Exploit for CVE-2022-2048

Eclipse Jetty Canonical Repository =============================...Read More ...

Continue Reading
[SECURITY] Fedora 39 Update: rust-tungstenite-0.20.1-1.fc39

Lightweight stream-based WebSocket implementation.Read More ...

Continue Reading
Rocky Linux 8 : qt5-qtbase and qt5-qtwebsockets (RLSA-2020:4690)

The remote Rocky Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RLSA-2020:4690 advisory. Qt through 5.14 allows an exponential XML entity expa ...

Continue Reading
Directus crashes on invalid WebSocket message

### Summary It seems that any Directus installation that has websockets enabled can be crashed if the websocket server receives an invalid frame. This could probably be posted as an issue and I might ...

Continue Reading
CVE-2023-6394

A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentic ...

Continue Reading
Amazon Linux 2 : tomcat (ALASTOMCAT9-2023-008)

The version of tomcat installed on the remote host is prior to 9.0.73-1. It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2TOMCAT9-2023-008 advisory. - When Apache Tom ...

Continue Reading
Directus crashes on invalid WebSocket message

### Summary It seems that any Directus installation that has websockets enabled can be crashed if the websocket server receives an invalid frame. This could probably be posted as an issue and I might ...

Continue Reading
Cybercriminals Using New ASMCrypt Malware Loader to Fly Under the Radar

[![ASMCrypt Malware Loader](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Threat actors are selling a new crypter and loader ca ...

Continue Reading

Back to Main

Subscribe for the latest news: