L'actu de la sécu


Les dernières news:

  • PipeMagic Trojan Exploits Windows Zero-Day Vulnerability to Deploy Ransomware
    Publié le April 9, 2025

    Source: HackerNews

    Microsoft has revealed that a now-patched security flaw impacting the Windows Common Log File System (CLFS) was exploited as a zero-day in ransomware attacks aimed at a small number of targets. "The targets include organizations in the information technology (IT) and real estate sectors of the United States, the financial sector in Venezuela, a Spanish software company, and the retail sector in

    Lien
  • CISA Warns of CentreStack's Hard-Coded MachineKey Vulnerability Enabling RCE Attacks
    Publié le April 9, 2025

    Source: HackerNews

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a critical security flaw impacting Gladinet CentreStack to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The vulnerability, tracked as CVE-2025-30406 (CVSS score: 9.0), concerns a case of a hard-coded cryptographic key that could be abused to achieve remote

    Lien
  • Microsoft Patches 125 Flaws Including Actively Exploited Windows CLFS Vulnerability
    Publié le April 9, 2025

    Source: HackerNews

    Microsoft has released security fixes to address a massive set of 125 flaws affecting its software products, including one vulnerability that it said has been actively exploited in the wild. Of the 125 vulnerabilities, 11 are rated Critical, 112 are rated Important, and two are rated Low in severity. Forty-nine of these vulnerabilities are classified as privilege escalation, 34 as remote code

    Lien
  • Adobe Patches 11 Critical ColdFusion Flaws Amid 30 Total Vulnerabilities Discovered
    Publié le April 9, 2025

    Source: HackerNews

    Adobe has released security updates to fix a fresh set of security flaws, including multiple critical-severity bugs in ColdFusion versions 2025, 2023 and 2021 that could result in arbitrary file read and code execution. Of the 30 flaws in the product, 11 are rated Critical in severity - CVE-2025-24446 (CVSS score: 9.1) - An improper input validation vulnerability that could result in an

    Lien
  • Qraved - 984,519 breached accounts
    Publié le April 9, 2025

    Source: HaveIBeenPwnd

    In July 2021, the Indonesian restaurant website Qraved suffered a data breach

    Lien
  • [webapps] PZ Frontend Manager WordPress Plugin 1.0.5 - Cross Site Request Forgery (CSRF)
    Publié le April 9, 2025

    Source: ExploitDB

    PZ Frontend Manager WordPress Plugin 1.0.5 - Cross Site Request Forgery (CSRF)

    Lien
  • [webapps] ChurchCRM 5.9.1 - SQL Injection
    Publié le April 9, 2025

    Source: ExploitDB

    ChurchCRM 5.9.1 - SQL Injection

    Lien
  • [webapps] Intelight X-1L Traffic controller Maxtime 1.9.6 - Remote Code Execution (RCE)
    Publié le April 9, 2025

    Source: ExploitDB

    Intelight X-1L Traffic controller Maxtime 1.9.6 - Remote Code Execution (RCE)

    Lien
  • [webapps] ResidenceCMS 2.10.1 - Stored Cross-Site Scripting (XSS)
    Publié le April 9, 2025

    Source: ExploitDB

    ResidenceCMS 2.10.1 - Stored Cross-Site Scripting (XSS)

    Lien