Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

Hackers Using Golang Variant of Cobalt Strike to Target Apple macOS Systems

A Golang implementation of Cobalt Strike called Geacon is likely to garner the attention of threat actors looking to target Apple macOS systems. The findings come from SentinelOne, which observed an uptick in the number of Geacon payloads appearing on VirusTotal in recent months. "While some of these are likely red-team operations, others bear the characteristics of genuine malicious attacks,"

The Hacker News
#web#mac#windows#apple#microsoft#linux#git#intel#backdoor#pdf#The Hacker News
Windows 11 is showing its first signs of Rust

Categories: News Tags: Windows 11 Tags: OS Tags: operating system Tags: programming language Tags: rust Tags: C Tags: C++ Tags: kernel Tags: buffer overflow We take a look at the slow introduction of programming language Rust into the Windows 11 kernel in an effort to make it more memory safe. (Read more...) The post Windows 11 is showing its first signs of Rust appeared first on Malwarebytes Labs.

CVE-2023-30245: cve_report/SQLi-1.md at main · qingning988/cve_report

SQL injection vulnerability found in Judging Management System v.1.0 allows a remote attacker to execute arbitrary code via the crit_id parameter of the edit_criteria.php file.

RockMongo 1.1.7 Cross Site Scripting

RockMongo version 1.1.7 suffers from a persistent cross site scripting vulnerability.

TinyWebGallery 2.5 Cross Site Scripting

TinyWebGallery version 2.5 suffers from a persistent cross site scripting vulnerability.

Epson Stylus SX510W Denial Of Service

Epson Stylus SX510W suffers from a power off denial of service vulnerability.

Siemens SIMATIC S7-1200 Cross Site Request Forgery

Siemens SIMATIC S7-1200 CPU start/stop command cross site request forgery exploit. This older issue elaborates on t4rkd3vilz's CVE-2015-5698 by issuing a POST command to a specified web server path.

Online Clinic Management System 2.2 Cross Site Scripting

Online Clinic Management System version 2.2 suffers from multiple persistent cross site scripting vulnerabilities.

Microsoft Advisories Are Getting Worse

A predictable patch cadence is nice, but the software giant can do more.

CVE-2023-31845: bug_report/SQLi-4.md at main · acmglz/bug_report

Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_class.php?id=.