Category: GBHackers

0day Vulnerability In 10,000 Web Apps Exploited Using XSS Payloads
13
Jun
2024

0day Vulnerability In 10,000 Web Apps Exploited Using XSS Payloads

A significant vulnerability, tracked as CVE-2024-37629, has been discovered in SummerNote 0.8.18. It allows Cross-Site Scripting (XSS) via the Code…

0day Vulnerability XSS Payloads
13
Jun
2024

Hackers Exploiting MS Office Editor Vulnerability Deploy Keylogger

Researchers have identified a sophisticated cyberattack orchestrated by the notorious Kimsuky threat group. The group has been exploiting a known…

Windows Servers MSMQ RCE Flaw
13
Jun
2024

Ivanti EPM SQL Injection Flaw Let Attackers Execute Remote Code

In May 24, 2024, Zero-Day Initiative released a security advisory for Ivanti EPM which was associated with SQL injection Remote…

Windows Servers MSMQ RCE Flaw
13
Jun
2024

CISA Warns of Scammers Impersonating as CISA Employees

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a surge in impersonation scams. These scams often…

Windows Servers MSMQ RCE Flaw
13
Jun
2024

Microsoft Window Ntqueryinformationtoken Flaw Escalate Privilege

Microsoft has disclosed a critical vulnerability identified as CVE-2024-30088. With a CVSS score of 8.8, this flaw affects Microsoft Windows and allows local attackers to escalate their privileges on affected…

Windows Servers MSMQ RCE Flaw
13
Jun
2024

Indian National Jailed For Hacked Servers Of Company

An Indian national was sentenced to two years and eight months in jail for unauthorized access to his former employer’s…

256,000+ Publicly Exposed Windows Servers Vulnerable to MSMQ RCE Flaw
13
Jun
2024

256,000+ Publicly Exposed Windows Servers Vulnerable to MSMQ RCE Flaw

Cybersecurity watchdog Shadowserver has identified 256,000+ publicly exposed servers vulnerable to a critical Remote Code Execution (RCE) flaw in Microsoft…

Hackers Exploiting Linux SSH Services to Deploy Malware
12
Jun
2024

Hackers Exploiting Linux SSH Services to Deploy Malware

SSH and RDP provide remote access to server machines (Linux and Windows respectively) for administration. Both protocols are vulnerable to…

JetBrains Warns of GitHub Plugin that Exposes Access Tokens
12
Jun
2024

JetBrains Warns of GitHub Plugin that Exposes Access Tokens

A critical vulnerability (CVE-2024-37051) in the JetBrains GitHub plugin for IntelliJ-based IDEs (2023.1 and later) exposed access tokens to malicious…

Microsoft Message Queuing RCE Flaw
12
Jun
2024

Critical Flaw In Apple Ecosystems Let Attackers Gain Unauthorized Access

Hackers go for Apple due to its massive user base along with rich customers, including business people and managers who…

Microsoft Message Queuing RCE Flaw
12
Jun
2024

Firefox 127 Released With patch for 15 Vulnerabilities

Mozilla has released Firefox 127, addressing 15 security vulnerabilities, some of which have been rated as high impact. This update…

Microsoft Message Queuing RCE Flaw
12
Jun
2024

Pure Storage Data Breach Following Snowflake Hack

Pure Storage has confirmed that a third party temporarily gained unauthorized access to a Snowflake data analytics workspace. This workspace…