NAME__________Sourcecodester Best Courier Management System file upload Platforms Affected:Sourcecodester Best Courier Management System 1.0 Risk… This article has been indexed from RedPacket Security Read the original article: Sourcecodester Best Courier Management System file upload | CVE-2023-46004
Category: RedPacket Security
Knight Ransomware Victim: Emmea Srl
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Knight Ransomware Victim: Emmea Srl
Number of hacked Cisco IOS XE devices plummets from 50K to hundreds
The number of Cisco IOS XE devices hacked with a malicious backdoor implant has mysteriously… This article has been indexed from RedPacket Security Read the original article: Number of hacked Cisco IOS XE devices plummets from 50K to hundreds
New TetrisPhantom hackers steal data from secure USB drives on govt systems
A new sophisticated threat tracked as ‘TetrisPhantom’ has been using compromised secure USB drives to… This article has been indexed from RedPacket Security Read the original article: New TetrisPhantom hackers steal data from secure USB drives on govt systems
Black Basta Ransomware Victim: Simpson Strong-Tie
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Black Basta Ransomware Victim: Simpson Strong-Tie
Black Basta Ransomware Victim: Panetteria Grandolfo
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Black Basta Ransomware Victim: Panetteria Grandolfo
LockBit 3.0 Ransomware Victim: chs[.]ca
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: chs[.]ca
TinyMCE cross-site scripting | CVE-2023-45818
NAME__________TinyMCE cross-site scripting Platforms Affected:TinyMCE TinyMCE 6.0.0 TinyMCE TinyMCE 5.10.7 TinyMCE TinyMCE 6.7.0 Risk Level:6.1… This article has been indexed from RedPacket Security Read the original article: TinyMCE cross-site scripting | CVE-2023-45818
ETSI TETRA Standard security bypass | CVE-2022-24404
NAME__________ETSI TETRA Standard security bypass Platforms Affected:ETSI TETRA Risk Level:5.9 Exploitability:Unproven Consequences:Bypass Security DESCRIPTION__________ ETSI… This article has been indexed from RedPacket Security Read the original article: ETSI TETRA Standard security bypass | CVE-2022-24404
D-Link DSL-2750U N300 ADSL2+ and DSL-2730U N150 ADSL2+ routers security bypass | CVE-2023-46033
NAME__________D-Link DSL-2750U N300 ADSL2+ and DSL-2730U N150 ADSL2+ routers security bypass Platforms Affected:D-Link DSL-2750U N300… This article has been indexed from RedPacket Security Read the original article: D-Link DSL-2750U N300 ADSL2+ and DSL-2730U N150 ADSL2+ routers security bypass | CVE-2023-46033
TinyMCE cross-site scripting | CVE-2023-45819
NAME__________TinyMCE cross-site scripting Platforms Affected:TinyMCE TinyMCE 6.0.0 TinyMCE TinyMCE 5.10.7 TinyMCE TinyMCE 6.7.0 Risk Level:6.1… This article has been indexed from RedPacket Security Read the original article: TinyMCE cross-site scripting | CVE-2023-45819
IBM Cognos Dashboards information disclosure | CVE-2023-38275
NAME__________IBM Cognos Dashboards information disclosure Platforms Affected:IBM Cognos Dashboards on Cloud Pak for Data 4.7.0… This article has been indexed from RedPacket Security Read the original article: IBM Cognos Dashboards information disclosure | CVE-2023-38275
Knight Ransomware Victim: Intellipop Fiber Internet
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Knight Ransomware Victim: Intellipop Fiber Internet
Knight Ransomware Victim: il Centro
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Knight Ransomware Victim: il Centro
8 Base Ransomware Victim: Brunton Shaw
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: 8 Base Ransomware Victim: Brunton Shaw
8 Base Ransomware Victim: Edwards Business Systems
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: 8 Base Ransomware Victim: Edwards Business Systems
8 Base Ransomware Victim: APS – Automotive Parts Solutions
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: 8 Base Ransomware Victim: APS – Automotive Parts Solutions
8 Base Ransomware Victim: JC Roman Construction
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: 8 Base Ransomware Victim: JC Roman Construction
Cyber Security Tip of the Week: Malware Detection and Prevention
Oops! It looks like the content you’re trying to access is exclusively available to our… This article has been indexed from RedPacket Security Read the original article: Cyber Security Tip of the Week: Malware Detection and Prevention
American Family Insurance confirms cyberattack is behind IT outages
Insurance giant American Family Insurance has confirmed it suffered a cyberattack and shut down portions… This article has been indexed from RedPacket Security Read the original article: American Family Insurance confirms cyberattack is behind IT outages
International Criminal Court systems breached for cyber espionage
The International Criminal Court provided additional information about the cyberattack five weeks ago, saying that… This article has been indexed from RedPacket Security Read the original article: International Criminal Court systems breached for cyber espionage
The Week in Ransomware – October 20th 2023 – Fighting Back
This was a bad week for ransomware, with the Trigona ransomware suffering a data breach… This article has been indexed from RedPacket Security Read the original article: The Week in Ransomware – October 20th 2023 – Fighting Back
Tunngle – 8,192,928 breached accounts
In 2016, the now defunct global LAN gaming network Tunngle suffered a data breach that… This article has been indexed from RedPacket Security Read the original article: Tunngle – 8,192,928 breached accounts
RansomHouse Ransomware Victim: Foursquare Healthcare
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues… This article has been indexed from RedPacket Security Read the original article: RansomHouse Ransomware Victim: Foursquare Healthcare
Commander – A Command And Control (C2) Server
Commander is a command and control framework (C2) written in Python, Flask and SQLite. It comes… This article has been indexed from RedPacket Security Read the original article: Commander – A Command And Control (C2) Server
SecuSphere – Efficient DevSecOps
SecuSphere is a comprehensive DevSecOps platform designed to streamline and enhance your organization’s security posture… This article has been indexed from RedPacket Security Read the original article: SecuSphere – Efficient DevSecOps
LockBit 3.0 Ransomware Victim: uaes[.]com
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: uaes[.]com
LockBit 3.0 Ransomware Victim: charleystaxi[.]com
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: charleystaxi[.]com
LockBit 3.0 Ransomware Victim: degrootgroep[.]nl
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: degrootgroep[.]nl
bbp style pack Plugin for WordPress cross-site scripting | CVE-2023-44984
NAME__________bbp style pack Plugin for WordPress cross-site scripting Platforms Affected:WordPress bbp style pack Plugin for… This article has been indexed from RedPacket Security Read the original article: bbp style pack Plugin for WordPress cross-site scripting | CVE-2023-44984
Seriously Simple Stats Plugin for WordPress cross-site scripting | CVE-2023-45005
NAME__________Seriously Simple Stats Plugin for WordPress cross-site scripting Platforms Affected:WordPress Seriously Simple Stats Plugin for… This article has been indexed from RedPacket Security Read the original article: Seriously Simple Stats Plugin for WordPress cross-site scripting | CVE-2023-45005
Social Media Share Buttons and Social Sharing Icons plugin for WordPress cross-site request forgery | CVE-2023-5602
NAME__________Social Media Share Buttons and Social Sharing Icons plugin for WordPress cross-site request forgery Platforms… This article has been indexed from RedPacket Security Read the original article: Social Media Share Buttons and Social Sharing Icons plugin for WordPress cross-site request…
Woo Custom Emails Plugin for WordPress cross-site scripting | CVE-2023-45004
NAME__________Woo Custom Emails Plugin for WordPress cross-site scripting Platforms Affected:WordPress Woo Custom Emails Plugin for… This article has been indexed from RedPacket Security Read the original article: Woo Custom Emails Plugin for WordPress cross-site scripting | CVE-2023-45004
Theme Switcha plugin for WordPress cross-site scripting | CVE-2023-5614
NAME__________Theme Switcha plugin for WordPress cross-site scripting Platforms Affected:WordPress Theme Switcha plugin for WordPress 3.3… This article has been indexed from RedPacket Security Read the original article: Theme Switcha plugin for WordPress cross-site scripting | CVE-2023-5614
Daily Vulnerability Trends: Sat Oct 21 2023
CVE NAME CVE Description CVE-2023-20198 Cisco is aware of active exploitation of a previously unknown… This article has been indexed from RedPacket Security Read the original article: Daily Vulnerability Trends: Sat Oct 21 2023
Critical RCE flaws found in SolarWinds access audit solution
Security researchers found three critical remote code execution vulnerabilities in the SolarWinds Access Rights Manager (ARM)… This article has been indexed from RedPacket Security Read the original article: Critical RCE flaws found in SolarWinds access audit solution
Okta says its support system was breached using stolen credentials
Update October 20, 16:15 EDT: Added BeyondTrust incident details. Update October 20, 18:59 EDT: Added Cloudflare incident… This article has been indexed from RedPacket Security Read the original article: Okta says its support system was breached using stolen credentials
Cisco discloses new IOS XE zero-day exploited to deploy malware implant
Cisco disclosed a new high-severity zero-day (CVE-2023-20273) today, actively exploited to deploy malicious implants on… This article has been indexed from RedPacket Security Read the original article: Cisco discloses new IOS XE zero-day exploited to deploy malware implant
Kwik Trip finally confirms cyberattack was behind ongoing outage
Two weeks into an ongoing IT outage, Kwik Trip finally confirmed that it’s investigating a… This article has been indexed from RedPacket Security Read the original article: Kwik Trip finally confirms cyberattack was behind ongoing outage
Fake Corsair job offers on LinkedIn push DarkGate malware
A threat actor is using fake LinkedIn posts and direct messages about a Facebook Ads… This article has been indexed from RedPacket Security Read the original article: Fake Corsair job offers on LinkedIn push DarkGate malware
Sphero – 832,255 breached accounts
In September 2023, over 1M rows of data from the educational robots company Sphero was… This article has been indexed from RedPacket Security Read the original article: Sphero – 832,255 breached accounts
Play Ransomware Victim: Tru-val Electric
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Play Ransomware Victim: Tru-val Electric
Play Ransomware Victim: Kobi Karp Architecture and Interior Design
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Play Ransomware Victim: Kobi Karp Architecture and Interior Design
Play Ransomware Victim: Bridgeport Fittings
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Play Ransomware Victim: Bridgeport Fittings
Play Ransomware Victim: Williamson Foodservice
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Play Ransomware Victim: Williamson Foodservice
Play Ransomware Victim: Epaccsys
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Play Ransomware Victim: Epaccsys
Akira Ransomware Victim: Southland Integrated Services
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Akira Ransomware Victim: Southland Integrated Services
Akira Ransomware Victim: Visionary Integratio n Professionals
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Akira Ransomware Victim: Visionary Integratio n Professionals
Akira Ransomware Victim: Protector Fire Servi ces
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Akira Ransomware Victim: Protector Fire Servi ces
Akira Ransomware Victim: Inventum Øst
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Akira Ransomware Victim: Inventum Øst
Akira Ransomware Victim: QuadraNet Enterprise s
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Akira Ransomware Victim: QuadraNet Enterprise s
LockBit 3.0 Ransomware Victim: nirolaw[.]com
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: nirolaw[.]com
Funnelforms Free Plugin for WordPress cross-site scripting | CVE-2023-4950
NAME__________Funnelforms Free Plugin for WordPress cross-site scripting Platforms Affected:WordPress Funnelforms Free Plugin for WordPress 3.3… This article has been indexed from RedPacket Security Read the original article: Funnelforms Free Plugin for WordPress cross-site scripting | CVE-2023-4950
Discourse denial of service | CVE-2023-44388
NAME__________Discourse denial of service Platforms Affected:Discourse Discourse 3.1.0.beta6 Discourse Discourse 3.1.0 Discourse Discourse 3.1.1 Discourse… This article has been indexed from RedPacket Security Read the original article: Discourse denial of service | CVE-2023-44388
Engelsystem weak security | CVE-2023-45659
NAME__________Engelsystem weak security Platforms Affected:Engelsystem Engelsystem Risk Level:3.6 Exploitability:Unproven Consequences:Gain Access DESCRIPTION__________ Engelsystem could provide… This article has been indexed from RedPacket Security Read the original article: Engelsystem weak security | CVE-2023-45659
Nextcloud Server and Enterprise Server information disclosure | CVE-2023-45151
NAME__________Nextcloud Server and Enterprise Server information disclosure Platforms Affected:Nextcloud Nextcloud Server 25.0.0 Nextcloud Nextcloud Enterprise… This article has been indexed from RedPacket Security Read the original article: Nextcloud Server and Enterprise Server information disclosure | CVE-2023-45151
Fiber cross-site request forgery | CVE-2023-45128
NAME__________Fiber cross-site request forgery Platforms Affected:Fiber Fiber 2.49.2 Risk Level:7.6 Exploitability:Unproven Consequences:Gain Access DESCRIPTION__________ Fiber… This article has been indexed from RedPacket Security Read the original article: Fiber cross-site request forgery | CVE-2023-45128
Knight Ransomware Victim: Benefit Management
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Knight Ransomware Victim: Benefit Management
BlackCat ransomware uses new ‘Munchkin’ Linux VM in stealthy attacks
The BlackCat/ALPHV ransomware operation has begun to use a new tool named ‘Munchkin’ that utilizes… This article has been indexed from RedPacket Security Read the original article: BlackCat ransomware uses new ‘Munchkin’ Linux VM in stealthy attacks
India targets Microsoft, Amazon tech support scammers in nationwide crackdown
India’s Central Bureau of Investigation (CBI) raided 76 locations in a nationwide crackdown on cybercrime… This article has been indexed from RedPacket Security Read the original article: India targets Microsoft, Amazon tech support scammers in nationwide crackdown
Casio discloses data breach impacting customers in 149 countries
Japanese electronics manufacturer Casio disclosed a data breach impacting customers from 149 countries after hackers… This article has been indexed from RedPacket Security Read the original article: Casio discloses data breach impacting customers in 149 countries
Iranian hackers lurked in Middle Eastern govt network for 8 months
The Iranian hacking group tracked as OilRig (APT34) breached at least twelve computers belonging to… This article has been indexed from RedPacket Security Read the original article: Iranian hackers lurked in Middle Eastern govt network for 8 months
Ragnar Locker ransomware’s dark web extortion sites seized by police
The Ragnar Locker ransomware operation’s Tor negotiation and data leak sites were seized Thursday morning… This article has been indexed from RedPacket Security Read the original article: Ragnar Locker ransomware’s dark web extortion sites seized by police
Play Ransomware Victim: Associated Wholesale Grocers
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Play Ransomware Victim: Associated Wholesale Grocers
US-CERT Vulnerability Summary for the Week of October 9, 2023
Bulletins provide weekly summaries of new vulnerabilities. Patch information is provided when available. This article has been indexed from RedPacket Security Read the original article: US-CERT Vulnerability Summary for the Week of October 9, 2023
HackerOne Bug Bounty Disclosure: b-deny-admin-from-editing-linkedin-company-page-using-gen-form-visibility-via-post-voyager-api-voyagerorganizationdashcompanies-id-b-domg
Company Name: b’LinkedIn’ Company HackerOne URL: https://hackerone.com/linkedin Submitted By:b’domg’ Link to Submitters Profile:https://hackerone.com/b’domg’ Report Title:b’Deny… This article has been indexed from RedPacket Security Read the original article: HackerOne Bug Bounty Disclosure: b-deny-admin-from-editing-linkedin-company-page-using-gen-form-visibility-via-post-voyager-api-voyagerorganizationdashcompanies-id-b-domg
HackerOne Bug Bounty Disclosure: b-responsive-server-side-request-forgery-ssrf-b-bhmth
Company Name: b’Nextcloud’ Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b’bhmth’ Link to Submitters Profile:https://hackerone.com/b’bhmth’ Report Title:b’Responsive… This article has been indexed from RedPacket Security Read the original article: HackerOne Bug Bounty Disclosure: b-responsive-server-side-request-forgery-ssrf-b-bhmth
Clever malvertising attack uses Punycode to look like KeePass’s official website
Threat actors are known for impersonating popular brands in order to trick users. In a recent… This article has been indexed from RedPacket Security Read the original article: Clever malvertising attack uses Punycode to look like KeePass’s official website
LockBit 3.0 Ransomware Victim: salaw[.]com
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: salaw[.]com
LockBit 3.0 Ransomware Victim: thecsi[.]com
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: thecsi[.]com
LockBit 3.0 Ransomware Victim: smart-union[.]org
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: smart-union[.]org
LockBit 3.0 Ransomware Victim: frs-fnrs[.]be
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: frs-fnrs[.]be
LockBit 3.0 Ransomware Victim: fdf[.]org
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: fdf[.]org
WebAuthn4J Spring Security security bypass | CVE-2023-45669
NAME__________WebAuthn4J Spring Security security bypass Platforms Affected:WebAuthn4J Spring Security 0.9.0.RELEASE Risk Level:4.8 Exploitability:Unproven Consequences:Bypass Security… This article has been indexed from RedPacket Security Read the original article: WebAuthn4J Spring Security security bypass | CVE-2023-45669
QNAP QTS, QuTS hero, and QuTScloud directory traversal | CVE-2023-32974
NAME__________QNAP QTS, QuTS hero, and QuTScloud directory traversal Platforms Affected:QNAP QuTS hero h5.1.0 QNAP QTS… This article has been indexed from RedPacket Security Read the original article: QNAP QTS, QuTS hero, and QuTScloud directory traversal | CVE-2023-32974
Who Hit The Page – Hit Counter plugin for WordPress cross-site scripting | CVE-2023-46066
NAME__________Who Hit The Page – Hit Counter plugin for WordPress cross-site scripting Platforms Affected:WordPress Mediabay… This article has been indexed from RedPacket Security Read the original article: Who Hit The Page – Hit Counter plugin for WordPress cross-site scripting |…
XnSoft NConvert for Windows denial of service | CVE-2023-43251
NAME__________XnSoft NConvert for Windows denial of service Platforms Affected:XnSoft NConvert for Windows 7.154 XnSoft NConvert… This article has been indexed from RedPacket Security Read the original article: XnSoft NConvert for Windows denial of service | CVE-2023-43251
Zephyr buffer overflow | CVE-2023-4263
NAME__________Zephyr buffer overflow Platforms Affected:Zephyr Project Zephyr 3.4.0 Risk Level:7.6 Exploitability:Unproven Consequences:Gain Access DESCRIPTION__________ Zephyr… This article has been indexed from RedPacket Security Read the original article: Zephyr buffer overflow | CVE-2023-4263
Knight Ransomware Victim: National Health Mission[.] Department of Health & Family Welfare, Govt[.] of U[.]P
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Knight Ransomware Victim: National Health Mission[.] Department of Health & Family Welfare, Govt[.]…
Google links WinRAR exploitation to Russian, Chinese state hackers
Google says that several state-backed hacking groups have joined ongoing attacks exploiting a high-severity vulnerability in WinRAR,… This article has been indexed from RedPacket Security Read the original article: Google links WinRAR exploitation to Russian, Chinese state hackers
MATA malware framework exploits EDR in attacks on defense firms
An updated version of the MATA backdoor framework was spotted in attacks between August 2022… This article has been indexed from RedPacket Security Read the original article: MATA malware framework exploits EDR in attacks on defense firms
Recently patched Citrix NetScaler bug exploited as zero-day since August
A critical vulnerability tracked as CVE-2023-4966 in Citrix NetScaler ADC/Gateway devices has been actively exploited as… This article has been indexed from RedPacket Security Read the original article: Recently patched Citrix NetScaler bug exploited as zero-day since August
Qubitstrike attacks rootkit Jupyter Linux servers to steal credentials
Hackers are scanning for internet-exposed Jupyter Notebooks to breach servers and deploy a cocktail of… This article has been indexed from RedPacket Security Read the original article: Qubitstrike attacks rootkit Jupyter Linux servers to steal credentials
FBI warns of extortion groups targeting plastic surgery offices
Update October 18, 12:12 EDT: Added statement from the American Board of Plastic Surgery. The… This article has been indexed from RedPacket Security Read the original article: FBI warns of extortion groups targeting plastic surgery offices
HackerOne Bug Bounty Disclosure: b-html-injection-at-company-name-or-product-name-and-can-be-shown-on-contact-sales-form-b-domg
Company Name: b’LinkedIn’ Company HackerOne URL: https://hackerone.com/linkedin Submitted By:b’domg’ Link to Submitters Profile:https://hackerone.com/b’domg’ Report Title:b’HTML… This article has been indexed from RedPacket Security Read the original article: HackerOne Bug Bounty Disclosure: b-html-injection-at-company-name-or-product-name-and-can-be-shown-on-contact-sales-form-b-domg
HackerOne Bug Bounty Disclosure: b-hackers-two-email-disclosed-on-submission-at-hackerone-hactivity-b-rynexx
Company Name: b’HackerOne’ Company HackerOne URL: https://hackerone.com/security Submitted By:b’rynexx’ Link to Submitters Profile:https://hackerone.com/b’rynexx’ Report Title:b’Hackers… This article has been indexed from RedPacket Security Read the original article: HackerOne Bug Bounty Disclosure: b-hackers-two-email-disclosed-on-submission-at-hackerone-hactivity-b-rynexx
LockBit 3.0 Ransomware Victim: kasperekusaoptical[.]com
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: kasperekusaoptical[.]com
Node.js security bypass | CVE-2023-39331
NAME__________Node.js security bypass Platforms Affected:Node.js Node.js 20.0 Risk Level:7.5 Exploitability:Unproven Consequences:Bypass Security DESCRIPTION__________ Node.js could… This article has been indexed from RedPacket Security Read the original article: Node.js security bypass | CVE-2023-39331
Grafana privilege escalation | CVE-2023-4822
NAME__________Grafana privilege escalation Platforms Affected:Grafana Grafana Risk Level:6.7 Exploitability:Unproven Consequences:Gain Privileges DESCRIPTION__________ Grafana could allow… This article has been indexed from RedPacket Security Read the original article: Grafana privilege escalation | CVE-2023-4822
HP displays security bypass | CVE-2023-5449
NAME__________HP displays security bypass Platforms Affected:HP E22 G4 FHD Monitor 1.0.3.0 HP EliteDisplay E273m 27-inch… This article has been indexed from RedPacket Security Read the original article: HP displays security bypass | CVE-2023-5449
Extreme Networks Switch Engine (EXOS) directory traversal | CVE-2023-43121
NAME__________Extreme Networks Switch Engine (EXOS) directory traversal Platforms Affected:Extreme Networks Switch Engine (EXOS) 32.5.1.4 Extreme… This article has been indexed from RedPacket Security Read the original article: Extreme Networks Switch Engine (EXOS) directory traversal | CVE-2023-43121
OpenTelemetry OpenTelemetry-Go Contrib denial of service | CVE-2023-45142
NAME__________OpenTelemetry OpenTelemetry-Go Contrib denial of service Platforms Affected:OpenTelemetry OpenTelemetry-Go Contrib 0.43.0 Risk Level:7.5 Exploitability:Unproven Consequences:Denial… This article has been indexed from RedPacket Security Read the original article: OpenTelemetry OpenTelemetry-Go Contrib denial of service | CVE-2023-45142
Knight Ransomware Victim: US Claims Solutions
NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Knight Ransomware Victim: US Claims Solutions
Our new principles to help make cloud backups more resilient
Every month there are press reports of a global organisation experiencing a ransomware attack. In… This article has been indexed from RedPacket Security Read the original article: Our new principles to help make cloud backups more resilient
Amazon adds passkey support as new passwordless login option
Amazon has quietly added passkey support as a new passwordless login option for customers, offering… This article has been indexed from RedPacket Security Read the original article: Amazon adds passkey support as new passwordless login option
Over 40,000 admin portal accounts use ‘admin’ as a password
Security researchers found that IT administrators are using tens of thousands of weak passwords to… This article has been indexed from RedPacket Security Read the original article: Over 40,000 admin portal accounts use ‘admin’ as a password
Fighting off cyberattacks? Make sure user credentials aren’t compromised
As an IT professional, you know that threat actors work overtime to get your end-users’… This article has been indexed from RedPacket Security Read the original article: Fighting off cyberattacks? Make sure user credentials aren’t compromised
SpyNote Android malware spreads via fake volcano eruption alerts
The Android ‘SpyNote’ malware was observed in attacks targeting Italy using a fake ‘IT-alert’ public… This article has been indexed from RedPacket Security Read the original article: SpyNote Android malware spreads via fake volcano eruption alerts
Over 10,000 Cisco devices hacked in IOS XE zero-day attacks
Update October 17, 16:40 EDT: Added new information on breached Cisco IOS XE devices. Attackers… This article has been indexed from RedPacket Security Read the original article: Over 10,000 Cisco devices hacked in IOS XE zero-day attacks
AndroidLista – 6,640,643 breached accounts
In July 2021, the Android applications and games review site AndroidLista suffered a data breach…. This article has been indexed from RedPacket Security Read the original article: AndroidLista – 6,640,643 breached accounts