Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

CSC-CMS 1.0.0 SQL Injection

CSC-CMS version 1.0.0 suffers from a remote SQL injection vulnerability.

Packet Storm
#sql#vulnerability#windows#google#php#auth#firefox
CMS Genetics Centre 4.0.1 SQL Injection

CMS Genetics Centre version 4.0.1 suffers from a remote SQL injection vulnerability.

CMS BMGI International 4.0 Cross Site Scripting

CMS BMGI International version 4.0 suffers from a cross site scripting vulnerability.

Conference Management Software 3.5.1 SQL Injection

Conference Management Software version 3.5.1 suffers from a remote SQL injection vulnerability.

North Korean Hackers Targets Russian Missile Engineering Firm

Two different North Korean nation-state actors have been linked to a cyber intrusion against the major Russian missile engineering company NPO Mashinostroyeniya. Cybersecurity firm SentinelOne said it identified "two instances of North Korea related compromise of sensitive internal IT infrastructure," including a case of an email server compromise and the deployment of a Windows backdoor dubbed

Elite North Korean Hackers Breach Russian Missile Developer

By Waqas North Korean hackers from OpenCarrot and Lazarus breached NPO Mashinostroyeniya, a major Russian missile developer, for at least five months last year. This is a post from HackRead.com Read the original post: Elite North Korean Hackers Breach Russian Missile Developer

New threat actor targets Bulgaria, China, Vietnam and other countries with customized Yashma ransomware

Cisco Talos discovered an unknown threat actor, seemingly of Vietnamese origin, conducting a ransomware operation that began at least as early as June 4, 2023 with customized Yashma ransomware.

Microsoft Bug Bounty Program Year in Review: $13.8M in Rewards

We are thrilled to share the results of our collaboration with over 345 security researchers from +45 countries around the world in the past 12 months. Together, we have discovered and fixed more than a thousand potential security issues before they impacted our customers. In recognition of this valuable collaboration, we have awarded $13.

CVE-2022-48579: Updated to 6.2.3 · pmachapman/unrar@2ecab6b

UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains.