Remove tag disclosure
article thumbnail

Google WordPress Site Kit plugin grants attacker Search Console Access

Security Affairs

Experts found a critical bug in Google’s official WordPress plugin ‘Site Kit’ that could allow hackers to gain owner access to targeted sites’ Google Search Console. The post Google WordPress Site Kit plugin grants attacker Search Console Access appeared first on Security Affairs. Pierluigi Paganini.

Access 98
article thumbnail

CISA adds ownCloud and Google Chrome bugs to its Known Exploited Vulnerabilities catalog

Security Affairs

The two issues are: CVE-2023-6345 Google Skia Integer Overflow Vulnerability CVE-2023-49103 ownCloud graphapi Information Disclosure Vulnerability CVE-2023-6345 – The CVE-2023-5217 is a high-severity integer overflow in Skia. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo).

IT 86
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Google addressed 3 actively exploited flaws in Android

Security Affairs

CVE-2023-26083 CVE-2021-29256 CVE-2023-2136 The CVE-2023-26083 is an Arm Mali GPU kernel driver information disclosure vulnerability that the US CISA added to its Known Exploited Vulnerabilities catalog in April 2023. An unprivileged user can exploit the flaw to gain unauthorized access to sensitive data and escalate privileges to the root.

article thumbnail

Microsoft Patch Tuesday, August 2022 Edition

Krebs on Security

Microsoft this month also issued a different patch for another MSDT flaw, tagged as CVE-2022-35743. The publicly disclosed Exchange flaw is CVE-2022-30134 , which is an information disclosure weakness. “Exchanges can be treasure troves of information, making them valuable targets for attackers.

article thumbnail

Experts warn of a surge of attacks targeting Ivanti SSRF flaw 

Security Affairs

An authenticated attacker can exploit the issue to access certain restricted resources. Ivanti expects the threat actor to change their behavior and we expect a sharp increase in exploitation once this information is public – similar to what we observed on 11 January following the 10 January disclosure.” x), Policy Secure (9.x,

article thumbnail

Microsoft Patches Six Zero-Day Security Holes

Krebs on Security

– CVE-2021-31955 , an information disclosure bug in the Windows Kernel. “The ‘exploit detected’ tag means attackers are actively using them, so for me, it’s the most important piece of information we need to prioritize the patches.” – CVE-2021-31956 , an elevation of privilege flaw in Windows NTFS.

Security 308
article thumbnail

CISA adds Veritas Backup Exec flaws to its Known Exploited Vulnerabilities catalog

Security Affairs

Unlike other ALPHV affiliates, UNC4466 doesn’t rely on stolen credentials for initial access to victim environments. Unlike other ALPHV affiliates, UNC4466 doesn’t rely on stolen credentials for initial access to victim environments.

IT 76