FreshRSS

πŸ”’
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ The Hacker News

Cybersecurity Agencies Warn Against IDOR Bugs Exploited for Data Breaches

By: THN β€” July 28th 2023 at 05:07
Cybersecurity agencies in Australia and the U.S. haveΒ publishedΒ a joint cybersecurity advisory warning against security flaws in web applications that could be exploited by malicious actors to orchestrate data breach incidents and steal confidential data. This includes a specific class of bugs called Insecure Direct Object Reference (IDOR), a type of access control flaw that occurs when an
☐ β˜† βœ‡ The Hacker News

Adobe Rolls Out New Patches for Actively Exploited ColdFusion Vulnerability

By: THN β€” July 20th 2023 at 03:31
Adobe has released a fresh round of updates to address an incomplete fix for a recently disclosed ColdFusion flaw that has come under active exploitation in the wild. The critical shortcoming, tracked asΒ CVE-2023-38205Β (CVSS score: 7.5), has been described as an instance of improper access control that could result in a security bypass. It impacts the following versions: ColdFusion 2023 (Update
☐ β˜† βœ‡ The Hacker News

Hackers Exploit Windows Policy Loophole to Forge Kernel-Mode Driver Signatures

By: THN β€” July 11th 2023 at 16:59
A Microsoft Windows policy loophole has been observed being exploited primarily by native Chinese-speaking threat actors to forge signatures on kernel-mode drivers. "Actors are leveraging multiple open-source tools that alter the signing date of kernel mode drivers to load malicious and unverified drivers signed with expired certificates," Cisco Talos said in anΒ exhaustive two-part reportΒ shared
❌