Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

Forum Fire Soft Board 0.3.0 Cross Site Scripting

Forum Fire Soft Board version 0.3.0 suffers from a cross site scripting vulnerability.

Packet Storm
#xss#vulnerability#windows#google#git#php#auth#firefox
Forma LMS 1.4 Database Disclosure

Forma LMS version 1.4 suffers from a database disclosure vulnerability.

Foodiee CMS 1.0.1 Insecure Direct Object Reference

Foodiee CMS version 1.0.1 suffers from an insecure direct object reference vulnerability.

Foodiee Online Food Ordering Web Application 1.0.0 Insecure Settings

Foodiee Online Food Ordering Web Application version 1.0.0 suffers from an ignored default credential vulnerability.

FlightPath LMS 4.8.2 Cross Site Scripting

FlightPath LMS version 4.8.2 suffers from a cross site scripting vulnerability.

FixBook Repair Shop Management Tool 3.0 Hash Disclosure

FixBook Repair Shop Management Tool version 3.0 suffers from an information leakage vulnerability.

DarkGate reloaded via malvertising and SEO poisoning campaigns

Categories: Threat Intelligence Tags: darkgate Tags: autoit Tags: malvertising Tags: seo poisoning The new version of the DarkGate malware is currently actively being distributed via malspam, malicious ads and SEO poisoning. (Read more...) The post DarkGate reloaded via malvertising and SEO poisoning campaigns appeared first on Malwarebytes Labs.

Syrian Threat Actor EVLF Unmasked as Creator of CypherRAT and CraxsRAT Android Malware

A Syrian threat actor named EVLF has been outed as the creator of malware families CypherRAT and CraxsRAT. "These RATs are designed to allow an attacker to remotely perform real-time actions and control the victim device's camera, location, and microphone," Cybersecurity firm Cyfirma said in a report published last week. CypherRAT and CraxsRAT are said to be offered to other cybercriminals as

Over a Dozen Malicious npm Packages Target Roblox Game Developers

More than a dozen malicious packages have been discovered on the npm package repository since the start of August 2023 with capabilities to deploy an open-source information stealer called Luna Token Grabber on systems belonging to Roblox developers. The ongoing campaign, first detected on August 1 by ReversingLabs, employs modules that masquerade as the legitimate package noblox.js, an API

CVE-2023-39026: FileMage Gateway LFI

Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component.