Microsoft Patch Tuesday September 2020: Zerologon and other exploits, RCEs in SharePoint and Exchange

I would like to start this post by talking about Microsoft vulnerabilities, which recently turned out to be much more serious than it seemed at first glance. ![](https://avleonov.com/wp-content/upload ...

Continue Reading
Triple-Threat Cryptocurrency RAT Mines, Steals and Harvests

A previously undocumented malware family called KryptoCibule is mounting a three-pronged cryptocurrency-related attack, while also deploying remote-access trojan (RAT) functionality to establish backd ...

Continue Reading
Mail.ru: [https://kiwi.youdrive.today/] Information disclosure via Kiwi TCMS vulnerability

Outdated ```kiwi.youdrive.today``` ([Kiwi TCMS](https://kiwitcms.org/) instance) was vulnerable to information disclosure via JSON-RPC endpoints. Outdated [Kiwi TCMS](https://kiwitcms.org/) instance w ...

Continue Reading
Cisco RV340 set_snmp usmUserPrivKey Command Injection Remote Code Execution Vulnerability

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Cisco RV340 routers. Authentication is required to exploit this vulnerability. The specific ...

Continue Reading
Cisco RV340 set_snmp usmUserEngineID Command Injection Remote Code Execution Vulnerability

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Cisco RV340 routers. Authentication is required to exploit this vulnerability. The specific ...

Continue Reading
Metasploit Wrap-Up

## Nagios modules ![Metasploit Wrap-Up](https://blog.rapid7.com/content/images/2021/04/metasploit-ascii-1-1.png) Community member Erik Wynter has contributed two more Nagios XI modules this week, on t ...

Continue Reading
Sifchain: xmlrpc.php And /wp-json/wp/v2/users FILE IS enable it will used for bruteforce attack and denial of service

Hi Team :) i am abbas heybati ;) ## Summary: After reviewing the given scope, I realized that the main domain "https://sifchain.finance" has several vulnerabilities that I will report to you as a scena ...

Continue Reading
Microsoft Exchange ProxyLogon RCE

This module exploit a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication, impersonating as the admin (CVE-2021-26855) and write arbitrary file (CVE-2021-27 ...

Continue Reading

Back to Main

Subscribe for the latest news: