bug

  1. Man

    A bug in CLFS turns ordinary Windows users into administrators

    Kernel protection turned out to be powerless against the new PoC exploit. A critical vulnerability in the Common Log File System (CLFS) driver has been discovered in the Windows 11 operating system, which allows local users to escalate their privileges. CLFS is responsible for efficiently...
  2. Father

    New Windows bug - a treat for QakBot: Microsoft fights botnet

    The corporation destroyed another way to infect systems. Microsoft has fixed a zero-day vulnerability that was actively used to spread the QakBot botnet on Windows systems. The heap-based buffer overflow vulnerability CVE-2024-30051 (CVSS score 3.1: 7.8) affects the Desktop Window Manager...
  3. Father

    The Fortinet bug has become the main tool of a new hacking campaign

    The negligence of administrators leads to theft of corporate data. Forescout has discovered a new campaign that exploits a vulnerability in Fortinet FortiClient EMS devices to spread malware. The SQL injection vulnerability CVE-2023-48788 (CVSS score: 9.8) allows an unauthorized attacker to...
  4. Father

    CVE-2024-1086: Bug exposes popular Linux distributions

    If you didn't update your Linux – you lost your computer. Security researcher Notselwyn discovered a new vulnerability in Linux that allows you to get root rights. The bug affects versions of the Linux kernel from 5.14 to 6.6.14. Vulnerability CVE-2024-1086 (CVSS score: 7.8) affects many...
  5. Teacher

    From Ubuntu to Debian: Many Linux distributions are at risk due to a long-standing bug

    The WallEscape vulnerability went unnoticed for 11 years. Did hackers manage to use it? A serious vulnerability has been discovered in the Linux operating system that allows unprivileged attackers to steal passwords or change the victims clipboard. The problem concerns the wall command in the...
  6. Teacher

    Hunt for a million: MaxPatrol SIEM and MaxPatrol VM released on bug bounty

    Positive Technologies launches another program to search for vulnerabilities in its products. Another program to search for vulnerabilities in Positive Technologies products was launched on the Standoff 365 Bug Bounty platform. Researchers can receive up to 1 million rubles for detected...
  7. Teacher

    Mining, encryption, remote access: a bug in TeamCity has become fatal for dozens of organizations

    CVE-2024-27198 opened a compromise portal for hackers. When will the administrators close it? Attackers continue to actively exploit vulnerabilities in the JetBrains TeamCity software, deploying ransomware, cryptocurrency miners, Cobalt Strike beacons, and Spark RAT remote access Trojans. The...
  8. Teacher

    8800 servers – one bug: any non-updated ScreenConnect system can be hacked remotely

    ConnectWise asks customers to take action before it's too late. ConnectWise is asking its customers to update their ScreenConnect servers urgently. The reason was a critical vulnerability that allows bypassing authentication and executing arbitrary code remotely. Attackers can use this flaw to...
  9. Brother

    A bug in common Web3 smart contracts led to an increase in Bug Bounty payments

    What are the consequences of a vulnerability if information about it is carefully hidden? The company Thirdweb, specializing in the development of smart contracts, discovered a vulnerability affecting many smart contracts in the Web3 ecosystem. The problem was identified in the popular open...
  10. Lord777

    Old bug – new risks: after publishing an exploit for a defect in CrushFTP, 10,000 servers are at risk

    The August patch was not the most reliable measure. A dangerous bug has been discovered in the popular secure file sharing software CrushFTP, which gives attackers the opportunity to gain full control over the vulnerable server. In fact, Converge experts discovered the vulnerability...
  11. Carding 4 Carders

    Through Protection: new VMware bug renders updates useless

    The VMware vulnerability puts your data at risk even after updates. VMware, which specializes in virtualization services, warned its customers about the existence of a PoC exploit for a recently patched vulnerability in the Aria Operations for Logs product. The authentication bypass...
  12. Carding 4 Carders

    Critical bug in the Linux subsystem: attackers can remotely control your server

    A logical error was detected in NVMe-oF / TCP, which gives full access to the system. A vulnerability identified as CVE-2023-5178 has been identified in the Linux subsystem known as nvmet-tcp (NVMe-oF/TCP), which is designed to access NVMe drives over a network using the TCP protocol. The...
Top