Security
Headlines
HeadlinesLatestCVEs

Tag

#google

Rail Pass Management System 1.0 Insecure Settings

Rail Pass Management System version 1.0 suffers from an ignored default credential vulnerability.

Packet Storm
#sql#vulnerability#windows#google#php#auth#firefox
PreSchool Enrollment System 1.0 Insecure Settings

PreSchool Enrollment System version 1.0 suffers from an ignored default credential vulnerability.

PHP SPM 1.0 Cross Site Request Forgery

PHP SPM version 1.0 suffers from a cross site request forgery vulnerability.

New Octo2 Android Banking Trojan Emerges with Device Takeover Capabilities

Cybersecurity researchers have discovered a new version of an Android banking trojan called Octo that comes with improved capabilities to conduct device takeover (DTO) and perform fraudulent transactions. The new version has been codenamed Octo2 by the malware author, Dutch security firm ThreatFabric said in a report shared with The Hacker News, adding campaigns distributing the malware have

Meet UNC1860: Iran's Low-Key Access Broker for State Hackers

The group has used more than 30 custom tools to target high-value government and telecommunications organizations on behalf of Iranian intelligence services, researchers say.

nullcon Goa 2025 Call For Papers

The Call For Papers for nullcon Goa 2025 is now open. Nullcon is an information security conference held in Goa, India. The focus of the conference is to showcase the next generation of offensive and defensive security technology. It will take place March 1st through the 2nd, 2025.

Ubuntu Security Notice USN-7028-1

Ubuntu Security Notice 7028-1 - It was discovered that the JFS file system contained an out-of-bounds read vulnerability when printing xattr debug information. A local attacker could use this to cause a denial of service. Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system.

Linux i915 PTE Use-After-Free

Linux i915 suffers from an out-of-bounds PTE write in vm_fault_gtt() that leads to a PTE use-after-free vulnerability.

Registration And Login System 1.0 SQL Injection

Registration and Login System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

SPIP BigUp 4.3.1 Code Injection

SPIP BigUp version 4.3.1 suffers from a remote PHP code injection vulnerability.