Cross-site scripting (XSS) from MIME type auto-detection of uploaded files

### TL;DR This vulnerability affects all Kirby sites that might have potential attackers in the group of authenticated Panel users or that allow external visitors to upload an arbitrary file to the co ...

Continue Reading
Insufficient Session Expiration after a password change

### TL;DR This vulnerability affects all Kirby sites with user accounts (unless Kirby's API and Panel are disabled in the config). It can only be abused if a Kirby user is logged in on a device or bro ...

Continue Reading
A Data Exfiltration Attack Scenario: The Porsche Experience

[![](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() As part of [**Checkmarx's mission**]() to help organizations develop and dep ...

Continue Reading
Cybersecurity Agencies Warn Against IDOR Bugs Exploited for Data Breaches

[![IDOR Bugs](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Cybersecurity agencies in Australia and the U.S. have [published]() ...

Continue Reading
Major Security Flaw Discovered in Metabase BI Software – Urgent Update Required

[![](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Users of Metabase, a popular business intelligence and data visualization so ...

Continue Reading
Patch now! Ivanti Endpoint Manager Mobile Authentication vulnerability used in the wild

The Cybersecurity and Infrastructure Security Agency (CISA) added one new vulnerability to its [Known Exploited Vulnerabilities Catalog]( "Known Exploited Vulnerabilities Catalog" ) affecting Ivanti E ...

Continue Reading
Preventing Web Application Access Control Abuse

### **SUMMARY** The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), U.S. Cybersecurity and Infrastructure Security Agency (CISA), and U.S. National Security Agency (NSA) ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Microsoft Defender Experts for XDR helps triage, investigate, and respond to cyberthreats

It has been an eventful time since the introduction of Microsoft Security Experts.1 We launched Defender Experts for Hunting, our first-party managed threat hunting service for customers who want Micr ...

Continue Reading

Back to Main

Subscribe for the latest news: