#PoC Exploit for CVE-2023-27524 in Apache Superset Leads to #RCE Released
https://securityonline.info/poc-exploit-for-cve-2023-27524-in-apache-superset-leads-to-rce-released/
#PoC Exploit for CVE-2023-27524 in Apache Superset Leads to #RCE Released
https://securityonline.info/poc-exploit-for-cve-2023-27524-in-apache-superset-leads-to-rce-released/
Apple łata dwa 0daye wykorzystywane w atakach na iPhone-y. Złośliwym obrazkiem można przejąć telefon
Nowa wersja iOS 16.6.1 przynosi łatki zaledwie dwóch błędów, z czego jeden wygląda dość groźnie – odpowiednio spreparowanym obrazkiem można wykonać dowolny kod na telefonie ofiary: Impact: Processing a maliciously crafted image may lead to arbitrary code execution. Apple is aware of a report that this issue may have been...
La pandemia di backdoor su Citrix NetScaler non accenna a diminuire. 2000 sono i server infetti e molti anche in Italia
Durante una #campagna su larga scala, gli #hacker criminali hanno compromesso circa 2.000 server #Citrix #NetScaler utilizzando la #vulnerabilità #RCE critica CVE-2023-3519 (9,8 punti sulla scala CVSS). I paesi europei hanno sofferto maggiormente di questi attacchi compresa l'Italia.
Condividi questo post se hai trovato la news interessante.
#redhotcyber #online #it #web #ai #hacking #privacy #cybersecurity #cybercrime #intelligence #intelligenzaartificiale #informationsecurity #ethicalhacking #dataprotection #cybersecurityawareness #cybersecuritytraining #cybersecuritynews #infosecurity
#campagna #hacker #citrix #netscaler #vulnerabilità #rce #redhotcyber #online #it #web #ai #hacking #privacy #cybersecurity #cybercrime #intelligence #intelligenzaartificiale #informationsecurity #ethicalhacking #dataprotection #CyberSecurityAwareness #cybersecuritytraining #CyberSecurityNews #infosecurity
SecurityOnline: Critical Remote Code Execution (RCE) Vulnerability Affects WPS Office https://securityonline.info/critical-remote-code-execution-rce-vulnerability-affects-wps-office/ #Vulnerability #wpsoffice #rce
#vulnerability #wpsoffice #rce
Citrix nel mirino del cybercrime. 640 server Citrix Netscaler ADC e Gateway espongono una webshell
Gli #esperti di sicurezza hanno avvertito che circa 640 #server #Citrix #Netscaler ADC e Gateway sono già stati violati e infettati da #backdoor a seguito di attacchi che hanno usato la #vulnerabilità #RCE critica CVE-2023-3519 (9,8 punti sulla scala CVSS), scoperta e corretta il mese scorso.
#redhotcyber #online #it #web #ai #hacking #privacy #cybersecurity #cybercrime #intelligence #intelligenzaartificiale #informationsecurity #ethicalhacking #dataprotection #cybersecurityawareness #cybersecuritytraining #cybersecuritynews #infosecurity
#esperti #server #citrix #netscaler #backdoor #vulnerabilità #rce #redhotcyber #online #it #web #ai #hacking #privacy #cybersecurity #cybercrime #intelligence #intelligenzaartificiale #informationsecurity #ethicalhacking #dataprotection #CyberSecurityAwareness #cybersecuritytraining #CyberSecurityNews #infosecurity
SecurityOnline: XSSer – From XSS to RCE https://securityonline.info/xsser-xss-rce/ #WebExploitation #xsser #rce #XSS
#webexploitation #xsser #rce #xss
Die "#BleedingPipe" in #Minecraft-Mods...
Full #RCE, Übernahme von Geräten...
Details
https://blog.mmpa.info/posts/bleeding-pipe/
"because of the significance of the vulnerability, it is completely dangerous to play with unpatched mods"
https://github.com/dogboy21/serializationisbad/blob/master/README.md
Giocatori Minecraft nel mirino del cybercrime. L’RCE BleedingPipe colpisce sia server che client
Gli #hacker #criminali stanno sfruttando una #vulnerabilità #RCE di esecuzione di #codice #remoto chiamata “#BleedingPipe” nelle mod di #Minecraft per eseguire comandi dannosi su #server e #client.
Condividi questo post se hai trovato la news interessante.
#redhotcyber #online #it #web #ai #hacking #privacy #cybersecurity #cybercrime #intelligence #intelligenzaartificiale #informationsecurity #ethicalhacking #dataprotection #cybersecurityawareness #cybersecuritytraining #cybersecuritynews #infosecurity
#hacker #criminali #vulnerabilità #rce #codice #remoto #BleedingPipe #minecraft #server #client #redhotcyber #online #it #web #ai #hacking #privacy #cybersecurity #cybercrime #intelligence #intelligenzaartificiale #informationsecurity #ethicalhacking #dataprotection #CyberSecurityAwareness #cybersecuritytraining #CyberSecurityNews #infosecurity
#minecraft #rce in some mods, spotted in the wild. Singleplayer is safe but servers aren't
Tldr known issue with how #java ObjectInputStream parses specifically created malicious network packets
#security
#minecraft #rce #java #security
HackRead: AXIS A1001 System Flaws Expose Secure Facilities to Unauthorized Access https://www.hackread.com/axis-a1001-flaw-facilities-unauthorized-access/ #Vulnerability #Security #security #CISA #IoT #RCE #OT
#vulnerability #security #cisa #iot #rce #ot
Wie unangenehm: ein #zeroday #exploit mit #rce bei #openssh.
Zum Glück lässt sich die neue #sicherheitslücke mit der #cve202338408 nur ausnutzen, wenn man per #ssh auf ein kompromittiertes System weitergeleitet wird. Das verkleinert den Angriffsvektor erheblich.
Wie es aussieht sind nahezu alle #debian Versionen betroffen und bis jetzt gibt's erst für sid ein Update.
#zeroday #exploit #rce #openssh #sicherheitslucke #cve202338408 #ssh #debian
Es gibt eine #RCE Lücke im OpenSSH Forwarded SSH Agent. Patches sind heute erschienen. #itsecnews
https://blog.qualys.com/vulnerabilities-threat-research/2023/07/19/cve-2023-38408-remote-code-execution-in-opensshs-forwarded-ssh-agent
Adobe ColdFusion soffre di una Remote Code Execution in pre-autenticazione. Aggiornare immediatamente
Una #vulnerabilità critica di Remote Code Execution (#RCE) in pre-auth è stata rilevata su #Adobe #ColdFusion tracciata come CVE-2023-29300 che è sfruttata in attacchi attivi.
Condividi questo post se hai trovato la news interessante.
#redhotcyber #online #it #web #ai #hacking #privacy #cybersecurity #cybercrime #intelligence #intelligenzaartificiale #informationsecurity #ethicalhacking #dataprotection #cybersecurityawareness #cybersecuritytraining #cybersecuritynews #infosecurity
#vulnerabilità #rce #adobe #coldfusion #redhotcyber #online #it #web #ai #hacking #privacy #cybersecurity #cybercrime #intelligence #intelligenzaartificiale #informationsecurity #ethicalhacking #dataprotection #CyberSecurityAwareness #cybersecuritytraining #CyberSecurityNews #infosecurity
Critical RCE found in popular Ghostscript open-source PDF library
https://www.bleepingcomputer.com/news/security/critical-rce-found-in-popular-ghostscript-open-source-pdf-library/
#computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #Ghostscript #Linux #Open_Source #PDF #PoC #RCE #Remote_Code_Execution #Vulnerability #virus_removal #malware_removal #computer_help #technical_support
#computers #windows #linux #mac #support #tech_support #spyware #malware #virus #security #ghostscript #open_source #pdf #poc #rce #remote_code_execution #vulnerability #virus_removal #malware_removal #computer_help #technical_support
#VMware warns of #exploit available for critical #vRealize #RCE bug
Successful exploitation enables threat actors to run arbitrary code as root following low-complexity attacks that don't require user interaction.
https://www.bleepingcomputer.com/news/security/vmware-warns-of-exploit-available-for-critical-vrealize-rce-bug/
#vmware #exploit #vrealize #rce
#RCE für Window mittels Office Dokument? Kein Problem für mutmaßliche Russische APT.
CVE-2023-36884 – Leitfaden für Sicherheitsupdates – Microsoft - Office and Windows HTML Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884
📬 Mastodon in Gefahr: Kritische Schwachstelle erlaubt Server-Übernahme
#ITSicherheit #Cure53 #Mastodon #OpenSource #RCE #RemoteCodeExecution #Sicherheitslücke #Sicherheitsupdate #XSS https://tarnkappe.info/artikel/it-sicherheit/mastodon-in-gefahr-kritische-schwachstelle-erlaubt-server-uebernahme-278307.html
#itsicherheit #cure53 #mastodon #opensource #rce #remotecodeexecution #sicherheitslucke #sicherheitsupdate #xss
Hope everyone updated their #Mastodon servers.
There's an #RCE in unpatched versions!
https://github.com/mastodon/mastodon/security/advisories/GHSA-9928-3cp5-93fm