Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

Cryptocurrency Companies Targeted in Sophisticated 3CX Supply Chain Attack

The adversary behind the supply chain attack targeting 3CX deployed a second-stage implant specifically singling out a small number of cryptocurrency companies. Russian cybersecurity firm Kaspersky, which has been internally tracking the versatile backdoor under the name Gopuram since 2020, said it observed an increase in the number of infections in March 2023 coinciding with the 3CX breach.

The Hacker News
#vulnerability#web#mac#windows#apple#microsoft#git#backdoor#perl#The Hacker News
CVE-2023-26855: Weak Salt Implementation · Issue #6449 · ChurchCRM/CRM

The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed hash tables or dictionary attacks to crack the hashed passwords.

CVE-2023-0614: Samba - Security Announcement Archive

The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.

3CX Breach Widens as Cyberattackers Drop Second-Stage Backdoor

"Gopuram" is a backdoor that North Korea's Lazarus Group has used in some campaigns dating back to 2020, some researchers say.

Online Pizza Ordering 1.0 Shell Upload

Online Pizza Ordering version 1.0 suffers from a remote shell upload vulnerability.

GLPI Activity Local File Inclusion

GLPI Activity versions prior to 3.1.0 suffer from a local file inclusion vulnerability.

GLPI Manageentities Local File Inclusion

GLPI Manageentities versions prior to 4.0.2 suffer from a local file inclusion vulnerability.

SQL Monitor 12.1.31.893 Cross Site Scripting

SQL Monitor version 12.1.31.893 suffers from a cross site scripting vulnerability.

Grand Theft Auto III Vice City Skin File 1.1 Buffer Overflow

Grand Theft Auto III with Vice City Skin File version 1.1 suffers from a buffer overflow vulnerability.