Cross site scripting

Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`, which is leveraged by the WebSocket authentication ...

Continue Reading
CVE-2023-41896

Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`, which is leveraged by the WebSocket authentication ...

Continue Reading
[SECURITY] Fedora 39 Update: rust-tungstenite-0.20.1-1.fc39

Lightweight stream-based WebSocket implementation.Read More ...

Continue Reading
Cybercriminals Using New ASMCrypt Malware Loader to Fly Under the Radar

[![ASMCrypt Malware Loader](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Threat actors are selling a new crypter and loader ca ...

Continue Reading
Amazon Linux 2 : tomcat (ALASTOMCAT8.5-2023-006)

The version of tomcat installed on the remote host is prior to 8.5.72-1. It is, therefore, affected by a vulnerability as referenced in the ALAS2TOMCAT8.5-2023-006 advisory. - The fix for bug 63362 ...

Continue Reading
Cross Site Scripting (XSS)

home-assistant/core and home-assistant-js-websocket are vulnerable to XSS attack.The vulnerability occurs due to a loophole in Websocket authentication logic. The logic utilises a `state` parameter wh ...

Continue Reading
Denial Of Service (DoS)

directus is vulnerable to Denial Of Service (DoS). The vulnerability exists because invalid websocket frames are not properly handled which allows an attacker to crash the application .Read More ...

Continue Reading
Amazon Linux 2 : tomcat (ALASTOMCAT9-2023-006)

The version of tomcat installed on the remote host is prior to 9.0.54-1. It is, therefore, affected by a vulnerability as referenced in the ALAS2TOMCAT9-2023-006 advisory. - The fix for bug 63362 pr ...

Continue Reading

Back to Main

Subscribe for the latest news: