MERCURY and DEV-1084: Destructive attack on hybrid environment

> **April 2023 update** – Microsoft Threat Intelligence has shifted to a new threat actor naming taxonomy aligned around the theme of weather. **MERCURY** is now tracked as **Mango Sandstorm** ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

MERCURY and DEV-1084: Destructive attack on hybrid environment

> **April 2023 update** – Microsoft Threat Intelligence has shifted to a new threat actor naming taxonomy aligned around the theme of weather. **MERCURY** is now tracked as **Mango Sandstorm** ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Github token with wide access to Nuxt related repositories leaked in the wild

# Description If you visit https://nuxt.com, you will find hardcoded Github token in the source code of the page - `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`. This token has access to multiple reposit ...

Continue Reading

CVSS3 - CRITICAL

Description of the security update for SharePoint Server 2019: April 11, 2023 (KB5002373)

None ## Summary This security update resolves a Microsoft SharePoint Server spoofing vulnerability. To learn more about the vulnerability, see ​​​​[Microsoft Common Vulnerabilities ...

Continue Reading

CVSS3 - MEDIUM

CVE-2023-30527

Jenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jen ...

Continue Reading

CVSS3 - MEDIUM

CVE-2023-30528

Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for attackers to observe and capture it.Read More ...

Continue Reading

CVSS3 - MEDIUM

Jenkins WSO2 Oauth Plugin stores WSO2 Oauth client secret unencrypted in global config.xml file on Jenkins controller

Jenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller as part of its configuration. This client secret can b ...

Continue Reading

CVSS3 - MEDIUM

Jenkins WSO2 Oauth Plugin does not mask the WSO2 Oauth client secret on the global configuration form

Jenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller as part of its configuration. This client secret can b ...

Continue Reading

CVSS3 - MEDIUM

Back to Main

Subscribe for the latest news: