Aggregator
Submit #396110: itsourcecode Payroll Management System V1.0 SQL Injection [Accepted]
Prism Infosec PULSE bridges the gap between penetration testing and red teaming
Prism Infosec launched its innovative PULSE testing service to enable organizations which may not have the bandwidth or resource to dedicate to a full-scale red team exercise to assess their defence capabilities against real-world threats. PULSE addresses the gap that currently exists between penetration testing and red teaming which can prevent organisations from gaining an accurate understanding of their security posture and provides an agile alternative that utilises an intensive testing approach. Penetration tests are … More →
The post Prism Infosec PULSE bridges the gap between penetration testing and red teaming appeared first on Help Net Security.
Company Fined $1m for Fake Joe Biden AI Calls
Submit #395465: sourcecodester Online Health Care System in PHP with Full Source Code v1.0 SQL Injection [Accepted]
CVE-2024-8079 | TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 exportOvpn buffer overflow
CVE-2024-8078 | TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 setTracerouteCfg buffer overflow
CVE-2024-8077 | TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 setTracerouteCfg os command injection
CVE-2024-8076 | TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 setDiagnosisCfg buffer overflow
CVE-2024-8075 | TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 setDiagnosisCfg os command injection
Submit #390937: TOTOLINK AC1200 T8 V4.1.5cu.862_B20230228 Buffer Overflow [Accepted]
Submit #390929: TOTOLINK AC1200 T8 V4.1.5cu.862_B20230228 OS Command Injection [Accepted]
Фишинг-тест вызвал массовую панику в Университете США
CVE-2024-43331 | VeronaLabs WP SMS Plugin up to 6.9.3 on WordPress authorization
CVE-2024-39745 | IBM Sterling Connect Direct Web Services 6.0/6.1/6.2/6.3 risky encryption (XFDB-297312)
CVE-2024-39744 | IBM Sterling Connect Direct Web Services 6.0/6.1/6.2/6.3 cross-site request forgery (XFDB-297236)
CVE-2024-6800: GitHub устранил критическую уязвимость в Enterprise Server
攻防过半:最能打的竟然不是0day?
Best practices for event logging and threat detection
CISA Releases Five Industrial Control Systems Advisories
CISA released five Industrial Control Systems (ICS) advisories on August 22, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
- ICSA-24-235-01 Rockwell Automation Emulate3D
- ICSA-24-235-02 Rockwell Automation 5015 – AENFTXT
- ICSA-24-235-03 MOBOTIX P3 and Mx6 Cameras
- ICSA-24-235-04 Avtec Outpost 0810
- ICSA-20-282-02 Mitsubishi Electric MELSEC iQ-R Series (Update D)
CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations.