science and technology Best Buy Gift Cards, USB Drive Used To Spread Infostealer By packetstormsecurity.com Published On :: Sat, 28 Mar 2020 15:12:50 GMT Full Article headline malware fraud
science and technology UK Government Cracks Down On Fake Coronavirus News By packetstormsecurity.com Published On :: Mon, 30 Mar 2020 15:32:46 GMT Full Article headline government virus britain fraud
science and technology A Crypto-Mining Botnet Has Been Hijacking MSSQL Servers For Almost Two Years By packetstormsecurity.com Published On :: Wed, 01 Apr 2020 14:26:20 GMT Full Article headline hacker microsoft database fraud flaw cryptography
science and technology Millions Of Guests Impacted In Marriott Data Breach, Again By packetstormsecurity.com Published On :: Wed, 01 Apr 2020 14:26:34 GMT Full Article headline hacker privacy bank cybercrime data loss fraud
science and technology Microsoft Warns Hospitals About VPN Attacks During Coronavirus By packetstormsecurity.com Published On :: Thu, 02 Apr 2020 13:49:43 GMT Full Article headline hacker microsoft fraud cryptography
science and technology Cryptocurrency Issuers, Exchanges Face U.S. Class Action Lawsuits By packetstormsecurity.com Published On :: Mon, 06 Apr 2020 18:17:58 GMT Full Article headline bank fraud cryptography
science and technology Low-Orbit Internet Banking Fraud Claim Alleged To Be Space Junk By packetstormsecurity.com Published On :: Thu, 09 Apr 2020 14:33:35 GMT Full Article headline bank space fraud
science and technology Coronavirus: Facebook Alerts Users Exposed To Misinformation By packetstormsecurity.com Published On :: Thu, 16 Apr 2020 15:30:39 GMT Full Article headline virus fraud facebook social
science and technology Google Blocked 126 Million COVID-19 Phishing Scams In One Week By packetstormsecurity.com Published On :: Fri, 17 Apr 2020 15:22:41 GMT Full Article headline email virus cybercrime fraud google phish
science and technology PoetRAT Trojan Targets Energy Sector Using Coronavirus Lures By packetstormsecurity.com Published On :: Fri, 17 Apr 2020 15:22:51 GMT Full Article headline hacker email virus fraud phish scada
science and technology Hackers Steal $25 Million Worth Of Cryptocurrency From Uniswap And Lendf.me By packetstormsecurity.com Published On :: Mon, 20 Apr 2020 15:06:39 GMT Full Article headline hacker bank cybercrime data loss fraud cryptography
science and technology Nintendo Accounts Are Getting Hacked To Buy Fortnite Currency By packetstormsecurity.com Published On :: Tue, 21 Apr 2020 13:43:05 GMT Full Article headline hacker cybercrime fraud nintendo password
science and technology DForce Hacker Returns $25m In Stolen Cryptocurrency By packetstormsecurity.com Published On :: Tue, 21 Apr 2020 13:43:11 GMT Full Article headline hacker cybercrime fraud cryptography
science and technology Hackers Have Breached 60 Ad Servers To Load Their Own Malicious Ads By packetstormsecurity.com Published On :: Wed, 22 Apr 2020 15:05:11 GMT Full Article headline hacker malware fraud backdoor
science and technology ESET Takes Down VictoryGate Cryptomining Botnet By packetstormsecurity.com Published On :: Thu, 23 Apr 2020 19:15:16 GMT Full Article headline malware botnet fraud cryptography
science and technology Shade Threat Actors Call It Quits, Release 750k Encryption Keys By packetstormsecurity.com Published On :: Fri, 01 May 2020 13:36:53 GMT Full Article headline hacker malware cybercrime fraud password cryptography
science and technology Hackers Target Remote Workers With Fake Zoom Downloader By packetstormsecurity.com Published On :: Mon, 04 May 2020 15:37:16 GMT Full Article headline hacker privacy malware fraud
science and technology Scam Coronavirus Sites Selling Fake Cures Taken Down By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:14:04 GMT Full Article headline virus cybercrime fraud science
science and technology Hackers Turned Virginia Government Sites Into eBook Scam By packetstormsecurity.com Published On :: Fri, 08 May 2020 14:23:04 GMT Full Article headline hacker government usa fraud
science and technology Favicons Found Housing Credit Card Skimming Malware By packetstormsecurity.com Published On :: Fri, 08 May 2020 14:23:15 GMT Full Article headline malware bank cybercrime fraud
science and technology Blue Mockingbird Monero-Mining Campaign Exploits Web Apps By packetstormsecurity.com Published On :: Fri, 08 May 2020 14:23:17 GMT Full Article headline malware fraud cryptography
science and technology Safari Webkit Proxy Object Type Confusion By packetstormsecurity.com Published On :: Sun, 02 Jun 2019 15:30:59 GMT This Metasploit module exploits a type confusion bug in the Javascript Proxy object in WebKit. The DFG JIT does not take into account that, through the use of a Proxy, it is possible to run arbitrary JS code during the execution of a CreateThis operation. This makes it possible to change the structure of e.g. an argument without causing a bailout, leading to a type confusion (CVE-2018-4233). The type confusion leads to the ability to allocate fake Javascript objects, as well as the ability to find the address in memory of a Javascript object. This allows us to construct a fake JSCell object that can be used to read and write arbitrary memory from Javascript. The module then uses a ROP chain to write the first stage shellcode into executable memory within the Safari process and kick off its execution. The first stage maps the second stage macho (containing CVE-2017-13861) into executable memory, and jumps to its entrypoint. The CVE-2017-13861 async_wake exploit leads to a kernel task port (TFP0) that can read and write arbitrary kernel memory. The processes credential and sandbox structure in the kernel is overwritten and the meterpreter payloads code signature hash is added to the kernels trust cache, allowing Safari to load and execute the (self-signed) meterpreter payload. Full Article
science and technology Red Hat Security Advisory 2019-1821-01 By packetstormsecurity.com Published On :: Mon, 22 Jul 2019 15:22:22 GMT Red Hat Security Advisory 2019-1821-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Issues addressed include bypass and denial of service vulnerabilities. Full Article
science and technology Ubuntu Security Notice USN-4130-1 By packetstormsecurity.com Published On :: Wed, 11 Sep 2019 20:00:19 GMT Ubuntu Security Notice 4130-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
science and technology Red Hat Security Advisory 2019-2925-01 By packetstormsecurity.com Published On :: Mon, 30 Sep 2019 13:33:33 GMT Red Hat Security Advisory 2019-2925-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Issues addressed include a denial of service vulnerability. Full Article
science and technology Red Hat Security Advisory 2019-2939-01 By packetstormsecurity.com Published On :: Mon, 30 Sep 2019 22:22:22 GMT Red Hat Security Advisory 2019-2939-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Issues addressed include a denial of service vulnerability. Full Article
science and technology Red Hat Security Advisory 2019-2955-01 By packetstormsecurity.com Published On :: Wed, 02 Oct 2019 15:03:59 GMT Red Hat Security Advisory 2019-2955-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Issues addressed include a denial of service vulnerability. Full Article
science and technology WhatWeb Scanner 0.5.0 By packetstormsecurity.com Published On :: Sat, 05 Oct 2019 13:11:29 GMT WhatWeb is a next-generation web scanner. WhatWeb recognises web technologies including content management systems (CMS), blogging platforms, statistic/analytics packages, JavaScript libraries, web servers, and embedded devices. WhatWeb has over 1800 plugins, each to recognise something different. WhatWeb also identifies version numbers, email addresses, account IDs, web framework modules, SQL errors, and more. WhatWeb supports an aggression level to control the trade off between speed and reliability. Full Article
science and technology Total.js CMS 12 Widget JavaScript Code Injection By packetstormsecurity.com Published On :: Mon, 21 Oct 2019 23:29:46 GMT This Metasploit module exploits a vulnerability in Total.js CMS. The issue is that a user with admin permission can embed a malicious JavaScript payload in a widget, which is evaluated server side, and gain remote code execution. Full Article
science and technology Ubuntu Security Notice USN-4178-1 By packetstormsecurity.com Published On :: Fri, 08 Nov 2019 15:35:29 GMT Ubuntu Security Notice 4178-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
science and technology Ubuntu Security Notice USN-4181-1 By packetstormsecurity.com Published On :: Tue, 12 Nov 2019 18:56:35 GMT Ubuntu Security Notice 4181-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
science and technology Ubuntu Security Notice USN-4261-1 By packetstormsecurity.com Published On :: Thu, 30 Jan 2020 14:46:06 GMT Ubuntu Security Notice 4261-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
science and technology Ubuntu Security Notice USN-4281-1 By packetstormsecurity.com Published On :: Tue, 18 Feb 2020 15:06:49 GMT Ubuntu Security Notice 4281-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
science and technology Red Hat Security Advisory 2020-0573-01 By packetstormsecurity.com Published On :: Tue, 25 Feb 2020 15:14:57 GMT Red Hat Security Advisory 2020-0573-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. HTTP request smuggling was addressed along with other security issues. Full Article
science and technology Red Hat Security Advisory 2020-0579-01 By packetstormsecurity.com Published On :: Tue, 25 Feb 2020 15:19:52 GMT Red Hat Security Advisory 2020-0579-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. HTTP request smuggling was addressed along with other security issues. Full Article
science and technology Red Hat Security Advisory 2020-0597-01 By packetstormsecurity.com Published On :: Tue, 25 Feb 2020 15:23:31 GMT Red Hat Security Advisory 2020-0597-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. HTTP request smuggling was addressed along with other security issues. Full Article
science and technology Red Hat Security Advisory 2020-0598-01 By packetstormsecurity.com Published On :: Tue, 25 Feb 2020 15:24:19 GMT Red Hat Security Advisory 2020-0598-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. HTTP request smuggling was addressed along with other security issues. Full Article
science and technology WhatWeb Scanner 0.5.1 By packetstormsecurity.com Published On :: Tue, 25 Feb 2020 15:24:44 GMT WhatWeb is a next-generation web scanner. WhatWeb recognizes web technologies including content management systems (CMS), blogging platforms, statistic/analytics packages, JavaScript libraries, web servers, and embedded devices. WhatWeb has over 1800 plugins, each to recognize something different. WhatWeb also identifies version numbers, email addresses, account IDs, web framework modules, SQL errors, and more. WhatWeb supports an aggression level to control the trade off between speed and reliability. Full Article
science and technology Red Hat Security Advisory 2020-0602-01 By packetstormsecurity.com Published On :: Wed, 26 Feb 2020 05:02:22 GMT Red Hat Security Advisory 2020-0602-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. HTTP request smuggling was addressed along with other security issues. Full Article
science and technology Ubuntu Security Notice USN-4310-1 By packetstormsecurity.com Published On :: Mon, 30 Mar 2020 15:43:08 GMT Ubuntu Security Notice 4310-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
science and technology Red Hat Security Advisory 2020-1293-01 By packetstormsecurity.com Published On :: Thu, 02 Apr 2020 14:46:47 GMT Red Hat Security Advisory 2020-1293-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Issues addressed include an integer overflow vulnerability. Full Article
science and technology Red Hat Security Advisory 2020-1317-01 By packetstormsecurity.com Published On :: Mon, 06 Apr 2020 18:24:03 GMT Red Hat Security Advisory 2020-1317-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Issues addressed include an integer overflow vulnerability. Full Article
science and technology Red Hat Security Advisory 2020-1325-01 By packetstormsecurity.com Published On :: Mon, 06 Apr 2020 18:40:24 GMT Red Hat Security Advisory 2020-1325-01 - python-XStatic-jQuery is the jQuery javascript library packaged for Python's setuptools. Issues addressed include code execution and denial of service vulnerabilities. Full Article
science and technology Red Hat Security Advisory 2020-1343-01 By packetstormsecurity.com Published On :: Tue, 07 Apr 2020 16:40:52 GMT Red Hat Security Advisory 2020-1343-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Issues addressed include an integer overflow vulnerability. Full Article
science and technology Ubuntu Security Notice USN-4331-1 By packetstormsecurity.com Published On :: Mon, 20 Apr 2020 15:24:18 GMT Ubuntu Security Notice 4331-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
science and technology Ubuntu Security Notice USN-4347-1 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 16:01:43 GMT Ubuntu Security Notice 4347-1 - A large number of security issues were discovered in the WebKitGTK Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
science and technology Baby Monitors Watched By Hackers, Warn Experts By packetstormsecurity.com Published On :: Tue, 03 Mar 2020 14:01:17 GMT Full Article headline hacker privacy flaw spyware
science and technology Spyware Maker NSO Group Fails To Show Up In Court By packetstormsecurity.com Published On :: Mon, 09 Mar 2020 15:01:28 GMT Full Article headline hacker government privacy phone israel spyware facebook
science and technology Spying Concerns Raised Over Iran's Official COVID-19 App By packetstormsecurity.com Published On :: Tue, 10 Mar 2020 12:56:35 GMT Full Article headline government malware virus spyware iran
science and technology US Congress: Spying Law Is Flawed, Open To Abuse, And Lacking In Accountability - So Let's Reauthorize It By packetstormsecurity.com Published On :: Fri, 13 Mar 2020 14:49:20 GMT Full Article headline government privacy usa phone spyware nsa