Mellium vulnerable to authentication failure or insufficient randomness used during authentication

An issue was discovered in Mellium mellium.im/sasl before 0.3.1. When performing SCRAM-based SASL authentication, if the remote end advertises support for channel binding, no random nonce is generated ...

Continue Reading
CVE-2023-22466

Tokio is a runtime for writing applications with Rust. Starting with version 1.7.0 and prior to versions 1.18.4, 1.20.3, and 1.23.1, when configuring a Windows named pipe server, setting `pipe_mode` w ...

Continue Reading
SpyNote Strikes Again: Android Spyware Targeting Financial Institutions

[![Android Spyware](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Financial institutions are being targeted by a new version of ...

Continue Reading
CircleCI Urges Customers to Rotate Secrets Following Security Incident

[![CircleCI](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() DevOps platform CircleCI on Wednesday urged its customers to rotate ...

Continue Reading
CVE-2023-22466

Tokio is a runtime for writing applications with Rust. Starting with version 1.7.0 and prior to versions 1.18.4, 1.20.3, and 1.23.1, when configuring a Windows named pipe server, setting `pipe_mode` w ...

Continue Reading
CVE-2023-22463

KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resulting in the same Jwtsigkeys for all online projects. This means that an attacker ...

Continue Reading
Go 1.20 Cryptography

![Go 1.20 Cryptography](https://words.filippo.io/content/images/2023/01/IMG_9975-2.jpeg) [The ~~first~~ second release candidate of Go 1.20 is out]()![1] This is the first release I participated in as ...

Continue Reading
FortiTester – Multiple command injection vulnerabilities in GUI and API

Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiTester may allow an authenticated attacker to execute arbitrary com ...

Continue Reading

Back to Main

Subscribe for the latest news: