Cyber Newsroom Feed

The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.

  • 0patch.com
Micropatches Released For Two Windows CNG Key Isolation Service Vulnerabilities (CVE-2023-28229, CVE-2023-36906)

Last month, security researcher @k0shl of Cyber Kunlun published a proof-of-concept for CVE-2023-28229, an elevation of privilege vulnerability in CNG Key Isolation Service. The same POC also demonstr ... Read more

Published Date: Oct 09, 2023 (1 year, 2 months ago)
  • cert.pl
Vulnerability in UptimeDC software

CVE ID CVE-2023-4997 Publication date 04 October 2023 Vendor ProIntegra S.A Product UptimeDC Vulnerable versions All below 2.0.0.33940 Vulnerability type (CWE) Missing Authorization (CWE-862) Report s ... Read more

Published Date: Oct 04, 2023 (1 year, 2 months ago)
  • 0patch.com
Micropatches Released For Windows Error Reporting Service Elevation of Privilege (CVE-2023-36874)

With July 2023 Windows Updates, Microsoft brought a fix for CVE-2023-36874, a local privilege escalation vulnerability in Windows Error Reporting Service that was found both by Google TAG and CrowdStr ... Read more

Published Date: Sep 13, 2023 (1 year, 3 months ago)
  • 0patch.com
Micropatches Released For Windows Search Remote Code Execution (CVE-2023-36884)

Alongside July 2023 Windows Updates, Microsoft revealed the existence of a 0day that was detected in the wild and assigned it CVE-2023-36884. Without issuing a patch, they titled their original adviso ... Read more

Published Date: Sep 06, 2023 (1 year, 3 months ago)
  • cert.pl
Vulnerability in lua-http library

CVE ID CVE-2023-4540 Publication date 05 September 2023 Vendor Daurnimator Product lua-http Vulnerable versions All including 0.4 before ddab283 commit Vulnerability type (CWE) Improper Handling of Ex ... Read more

Published Date: Sep 05, 2023 (1 year, 3 months ago)
  • 0patch.com
Micropatches Released For Denial of Service in Microsoft Message Queuing (CVE-2023-28302, CVE-2023-21769)

April 2023 Windows Updates brought fixes for a number of vulnerabilities in Microsoft Message Queuing Service. We first issued patches for the "Queuejumper" remote code execution vulnerability (CVE-20 ... Read more

Published Date: Jul 14, 2023 (1 year, 5 months ago)
  • 0patch.com
Micropatches Released For DHCP Server Service Remote Code Execution (CVE-2023-28231)

April 2023 Windows Updates brought a fix for CVE-2023-28231, a remote code execution vulnerability in DHCP Server service. The vulnerability was reported to Microsoft by security researcher YanZiShuan ... Read more

Published Date: Jun 30, 2023 (1 year, 6 months ago)
  • curatedintel.org
CL0P likes to MOVEit MOVEit

CL0P likes to MOVEit MOVEit BackgroundFor the last couple of years, the threat actors associated with the CL0P ransomware group have occasionally ditched encryption in favour of exploiting file transf ... Read more

Published Date: Jun 08, 2023 (1 year, 6 months ago)
  • 360 Netlab Blog - Network Security Research Lab at 360
快讯:使用21个漏洞传播的DDoS家族WSzero已经发展到第4个版本

概述 近期,我们的BotMon系统连续捕获到一个由Go编写的DDoS类型的僵尸网络家族,它用于DDoS攻击,使用了包括SSH/Telnet弱口令在内的多达22种传播方式。短时间内出现了4个不同的版本,有鉴于此,我们觉得该家族未来很可能继续活跃,值得警惕。下面从传播、样本和跟踪角度分别介绍。 传播分析 除了Telnet/SSH弱口令,我们观察到wszero还使用了如下21个漏洞进行传播: VULNE ... Read more

Published Date: Dec 07, 2022 (2 years ago)
  • malwaretech.com
Everything you need to know about the OpenSSL 3.0.7 Patch (CVE-2022-3602 & CVE-2022-3786)

Discussion thread: https://updatedsecurity.com/topic/9-openssl-vulnerability-cve-2022-3602-cve-2022-3786/ Vulnerability Details From https://www.openssl.org/news/secadv/20221101.txt X.509 Email Addres ... Read more

Published Date: Nov 01, 2022 (2 years, 2 months ago)

Filters

Showing 10 of 2744 Results
© cvefeed.io
Latest DB Update: Jan. 02, 2025 14:54