Tag
#chrome
H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via CMD parameter at /goform/aspForm.
The supply chain attack targeting 3CX was the result of a prior supply chain compromise associated with a different company, demonstrating a new level of sophistication with North Korean threat actors. Google-owned Mandiant, which is tracking the attack event under the moniker UNC4736, said the incident marks the first time it has seen a "software supply chain attack lead to another software
Categories: News Tags: chrome Tags: browser Tags: update Tags: vulnerability Tags: CVE Tags: exploit Tags: exploitation Tags: zero-day Users of Chrome should ensure they're running the latest version to patch an integer overflow in the Skia graphics library. (Read more...) The post Update now, there's a Chrome zero-day in the wild appeared first on Malwarebytes Labs.
Mandiant found that North Korea's UNC4736 gained initial access on 3CX's network when an employee downloaded a weaponized but legitimately-signed app from Trading Technologies.
Overcoming the limitations of consumer MFA with a new flavor of passwordless.
Chitor-CMS version 1.1.2 suffers from a remote SQL injection vulnerability.
ProjeQtOr Project Management System version 10.3.2 suffers from a remote shell upload vulnerability.
Piwigo version 13.6.0 suffers from a persistent cross site scripting vulnerability.
Swagger UI version 4.1.3 user interface misrepresentation of information proof of concept exploit.
Serendipity version 2.4.0 suffers from a cross site scripting vulnerability.