-
Week in review: Exploited Ivanti Connect Secure zero-day, Patch Tuesday forecast
Week in review: Exploited Ivanti Connect Secure zero-day, Patch Tuesday forecast Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Ivanti Connect Secure zero-day exploited by attackers (CVE-2025-0282) Ivanti has fixed two vulnerabili … Read more Published Date: Jan 12, 2025 (7 hours, 4 minutes ago) Vulnerabilities has been mentioned in…
-
CVE-2024-5594 impacts OpenVPN
CVE-2024-5594 impacts OpenVPN CVE-2024-5594 is a critical vulnerability identified in OpenVPN versions prior to 2.6.11. This vulnerability stems from improper sanitization of PUSH_REPLY messages, which allows attackers to inject u … Read more Published Date: Jan 12, 2025 (13 hours, 44 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2024-12847 CVE-2024-53704 CVE-2024-5594 CVE-2024-54677 CVE-2024-50379 CVE-2024-49415 Go…
-
CVE-2025-22777 (CVSS 9.8): Critical Security Alert for GiveWP Plugin with 100,000 Active Installations
CVE-2025-22777 (CVSS 9.8): Critical Security Alert for GiveWP Plugin with 100,000 Active Installations A severe vulnerability has been identified in the GiveWP plugin, one of WordPress’s most widely used tools for online donations and fundraising. Tracked as CVE-2025-22777, the flaw has a CVSS score of … Read more Published Date: Jan 12, 2025 (14 hours, 44 minutes…
-
Fake LDAPNightmware exploit on GitHub spreads infostealer malware
Fake LDAPNightmware exploit on GitHub spreads infostealer malware A deceptive proof-of-concept (PoC) exploit for CVE-2024-49113 (aka “LDAPNightmare”) on GitHub infects users with infostealer malware that exfiltrates sensitive data to an external FTP server. The tact … Read more Published Date: Jan 11, 2025 (1 day ago) Vulnerabilities has been mentioned in this article. CVE-2024-49113 CVE-2024-49112 Go…
-
CVE-2024-49415 : Samsung Android devices Impacted
CVE-2024-49415 : Samsung Android devices Impacted CVE-2024-49415 is a critical vulnerability found in Samsung devices running Android versions 12, 13, and 14. This vulnerability was discovered by researchers from Google Project Zero, a team dedicated … Read more Published Date: Jan 11, 2025 (1 day, 2 hours ago) Vulnerabilities has been mentioned in this article. CVE-2024-12847 CVE-2024-53704…
-
CVE-2024-53704 impacts SonicWall
CVE-2024-53704 impacts SonicWall CVE-2024-53704 is a high-severity vulnerability impacting SonicWall’s SSLVPN authentication mechanism. This flaw, with a CVSS score of 8.2, allows remote attackers to bypass authentication and gain un … Read more Published Date: Jan 11, 2025 (1 day, 4 hours ago) Vulnerabilities has been mentioned in this article. CVE-2024-12847 CVE-2024-53704 CVE-2024-51741 CVE-2024-46981 CVE-2024-54677 CVE-2024-50379 CVE-2024-38193…
-
2025-01-09: CVE-2017-0199 XLS –> HTA –> VBS –> steganography –> DBatLoader/GuiLoader style malware
2025-01-09: CVE-2017-0199 XLS –> HTA –> VBS –> steganography –> DBatLoader/GuiLoader style malware 2025-01-09 (THURSDAY): CVE-2017-0199 XLS –> HTA –> VBS –> STEGANOGRAPHY –> DBATLOADER/GUILOADER STYLE MALWARE NOTES: Zip files are password-protected. Of note, this site has a new password scheme … Read more Published Date: Jan 11, 2025 (1 day, 8 hours ago) Vulnerabilities has been…
-
CVE-2024-12847: Proof-of-Concept Exploit Code Released
CVE-2024-12847: Proof-of-Concept Exploit Code Released OverviewCVE-2024-12847 is a critical security vulnerability affecting certain models of NETGEAR routers, notably the DGN1000 and DGN2200 v1. This vulnerability has been assigned a CVSS score of 9.8, r … Read more Published Date: Jan 11, 2025 (1 day, 9 hours ago) Vulnerabilities has been mentioned in this article. CVE-2024-12847 CVE-2024-51741 CVE-2024-46981…
-
Reversing, Discovering, And Exploiting A TP-Link Router Vulnerability — CVE-2024–54887
Reversing, Discovering, And Exploiting A TP-Link Router Vulnerability — CVE-2024–54887 OverviewRecently, I picked up an interest in reverse engineering and exploit development. After a while, picking at Hack The Box challenges can get tired, and I started looking for a more interesting … Read more Published Date: Jan 11, 2025 (1 day, 10 hours ago) Vulnerabilities has been mentioned…
-
CVE-2024-12847 (CVSS 9.8): NETGEAR Router Flaw Exploited in the Wild for Years, PoC Published
CVE-2024-12847 (CVSS 9.8): NETGEAR Router Flaw Exploited in the Wild for Years, PoC Published A severe security vulnerability has been discovered in several Netgear routers, allowing remote attackers to gain unauthorized access and control over the devices. The vulnerability, identified as CVE … Read more Published Date: Jan 11, 2025 (1 day, 14 hours ago) Vulnerabilities has…