Security
Headlines
HeadlinesLatestCVEs

Tag

#auth

Sloppy Entra ID Credentials Attract Hybrid Cloud Ransomware

Microsoft warns that ransomware group Storm-0501 has shifted from buying initial access to leveraging weak credentials to gain on-premises access before moving laterally to the cloud.

DARKReading
#vulnerability#web#microsoft#intel#backdoor#auth
Debian Security Advisory 5778-1

Debian Linux Security Advisory 5778-1 - Simone Margaritelli reported several vulnerabilities in cups-filters. Missing validation of IPP attributes returned from an IPP server and multiple bugs in the cups-browsed component can result in the execution of arbitrary commands without authentication when a print job is started.

VegaBird Vooki 5.2.9 DLL Hijacking

VegaBird Vooki version 5.2.9 suffers from a dll hijacking vulnerability.

VegaBird Yaazhini 2.0.2 DLL Hijacking

VegaBird Yaazhini version 2.0.2 suffers from a dll hijacking vulnerability.

Debian Security Advisory 5777-1

Debian Linux Security Advisory 5777-1 - It was discovered that the Booth cluster ticket manager failed to correctly validate some authentication hashes.

Debian Security Advisory 5776-1

Debian Linux Security Advisory 5776-1 - Albert Cervera discovered two missing authorisation checks in the Tryton application platform.

Elaborate Deepfake Operation Takes a Meeting With US Senator

The threat actors managed to gain access to Sen. Ben Cardin (D-Md.) by posing as a Ukrainian official, before quickly being outed.

Treat Your Enterprise Data Like a Digital Nomad

By combining agility with compliance, and security with accessibility, businesses will treat their data as a well-prepared traveler, ready for any adventure.

Student Enrollment 1.0 Arbitrary File Upload

Student Enrollment version 1.0 suffers from an arbitrary file upload vulnerability.