Security
Headlines
HeadlinesLatestCVEs

Tag

#mac

Dark Pink APT Group Targets Governments and Military in APAC Region

Government and military organizations in the Asia Pacific region are being targeted by a previously unknown advanced persistent threat (APT) actor, per the latest research. Singapore-headquartered Group-IB, in a report shared with The Hacker News, said it's tracking the ongoing campaign under the name Dark Pink and attributed seven successful attacks to the adversarial collective between June

The Hacker News
#web#mac#git#c++#The Hacker News
Open redirect on government website sends users to adult content

Categories: News Tags: open redirect Tags: UKGOV Tags: website Tags: fix Tags: onlyfans Tags: porn Tags: pornography Tags: dating Tags: cheating Tags: phishing We take a look at reports an open redirect on a UKGOV site which took a little while to address. (Read more...) The post Open redirect on government website sends users to adult content appeared first on Malwarebytes Labs.

CVE-2022-48253

nhttpd in Nostromo before 2.1 is vulnerable to a path traversal that may allow an attacker to execute arbitrary commands on the remote server. The vulnerability occurs when the homedirs option is used.

5 must-haves for K-12 cybersecurity

Categories: Business Over the years, cyberattacks on K-12 schools and districts have steadily increased and in 2022 that trend only continued. In this post, we’ll look at the 5 must-haves for K-12 cybersecurity. (Read more...) The post 5 must-haves for K-12 cybersecurity appeared first on Malwarebytes Labs.

CVE-2022-48252: Remote Code Execution via OS Command Injection

The jokob-sk/Pi.Alert fork (before 22.12.20) of Pi.Alert allows Remote Code Execution via nmap_scan.php (scan parameter) OS Command Injection.

Intel's New Xeon Chip Pushes Confidential Computing to the Cloud

After a delay of more than a year, Intel's on-chip confidential computing feature is coming to all the major cloud providers, starting with Microsoft's Azure.

OpenSSL: From FIPS 140-2 upstream to 140-3 downstream

<h3>Red Hat Enterprise Linux 9.0 and OpenSSL 3.0</h3> <p>During the development of Red Hat Enterprise Linux (RHEL) 9, we decided to switch to OpenSSL 3.0 even though we were not sure that it would be finalized early enough. This decision was made to significantly reduce our maintenance burden during the 10+ years of RHEL 9 support.</p> <p>One of the anticipated changes in OpenSSL 3.0 was the new provider model. The provider that we were particularly interested in was the one implementing Federal Information Processing

Alleged Insider Access to Telegram Servers Sold on the Dark Web

By Waqas The alleged access is being sold for a whopping $20,000. This is a post from HackRead.com Read the original post: Alleged Insider Access to Telegram Servers Sold on the Dark Web

CVE-2022-4382: security - Re: Linux Kernel: usb: A use-after-free Write in put_dev

A use-after-free flaw caused by a race among the superblock operations in the gadgetfs Linux driver was found. It could be triggered by yanking out a device that is running the gadgetfs side.