Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

CVE-2023-35362

Windows Clip Service Elevation of Privilege Vulnerability

CVE
#vulnerability#windows
CVE-2023-36868

Azure Service Fabric on Windows Information Disclosure Vulnerability

CVE-2023-36874

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVE-2023-32049

Windows SmartScreen Security Feature Bypass Vulnerability

Undocumented driver-based browser hijacker RedDriver targets Chinese speakers and internet cafes

Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic.

Old certificate, new signature: Open-source tools forge signature timestamps on Windows drivers

Actors are leveraging multiple open-source tools that alter the signing date of kernel mode drivers to load malicious and unverified drivers signed with expired certificates.

Hackers Exploit Windows Policy Loophole to Forge Kernel-Mode Driver Signatures

A Microsoft Windows policy loophole has been observed being exploited primarily by native Chinese-speaking threat actors to forge signatures on kernel-mode drivers. "Actors are leveraging multiple open-source tools that alter the signing date of kernel mode drivers to load malicious and unverified drivers signed with expired certificates," Cisco Talos said in an exhaustive two-part report shared

Mastery LMS 1.2 Cross Site Scripting

Mastery LMS version 1.2 suffers from a cross site scripting vulnerability.

Academy LMS 5.15 Cross Site Scripting

Academy LMS version 5.15 suffers from a cross site scripting vulnerability.

Atlas Business Directory Listing 2.13 Cross Site Scripting

Atlas Business Directory Listing version 2.13 suffers from cross site scripting vulnerabilities.