access?
-
A critical vulnerability in SolarWinds’ Web Help Desk software (CVE-2024-28989) allowed attackers to decrypt sensitive credentials, including database passwords and LDAP/SMTP authentication secrets, through cryptographic weaknesses in its AES-GCM implementation. Patched in version 12.8.5, the flaw stemmed from predictable encryption keys and nonce reuse, enabling practical decryption of stored secrets even without direct system access.…
-
A vulnerability was found in Microsoft Access. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to use after free. This vulnerability was named CVE-2025-26630. The attack can be initiated remotely. There is no exploit available. It is recommended to apply a patch to fix this issue.
-
A vulnerability was found in Microsoft Windows 11 22H2/11 23H2/11 24H2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Cross Device Service. The manipulation leads to improper access controls. This vulnerability is known as CVE-2025-24994. The attack needs to be approached locally. There is no exploit…
-
A vulnerability, which was classified as critical, was found in Apple macOS up to 14.x. Affected is an unknown function of the component Removable Volume Handler. The manipulation leads to improper access controls. This vulnerability is traded as CVE-2024-54463. It is possible to launch the attack on the local host. There is no exploit available.…
-
A vulnerability was found in Pluggabl Booster Elite for WooCommerce Plugin up to 7.1.2 on WordPress. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper access controls. The identification of this vulnerability is CVE-2023-51511. The attack may be initiated remotely. There is no exploit available. It is…
-
Physical penetration testing provides crucial insights into real-world security vulnerabilities that might be overlooked in purely digital assessments. A recent case study conducted by Hackmosphere for a furniture retailer, referred to as ExCorp, revealed how physical access to facilities could compromise internal networks despite robust cybersecurity measures. The penetration test identified four critical vulnerabilities that…
-
Threat hunters have shed light on a “sophisticated and evolving malware toolkit” called Ragnar Loader that’s used by various cybercrime and ransomware groups like Ragnar Locker (aka Monstrous Mantis), FIN7, FIN8, and Ruthless Mantis (ex-REvil). “Ragnar Loader plays a key role in keeping access to compromised systems, helping attackers stay in networks for long-term operations,”…
-
arXiv:2503.04259v1 Announce Type: new Abstract: The European General Data Protection Regulation (GDPR) grants European users the right to access their data processed and stored by organizations. Although the GDPR contains requirements for data processing organizations (e.g., understandable data provided within a month), it leaves much flexibility. In-depth research on how online services handle data subject…
-
A vulnerability was found in Mirotalk. It has been declared as problematic. Affected by this vulnerability is the function roomAction. The manipulation leads to improper access controls. This vulnerability is known as CVE-2024-44734. The attack can only be done within the local network. There is no exploit available. It is recommended to apply a patch…
-
Cisco Systems has disclosed a security vulnerability in its Webex for BroadWorks unified communications platform that could allow attackers to intercept sensitive credentials and user data under specific configurations. The flaw, tracked as CSCwo20742 and classified as a low-severity issue, impacts organizations using Release 45.2 of the software in Windows-based environments, prompting Cisco to release configuration-based fixes and recommend…
-
Specops Software has launched Specops Secure Access, a new capability that provides multi-factor authentication (MFA) to Windows logon, Remote Desktop Protocol (RDP), and VPN connections. This new innovation adds a layer of security to on-premises or hybrid Active Directory environments, strengthening protection against unauthorized access and credential-based attacks. Password-based threats are on the rise. Specops…
-
arXiv:2503.02019v1 Announce Type: new Abstract: The rapid advancements in wireless technology have significantly increased the demand for communication resources, leading to the development of Spectrum Access Systems (SAS). However, network regulations require disclosing sensitive user information, such as location coordinates and transmission details, raising critical privacy concerns. Moreover, as a database-driven architecture reliant on user-provided…
-
A vulnerability classified as critical was found in Google Android. Affected by this vulnerability is an unknown functionality of the component Kernel File System. The manipulation leads to improper access controls. This vulnerability is known as CVE-2017-13165. Local access is required to approach this attack. There is no exploit available. It is recommended to apply…
-
Security researchers from Unit 42 have uncovered an advanced phishing campaign orchestrated by the JavaGhost threat actor group. The post JavaGhost’s Persistent Phishing Attacks: Exploiting Cloud Environments for Long-Term Access appeared first on Cybersecurity News.
-
A vulnerability, which was classified as critical, has been found in Red Hat OpenStack 4.0. This issue affects some unknown processing of the component Access Restriction. The manipulation leads to improper access controls. The identification of this vulnerability is CVE-2014-0071. The attack may be initiated remotely. There is no exploit available.
-
A vulnerability was found in ImageMagick and classified as critical. This issue affects some unknown processing of the file coders/xpm.c of the component XPM File Handler. The manipulation leads to improper access controls. The identification of this vulnerability is CVE-2014-9827. The attack may be initiated remotely. There is no exploit available.
-
A vulnerability was found in HYPR Workforce Access up to 8.7.0 on macOS. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to link following. This vulnerability was named CVE-2024-0068. Attacking locally is a requirement. There is no exploit available. It is recommended to upgrade the affected component.