 Series: API4:2023 Unrestricted Resource Consumption

Welcome to the 5th post in our weekly series on the new [2023 OWASP API Security Top-10]() list, with a particular focus on security practitioners. This post will focus on [API4:2023 Unrestricted Reso ...

Continue Reading
WoofLocker Toolkit Hides Malicious Codes in Images to Run Tech Support Scams

[![](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Cybersecurity researchers have detailed an updated version of an advanced fi ...

Continue Reading
Xsubfind3R – A CLI Utility To Find Domain’S Known Subdomains From Curated Passive Online Sources

[![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNUU02QE-Yw9IlS7oBVH3Kfxte3lMa-HrL4DcQrWnX5Cd6--jGqdloFEkQFpi8O14OZ0nI-VPLJ5oXaCu-1l4T0VsYHXxJQ6zPjG2_i3__6FGMtVLJWM9CxTATCJrQiGe6VrarBm ...

Continue Reading
Cross-site Scripting (XSS) – Reflected

# Description Reflected Cross-Site Scripting (XSS) vulnerability allows attackers to execute arbitrary external javascript code in the browser. In the application there exists a XSS vulnerability that ...

Continue Reading
CVE-2023-4415

A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/sys/login. The manipulation leads to ...

Continue Reading
CVE-2023-38902

An issue in RG-EW series home routers and repeaters v.EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P218, RG-EG series business VPN routers v.EG_3.0(1)B11P216, EAP and RAP se ...

Continue Reading
mTLS: When certificate authentication is done wrong

Although [X.509]() certificates have been here for a while, they have become more popular for client authentication in zero-trust networks in recent years. Mutual TLS, or authentication based on X.509 ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

New BlackCat Ransomware Variant Adopts Advanced Impacket and RemCom Tools

[![BlackCat Ransomware](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Microsoft on Thursday disclosed that it found a new versi ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Back to Main

Subscribe for the latest news: