Threat actors, including at least one nation-state actor, are attempting to exploit the newly disclosed Log4j flaw to deploy ransomware, remote access Trojans, and...
By: Ravie Lakshmanan
Identity and access management provider Okta on Tuesday said it concluded its probe into the breach of a third-party vendor in late...
Jan 07, 2025Ravie LakshmananFirmware Security / Malware
Cybersecurity researchers have uncovered firmware security vulnerabilities in the Illumina iSeq 100 DNA sequencing instrument that, if successfully...
By:
Mar 23, 2023Ravie LakshmananCritical Infrastructure Security
Telecommunication providers in the Middle East are the subject of new cyber attacks that commenced in the first...
By: Tina Martin
Why You Need Cybersecurity to Protect Your Greatest Assets
When it comes to cybersecurity, you can never be too careful. After all, not...
By:
Dec 14, 2023NewsroomVulnerability / Data Breach
A previously unknown hacker outfit called GambleForce has been attributed to a series of SQL injection attacks against...
Authored by Guillaume Petit
Nxlog Community Edition version 2.10.2150 denial of service proof of concept exploit.
Change Mirror Download
# Exploit Title: Nxlog Community Edition 2.10.2150 -...
Authored by Skoll
Mars Stealer version 8.3 suffers from an account takeover vulnerability.
Change Mirror Download
# Exploit Title: Mars Stealer 8.3 - Admin Account Takeover# Product:...
The WordPress WP HTML Mail plugin for personalized emails is vulnerable to code injection and phishing due to XSS.
More than 20,000 WordPress sites are...
I Can Haz Domain Admin?
Active Directory security is notoriously difficult. Small organizations generally have no idea what they're doing, and way too many people...
domhttpx is a google search engine dorker with HTTP toolkit built with python, can make it easier for you to find many URLs/IPs at once with fast time.
Usage
Flags
This...
Sniffle is a sniffer for Bluetooth 5 and 4.x (LE) using TI CC1352/CC26x2 hardware.
Sniffle has a number of useful features, including:
Support for BT5/4.2 extended...
Modular brute force tool written in Python, for very fast password spraying SSH, and FTP and in the near future other network services.
COMING SOON: SMB,...
This project builds virtual machine which can be used for analytics of tshark -T ek (ndjson) output. The virtual appliance is built using vagrant, which builds...
Authored by h00die-gr3y | Site metasploit.com
The Acronis Cyber Protect appliance, in its default configuration, allows the anonymous registration of new protect/backup agents on new...
Authored by Stefan Viehboeck, Constantin Schieber-Knöbl | Site sec-consult.com
Various Siemens products suffer from vulnerabilities. There is an unlocked JTAG Interface for Zynq-7000 on SM-2558...
Authored by Daniel Hirschberger | Site sec-consult.com
Omada Identity versions prior to 15U1 and 14.14 hotfix #309 suffer from a persistent cross site scripting vulnerability.
advisories...