Remove tag disclosure
article thumbnail

Weekly Update 359

Troy Hunt

I've been speaking about it a lot in these videos over recent weeks so many of you have already know what it entails, but it's the tip of the iceberg you've seen publicly. I settled for dumping stuff in a <pre> tag for now and will invest the time in doing it right later on.)

article thumbnail

Microsoft March 2022 Patch Tuesday updates fix 89 vulnerabilities

Security Affairs

Below is the complete list of vulnerabilities addressed by Microsoft: Tag CVE ID CVE Title Severity.NET and Visual Studio CVE-2022-24512.NET Below is the complete list of vulnerabilities addressed by Microsoft: Tag CVE ID CVE Title Severity.NET and Visual Studio CVE-2022-24512.NET

Libraries 103
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Microsoft February 2022 Patch Tuesday security updates fix a zero-day

Security Affairs

Tag CVE ID CVE Title Severity Azure Data Explorer CVE-2022-23256 Azure Data Explorer Spoofing Vulnerability Important Kestrel Web Server CVE-2022-21986.NET Tag CVE ID CVE Title Severity Azure Data Explorer CVE-2022-23256 Azure Data Explorer Spoofing Vulnerability Important Kestrel Web Server CVE-2022-21986.NET

article thumbnail

[Full-Disclosure] HideezKey 2 FAIL: How a good idea turns into a SPF (Security Product Failure)

Security Affairs

video below), I started looking around for more interesting and concerning (from a security point of view) NRF52-based products. To give you a quick overview of this piece of hardware, check out their video intro: Now that you got the point of this product. And here it comes the #Hideez Key 2 ! meh…). Pierluigi Paganini.

Security 102
article thumbnail

Weekly Vulnerability Recap – October 9, 2023 – Zero-Days Strike Android, Microsoft, Apple, Cisco & More

eSecurity Planet

Targeted Attacks Exploit Arm’s Mali GPU Vulnerabilities Type of attack: Remote code execution (RCE) vulnerability, Out-of-Bounds Write Weakness, and Information Disclosure vulnerability. The fix: Exim patched an RCE flaw ( CVE-2023-42114 ) and an information disclosure vulnerability ( CVE-2023-42116 ).

Libraries 104
article thumbnail

Nation-state actors are exploiting CVE-2020-0688 Microsoft Exchange server flaw

Security Affairs

Security experts Simon Zuckerbraun from Zero Day Initiative published technical details on how to exploit the Microsoft Exchange CVE-2020-0688 along with a video PoC. Query our API for "tags=CVE-2020-0688" to locate hosts conducting scans. wrote Zuckerbraun. CVE-2020-0688 mass scanning activity has begun.

article thumbnail

Flaw in Evernote Web Clipper for Chrome extension allows stealing data

Security Affairs

Researchers published a video PoC of the attacks that shows how hackers can steal a user’s Facebook information and data on PayPal transactions. Malicious website silently loads hidden, legitimate iframe tags (link) of targeted websites. Below the timeline of the flaw: May 27th, 2019 – Initial disclosure.