DSA-5301 firefox-esr – security update
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or information disclosure....
Trojan-Dropper.Win32.Decay.dxv (CyberGate v1.00.0) / Insecure Proprietary Password Encryption
Posted by malvuln on Dec 13 Discovery / credits: Malvuln (John Page aka hyp3rlinx) (c) 2022 Original source: https://malvuln.com/advisory/618f28253d1268132a9f10819a6947f2.txt Contact: malvuln13 () gmail com Media:...
Re: CyberDanube Security Research 20221009-0 | Authenticated Command Injection in Intelbras WiFiber 120AC inMesh
Posted by Thomas Weber on Dec 13 CyberDanube Security Research 20221009-0 ------------------------------------------------------------------------------- title| Authenticated Command Injection product| Intelbras WiFiber 120AC inMesh vulnerable...
SEC Consult SA-20221213-0 :: Privilege Escalation Vulnerabilities (UNIX Insecure File Handling) in SAP Host Agent (saposcol)
Posted by SEC Consult Vulnerability Lab, Research via Fulldisclosure on Dec 13 SEC Consult Vulnerability Lab Security Advisory < 20221213-0 > ======================================================================= title: Privilege Escalation...
Vulnerabilities Disclosure – Shoplazza Stored XSS
Posted by Andrey Stoykov on Dec 13 # Exploit Title: Shoplazza 1.1 - Stored Cross Site Scripting # Exploit Author: Andrey Stoykov # Software Link:...
Multiple Vulnerabilities in VMware vRealize Network Insight (vRNI) Could Allow for Arbitrary Code Execution
Multiple vulnerabilities have been discovered in VMware vRealize Network Insight (vRNI), the most severe of which could result in arbitrary code execution. VMware vRealize Network...
Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution
Multiple vulnerabilities have been discovered in Mozilla Firefox, Firefox Extended Support Release (ESR) and Mozilla Thunderbird, the most severe of which could allow for arbitrary...
IPS Spike Observed in “TP-Link.Tapo.C200.IP.Camera.Command.Injection”
On December 11th, 2022, FortiGuard Labs observed a significant spike in IPS signature "TP-Link.Tapo.C200.IP.Camera.Command.Injection". The IPS signature is for CVE-2021-4045 and detects an attack to...
Cobalt Mirage Affiliate Deployed Drokbk Malware
FortiGuard Labs is aware of a report that the "Cluster B" group who is an alleged affiliate to the Iranian threat actor "Cobalt Mirage" deployed...
New Wiper Malware “Fantasy” Used in Supply-Chain Attack
FortiGuard Labs is aware of a report that a new wiper malware "Fantasy" that was deployed by potentially leveraging an unidentified software commonly used in...