Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

FlightPath LMS 4.8.2 Insecure Direct Object Reference

FlightPath LMS version 4.8.2 suffers from an insecure direct object reference vulnerability.

Packet Storm
#vulnerability#windows#google#auth#firefox
FleetCart Laravel Ecommerce System 1.1.2 Insecure Settings

FleetCart Laravel Ecommerce System version 1.1.2 suffers from an ignored default credential vulnerability.

FixBook Repair Shop Management Tool 2.2 Hash Disclosure

FixBook Repair Shop Management Tool version 2.2 suffers from an information leakage vulnerability.

Update now! WinRAR files can be abused to run malware

Categories: Exploits and vulnerabilities Categories: News Tags: WinRAR Tags: CVE-2023-40477 Tags: RCE Tags: Windows 11 A new version of WinRAR is available that patches two vulnerabilities attackers could use for remote code execution. (Read more...) The post Update now! WinRAR files can be abused to run malware appeared first on Malwarebytes Labs.

New Supply Chain Attack Hit Close to 100 Victims—and Clues Point to China

The hackers, who mostly targeted victims in Hong Kong, also hijacked Microsoft’s trust model to make their malware harder to detect.

Trusted Advisor puts you in the security driving seat

Categories: Personal Malwarebytes' new Trusted Advisor makes security easy with a comprehensive, at-a-glance, real-time assessment. (Read more...) The post Trusted Advisor puts you in the security driving seat appeared first on Malwarebytes Labs.

New Variant of XLoader macOS Malware Disguised as 'OfficeNote' Productivity App

A new variant of an Apple macOS malware called XLoader has surfaced in the wild, masquerading its malicious features under the guise of an office productivity app called "OfficeNote." "The new version of XLoader is bundled inside a standard Apple disk image with the name OfficeNote.dmg," SentinelOne security researchers Dinesh Devadoss and Phil Stokes said in a Monday analysis. "The application

CVE-2023-4373: Devolutions

Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature.

CVE-2023-4417: Devolutions

Improper access controls in the entry duplication component in Devolutions Remote Desktop Manager 2023.2.19 and earlier versions on Windows allows an authenticated user, under specific circumstances, to inadvertently share their personal vault entry with shared vaults via an incorrect vault in the duplication write process.

Academy LMS 6.1 Cross Site Scripting / File Upload

Academy LMS version 6.1 suffers from an upload vulnerability that could lead to persistent cross site scripting attacks.