NEW CARDING CHAT IN TELEGRAM

vulnerability

  1. Man

    Breaking the Barrier: Six-Year-Old Vulnerability Leaves AMD and Intel Alone

    Speculative attacks continue to find loopholes even in modern processors. It's been more than six years since the legendary Spectre vulnerability was discovered, however, the latest AMD and Intel CPUs are still susceptible to speculative execution attacks. This is the conclusion reached by...
  2. Man

    Chinese Hackers Hunt for Trump's Phones Through Verizon Vulnerability

    What is behind the attempted attack on the Trump and Harris campaigns. Chinese hackers tried to access data on the phones of former US President Donald Trump and his campaign partner J.D. Vance, as well as people associated with the campaign of Vice President Kamala Harris. This is reported by...
  3. Man

    Dutch authorities fight for safe intersections due to vulnerability in traffic lights

    Talking Traffic is a system that will solve the problem or put entire provinces at risk. A serious vulnerability has been discovered in the Netherlands in a traffic light management system that allows attackers to remotely control signals at thousands of intersections across the country. This...
  4. Man

    Vulnerability in pam_oath that could allow root privileges on the system

    A vulnerability (CVE-2024-47191) has been identified in the pam_oath PAM module, which is part of the oath-toolkit package and is used for two-factor authentication using one-time passwords (OTP), which allows an unprivileged user to gain root access in the system. The pam_oath module is...
  5. Man

    Patch or Crash: The Exploitation of the Zimbra Vulnerability Has Already Begun

    Attackers disguise commands in email messages. Cybersecurity experts are calling for immediate updates to Zimbra's email servers, as a new critical vulnerability is already being actively exploited by hackers. The vulnerability with the identifier CVE-2024-45519 was discovered on September 27...
  6. Friend

    Lesson Not Learned: Onyx Loses $3.8 Million Due to Old Vulnerability

    The protocol was attacked again due to a bug in Compound Finance v2. On September 26, the decentralized finance (DeFi) protocol Onyx was attacked, as a result of which attackers managed to steal assets worth $3.8 million. Information about the incident was published by the blockchain security...
  7. Friend

    $2 Million Vulnerability: Bedrock Prepares Recovery Plan

    The project promises compensation after the leakage of funds. The Bedrock team has announced the identification of a vulnerability related to the uniBTC token, which affected funds worth about $2 million. Most of the losses affected liquidity pools on decentralized exchanges (DEXs LPs). Despite...
  8. Man

    Vulnerability in libnv on FreeBSD and vulnerabilities in Netfilter on Linux

    A fix for a vulnerability in the libnv library, released in early September, identified a logical error that prevented the vulnerability from being properly addressed and the system remained vulnerable to attack. The libnv library is developed by the FreeBSD project and is used in the kernel and...
  9. Friend

    Critical RCE vulnerability found in GNU/Linux systems, no patch yet

    Experts warn of a critical vulnerability affecting all GNU/Linux systems. If exploited, an unauthenticated attacker can execute the code remotely. Apparently, the problem has existed for more than a decade, and in two weeks, the researchers promise to publish technical details. Interestingly...
  10. Friend

    Houzez Vulnerability: 46,000 Websites at Risk of Takeover

    PatchStack researchers have revealed details of critical security flaws. Two vulnerabilities have been discovered in the Houzez WordPress theme, as well as in the associated Login Register plugin, threatening the security of more than 46,000 websites. Researchers from PatchStack found that...
  11. Friend

    Vulnerability avalanche: 2024 breaks records in the number of cyber threats

    Aqua Nautilus cites 28,000 reasons for concern in its report. There is an alarming trend in the field of cybersecurity: the number of vulnerabilities identified is breaking all records. According to the National Database (NVD), 28,821 security breaches were reported in 2023. Even more alarming...
  12. Friend

    Critical vulnerability in GitLab: passwordless login is available to every hacker

    The identified flaw received the highest possible CVSS score. GitLab has released updates to address a critical vulnerability in its Community Edition (CE) and Enterprise Edition (EE) editions that could lead to authentication bypass. The issue is related to the ruby-saml library (...
  13. Friend

    CVSS 9.9: SolarWinds ARM vulnerability hits companies' security

    How could the leading software vendors have made such a gross miscalculation? SolarWinds has released updates to address two vulnerabilities in its Access Rights Manager (ARM) software, one of which is classified as critical. The vulnerability, identified CVE-2024-28991, has a CVSS score of 9.0...
  14. Friend

    CVE-2024-7029: 0-day vulnerability in AVTECH cameras returns Mirai botnet to the game

    The problem has been known for 5 years, but experts began to sound the alarm only now. Akamai has detected a new wave of attacks on outdated security cameras from the Taiwanese manufacturer AVTECH. Attackers exploit a critical vulnerability in the AVM1203 model to spread malware from the Mirai...
  15. Friend

    CVE-2024-7965: Google Patches 10th Zero-Day Vulnerability in 2024

    Update your browser urgently to avoid cyberattacks. Google has announced the release of an update that closes the tenth zero-day vulnerability that was actively exploited by attackers or white hat hackers as part of the competition in 2024. CVE-2024-7965 (CVSS score: 8.8) is a bug in the...
  16. Friend

    CVE-2024-6800: GitHub resolves critical vulnerability in Enterprise Server

    Update as soon as possible if you don't want to share your data with hackers. On August 20, GitHub released updates to address three security vulnerabilities in its Enterprise Server product, including one critical issue that allowed attackers to gain site administrator privileges. The most...
  17. Friend

    Zero-click vulnerability found in all versions of Windows

    The TCP / IP error propagates over IPv6 systems without user intervention. Microsoft has warned users about a critical TCP / IP vulnerability that allows remote code execution (RCE) on all Windows systems with IPv6 enabled by default. Vulnerability CVE-2024-38063 (CVSS score: 9.8) is...
  18. Carding Forum

    CVE-2024-37085: Vulnerability in VMware gets out of control

    Cobalt Strike and Pypykatz open the way to full control of the network. A recently fixed vulnerability in the VMware ESXi hypervisors is actively used by several ransomware groups to gain elevated rights and deploy malicious software that encrypts files. These attacks exploit the vulnerability...
  19. Carding Forum

    Vulnerability in WhatsApp allows you to silently run malicious Python and PHP scripts

    Why is Meta slow to take measures to protect users? The latest version of WhatsApp for Windows hides a serious vulnerability. It allows attackers to send attachments with Python and PHP scripts that run without warning as soon as the recipient opens them. The problem is similar to the Telegram...
  20. Carding Forum

    PKfail: 12-year-old UEFI vulnerability lets you bypass Secure Boot

    A massive supply chain problem affects 813 UEFI products. Binarly experts report that hundreds of UEFI products from 10 vendors are at risk of being hacked due to a critical PKfail vulnerability in the firmware supply chain that allows you to bypass Secure Boot and install malware. Vulnerable...
Top