Securing our home labs: Home Assistant code review

Introduction In July, the GitHub Security Lab team conducted a collaborative review of one of our favorite software pieces. While it's not uncommon for our Security Lab researchers to work togeth ...

Continue Reading
Exploit for Insufficient Session Expiration in Eclipse Jetty

Eclipse Jetty Canonical Repository =============================...Read More ...

Continue Reading
Peeling off QR Code Phishing Onion

# Peeling off QR Code Phishing Onion: Revealing the Hidden Layers of Deceit By Neel H. Pathak and Pratik Sunil Kadam ยท October 10, 2023 ## Introduction: Malicious actors always seek innovative ways ...

Continue Reading
Amazon Linux 2 : tomcat (ALASTOMCAT9-2023-008)

The version of tomcat installed on the remote host is prior to 9.0.73-1. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2TOMCAT9-2023-008 advisory. - When Apache Tom ...

Continue Reading
Exploit for Improper Handling of Exceptional Conditions in Eclipse Jetty

Eclipse Jetty Canonical Repository =============================...Read More ...

Continue Reading
[SECURITY] Fedora 38 Update: python-aiohttp-3.8.6-1.fc38

Python HTTP client/server for asyncio which supports both the client and the server side of the HTTP protocol, client and server websocket, and webserve rs with middlewares and pluggable...Read More ...

Continue Reading
Exploit for CVE-2021-28169

Eclipse Jetty Canonical Repository =============================...Read More ...

Continue Reading
Code injection

Directus is a real-time API and App dashboard for managing SQL database content. In affected versions any Directus installation that has websockets enabled can be crashed if the websocket server recei ...

Continue Reading

Back to Main

Subscribe for the latest news: