FreshRSS

🔒
❌ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
☐ ☆ ✇ /r/netsec - Information Security News & Discussion

New Kerio Control Advisory!

By: /u/Straight-Zombie-646 — June 24th 2025 at 18:03

Kerio Control has a design flaw in the implementation of the communication with GFI AppManager, leading to an authentication bypass vulnerability in the product under audit. Once the authentication bypass is achieved, the attacker can execute arbitrary code and commands.

submitted by /u/Straight-Zombie-646
[link] [comments]
☐ ☆ ✇ /r/netsec - Information Security News & Discussion

Samsung MagicINFO Unauthenticated RCE

By: /u/Straight-Zombie-646 — April 30th 2025 at 09:23

MagicINFO exposes an endpoint with several flaws that, when combined, allow an unauthenticated attacker to upload a JSP file and execute arbitrary server-side code.

submitted by /u/Straight-Zombie-646
[link] [comments]
☐ ☆ ✇ /r/netsec - Information Security News & Discussion

2 New UAF Vulnerabilities in Chrome

By: /u/Straight-Zombie-646 — April 24th 2025 at 12:41

Use-After-Free (UAF) vulnerabilities within the Chrome Browser process have frequently been a key vector for sandbox escapes. These flaws could have led to critical exploits in the past, but thanks to Chrome’s latest security technology, MiraclePtr, they are no longer exploitable.

submitted by /u/Straight-Zombie-646
[link] [comments]
❌