Security
Headlines
HeadlinesLatestCVEs

Latest News

VICIdial SQL Injection / Remote Code Execution

Proof of concept exploit that allows an attacker to retrieve administrative credentials through SQL injection and ultimately execute arbitrary code on the target server.

Packet Storm
#sql#rce
Rejetto HTTP File Server 2.3m Template Injection / Arbitrary Code Execution

Proof of concept remote code execution exploit for Rejetto HTTP File Server (HFS) version 2.3m.

Calibre 7.14.0 Remote Code Execution

Proof of concept unauthenticated remote code execution exploit for Calibre versions 7.14.0 and below.

Veeam Backup And Replication 12.1.2.172 Remote Code Execution

Veeam Backup and Replication version 12.1.2.172 unauthenticated remote code execution exploit.

Google Fixes GCP Composer Flaw That Could've Led to Remote Code Execution

A now-patched critical security flaw impacting Google Cloud Platform (GCP) Composer could have been exploited to achieve remote code execution on cloud servers by means of a supply chain attack technique called dependency confusion. The vulnerability has been codenamed CloudImposer by Tenable Research. "The vulnerability could have allowed an attacker to hijack an internal software dependency

Unleashing Worms And Extracting Data

Whitepaper called Unleashing Worms and Extracting Data: Escalating the Outcome of Attacks against RAG-based Inference in Scale and Severity Using Jailbreaking. In this paper, the authors show that with the ability to jailbreak a GenAI model, attackers can escalate the outcome of attacks against RAG-based GenAI-powered applications in severity and scale.

23andMe to pay $30 million in settlement over 2023 data breach

Genetic testing company 23andMe will pay $30 million over a 2023 data breach which ended in millions of customers having data exposed.

Debian Security Advisory 5769-1

Debian Linux Security Advisory 5769-1 - Multiple issues were found in Git, a fast, scalable, distributed revision control system, which may result in file overwrites outside the repository, arbitrary configuration injection or arbitrary code execution.

Red Hat Security Advisory 2024-6667-03

Red Hat Security Advisory 2024-6667-03 - Red Hat OpenShift Dev Spaces 3.16 has been released.