Category: RedPacket Security

Modern GPUs vulnerable to new GPU.zip side-channel attack

Researchers from four American universities have developed a new GPU side-channel attack that leverages data… This article has been indexed from RedPacket Security Read the original article: Modern GPUs vulnerable to new GPU.zip side-channel attack

Google Chrome Multiple Vulnerabilities

Multiple vulnerabilities were identified in Google Chrome.  A remote attacker could exploit some of these… This article has been indexed from RedPacket Security Read the original article: Google Chrome Multiple Vulnerabilities

HackerOne Bug Bounty Disclosure: b-missing-function-level-access-control-in-mozilla-formula-containsregular-expression-denial-of-service-cve-b-unexpectedbuffercon

Company Name: b’Mozilla Core Services’ Company HackerOne URL: https://hackerone.com/mozilla_core_services Submitted By:b’unexpectedbuffercon_’ Link to Submitters Profile:https://hackerone.com/b’unexpectedbuffercon_’… This article has been indexed from RedPacket Security Read the original article: HackerOne Bug Bounty Disclosure: b-missing-function-level-access-control-in-mozilla-formula-containsregular-expression-denial-of-service-cve-b-unexpectedbuffercon

HackerOne Bug Bounty Disclosure: b-subdomain-takeover-on-mozaws-net-b-mikey

Company Name: b’Mozilla Core Services’ Company HackerOne URL: https://hackerone.com/mozilla_core_services Submitted By:b’mikey96′ Link to Submitters Profile:https://hackerone.com/b’mikey96′… This article has been indexed from RedPacket Security Read the original article: HackerOne Bug Bounty Disclosure: b-subdomain-takeover-on-mozaws-net-b-mikey

HackerOne Bug Bounty Disclosure: b-curl-cve-http-header-allocation-dos-b-selmelc

Company Name: b’Internet Bug Bounty’ Company HackerOne URL: https://hackerone.com/ibb Submitted By:b’selmelc’ Link to Submitters Profile:https://hackerone.com/b’selmelc’… This article has been indexed from RedPacket Security Read the original article: HackerOne Bug Bounty Disclosure: b-curl-cve-http-header-allocation-dos-b-selmelc

Medusa Locker Ransomware Victim: LANDSTAR POWER ONTARIO INC

  NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues… This article has been indexed from RedPacket Security Read the original article: Medusa Locker Ransomware Victim: LANDSTAR POWER ONTARIO INC

Medusa Locker Ransomware Victim: Acoustic Center

  NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues… This article has been indexed from RedPacket Security Read the original article: Medusa Locker Ransomware Victim: Acoustic Center

LockBit 3.0 Ransomware Victim: cochraninc[.]com

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: cochraninc[.]com

Poll Maker Plugin for WordPress cross-site scripting | CVE-2023-41872

NAME__________Poll Maker Plugin for WordPress cross-site scripting Platforms Affected:WordPress Poll Maker Plugin for WordPress 4.7.0… This article has been indexed from RedPacket Security Read the original article: Poll Maker Plugin for WordPress cross-site scripting | CVE-2023-41872

Online Job Portal SQL injection | CVE-2023-43468

NAME__________Online Job Portal SQL injection Platforms Affected:SourceCodester Online Job Portal 2020 Risk Level:6.5 Exploitability:High Consequences:Data… This article has been indexed from RedPacket Security Read the original article: Online Job Portal SQL injection | CVE-2023-43468

szvone vmqphp SQL injection | CVE-2023-43132

NAME__________szvone vmqphp SQL injection Platforms Affected:szvone vmqphp 1.13 Risk Level:6.5 Exploitability:High Consequences:Data Manipulation DESCRIPTION__________ szvone… This article has been indexed from RedPacket Security Read the original article: szvone vmqphp SQL injection | CVE-2023-43132

CACTUS Ransomware Victim: www[.]astrolighting[.]com

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: CACTUS Ransomware Victim: www[.]astrolighting[.]com

CACTUS Ransomware Victim: www[.]orthumbau[.]de

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: CACTUS Ransomware Victim: www[.]orthumbau[.]de

8 Base Ransomware Victim: Muenz-Engineered Sales

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: 8 Base Ransomware Victim: Muenz-Engineered Sales

Hackers actively exploiting Openfire flaw to encrypt servers

Hackers are actively exploiting a high-severity vulnerability in Openfire messaging servers to encrypt servers with… This article has been indexed from RedPacket Security Read the original article: Hackers actively exploiting Openfire flaw to encrypt servers

New AtlasCross hackers use American Red Cross as phishing lure

A new APT hacking group named ‘AtlasCross’ targets organizations with phishing lures impersonating the American… This article has been indexed from RedPacket Security Read the original article: New AtlasCross hackers use American Red Cross as phishing lure

Can we fix the weaknesses in password-based authentication?

In password-based authentication, end-users confirm their identity using login credentials, commonly a unique username, and… This article has been indexed from RedPacket Security Read the original article: Can we fix the weaknesses in password-based authentication?

ChromeOS Multiple Vulnerabilities

Multiple vulnerabilities were identified in ChromeOS. A remote attacker could exploit some of these vulnerabilities… This article has been indexed from RedPacket Security Read the original article: ChromeOS Multiple Vulnerabilities

Apple Products Multiple Vulnerabilities

Multiple vulnerabilities were identified in Apple Products. A remote attacker could exploit some of these… This article has been indexed from RedPacket Security Read the original article: Apple Products Multiple Vulnerabilities

HackerOne Bug Bounty Disclosure: b-no-rate-limit-on-forgot-password-on-https-apps-nextcloud-com-b-cyber-world

Company Name: b’Nextcloud’ Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b’cyber_world_01′ Link to Submitters Profile:https://hackerone.com/b’cyber_world_01′ Report Title:b’No… This article has been indexed from RedPacket Security Read the original article: HackerOne Bug Bounty Disclosure: b-no-rate-limit-on-forgot-password-on-https-apps-nextcloud-com-b-cyber-world

HackerOne Bug Bounty Disclosure: b-dos-in-form-submission-at-https-nextcloud-com-instant-trial-b-krrish-hackk

Company Name: b’Nextcloud’ Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b’krrish_hackk’ Link to Submitters Profile:https://hackerone.com/b’krrish_hackk’ Report Title:b’Dos… This article has been indexed from RedPacket Security Read the original article: HackerOne Bug Bounty Disclosure: b-dos-in-form-submission-at-https-nextcloud-com-instant-trial-b-krrish-hackk

HackerOne Bug Bounty Disclosure: b-nextcloud-all-in-one-path-disclosure-of-internal-frontend-b-shuvam

Company Name: b’Nextcloud’ Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b’shuvam321′ Link to Submitters Profile:https://hackerone.com/b’shuvam321′ Report Title:b’Nextcloud… This article has been indexed from RedPacket Security Read the original article: HackerOne Bug Bounty Disclosure: b-nextcloud-all-in-one-path-disclosure-of-internal-frontend-b-shuvam

HackerOne Bug Bounty Disclosure: b-existance-of-calendars-and-addressbooks-can-be-checked-by-unauthenticated-users-b-themarkib-x

Company Name: b’Nextcloud’ Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b’themarkib0x0′ Link to Submitters Profile:https://hackerone.com/b’themarkib0x0′ Report Title:b’Existance… This article has been indexed from RedPacket Security Read the original article: HackerOne Bug Bounty Disclosure: b-existance-of-calendars-and-addressbooks-can-be-checked-by-unauthenticated-users-b-themarkib-x

RustCrypto aes-gcm information disclosure | CVE-2023-42811

NAME__________RustCrypto aes-gcm information disclosure Platforms Affected:RustCrypto aes-gcm 0.10.0 RustCrypto aes-gcm 0.10.2 Risk Level:4.7 Exploitability:Proof of… This article has been indexed from RedPacket Security Read the original article: RustCrypto aes-gcm information disclosure | CVE-2023-42811

Galaxy Project Galaxy server-side request forgery | CVE-2023-42812

NAME__________Galaxy Project Galaxy server-side request forgery Platforms Affected:Galaxy Project Galaxy 22.01 Risk Level:6.3 Exploitability:Unproven Consequences:Gain… This article has been indexed from RedPacket Security Read the original article: Galaxy Project Galaxy server-side request forgery | CVE-2023-42812

WithSecure Policy Manager cross-site scripting | CVE-2023-43763

NAME__________WithSecure Policy Manager cross-site scripting Platforms Affected:WithSecure Policy Manager 15 Windows WithSecure Policy Manager 15… This article has been indexed from RedPacket Security Read the original article: WithSecure Policy Manager cross-site scripting | CVE-2023-43763

Mixin Network suspends operations following $200 million hack

Mixin Network, an open-source, peer-to-peer transactional network for digital assets, has announced today on Twitter… This article has been indexed from RedPacket Security Read the original article: Mixin Network suspends operations following $200 million hack

Brute Ratel C4 Detected – :

Brute Ratel C4 Detection Alerts This article has been indexed from RedPacket Security Read the original article: Brute Ratel C4 Detected – :

LockBit 3.0 Ransomware Victim: altmanplants[.]com

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: altmanplants[.]com

Cobalt Stike Beacon Detected – :

Cobalt Strike Beacon Detection Alerts This article has been indexed from RedPacket Security Read the original article: Cobalt Stike Beacon Detected – :

OpenKnowledgeMaps cross-site scripting | CVE-2023-40618

NAME__________OpenKnowledgeMaps cross-site scripting Platforms Affected:OpenKnowledgeMaps Head Start 7 Risk Level:5.4 Exploitability:High Consequences:Cross-Site Scripting DESCRIPTION__________ OpenKnowledgeMaps… This article has been indexed from RedPacket Security Read the original article: OpenKnowledgeMaps cross-site scripting | CVE-2023-40618

8 Base Ransomware Victim: Springer Eubank

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: 8 Base Ransomware Victim: Springer Eubank

8 Base Ransomware Victim: J[.]T[.] Cullen Co[.], Inc[.]

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: 8 Base Ransomware Victim: J[.]T[.] Cullen Co[.], Inc[.]

Mobile Security Framework information disclosure | CVE-2023-42261

NAME__________Mobile Security Framework information disclosure Platforms Affected:MobSF MobSF 3.7.8 Risk Level:5.3 Exploitability:Unproven Consequences:Bypass Security DESCRIPTION__________… This article has been indexed from RedPacket Security Read the original article: Mobile Security Framework information disclosure | CVE-2023-42261

Contribsys faktory denial of service | CVE-2023-37279

NAME__________Contribsys faktory denial of service Platforms Affected:contribsys faktory 1.7.0 Risk Level:7.5 Exploitability:Unproven Consequences:Denial of Service… This article has been indexed from RedPacket Security Read the original article: Contribsys faktory denial of service | CVE-2023-37279

Ivanti Endpoint Manager file disclosure | CVE-2023-38344

NAME__________Ivanti Endpoint Manager file disclosure Platforms Affected:Ivanti Endpoint Manager 2022 Risk Level:4.3 Exploitability:Unproven Consequences:Obtain Information… This article has been indexed from RedPacket Security Read the original article: Ivanti Endpoint Manager file disclosure | CVE-2023-38344

Ivanti Endpoint Manager information disclosure | CVE-2023-38343

NAME__________Ivanti Endpoint Manager information disclosure Platforms Affected:Ivanti Endpoint Manager 2022 Risk Level:5.3 Exploitability:Unproven Consequences:Obtain Information… This article has been indexed from RedPacket Security Read the original article: Ivanti Endpoint Manager information disclosure | CVE-2023-38343

National Student Clearinghouse data breach impacts 890 schools

U.S. educational nonprofit National Student Clearinghouse has disclosed a data breach affecting 890 schools using… This article has been indexed from RedPacket Security Read the original article: National Student Clearinghouse data breach impacts 890 schools

CISA: ISC Releases Security Advisories for BIND 9

ISC Releases Security Advisories for BIND 9 The Internet Systems Consortium (ISC) has released security… This article has been indexed from RedPacket Security Read the original article: CISA: ISC Releases Security Advisories for BIND 9

CISA: FBI and CISA Release Advisory on Snatch Ransomware

FBI and CISA Release Advisory on Snatch Ransomware Today, the Federal Bureau of Investigation (FBI)… This article has been indexed from RedPacket Security Read the original article: CISA: FBI and CISA Release Advisory on Snatch Ransomware

Medusa Locker Ransomware Victim: Franktronics, Inc

  NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues… This article has been indexed from RedPacket Security Read the original article: Medusa Locker Ransomware Victim: Franktronics, Inc

Medusa Locker Ransomware Victim: Philippine Health Insurance

  NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues… This article has been indexed from RedPacket Security Read the original article: Medusa Locker Ransomware Victim: Philippine Health Insurance

LockBit 3.0 Ransomware Victim: pelmorex[.]com

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: pelmorex[.]com

LockBit 3.0 Ransomware Victim: precisionpractice[.]com

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: precisionpractice[.]com

LockBit 3.0 Ransomware Victim: marshallindtech[.]com

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: marshallindtech[.]com

Hestiacp cross-site scripting | CVE-2023-5084

NAME__________Hestiacp cross-site scripting Platforms Affected:hestiacp hestiacp 1.8.7 Risk Level:3.9 Exploitability:High Consequences:Cross-Site Scripting DESCRIPTION__________ Hestiacp is… This article has been indexed from RedPacket Security Read the original article: Hestiacp cross-site scripting | CVE-2023-5084

Charts Plugin for WordPress cross-site scripting | CVE-2023-5062

NAME__________Charts Plugin for WordPress cross-site scripting Platforms Affected:WordPress Charts Plugin for WordPress 0.7.0 Risk Level:6.4… This article has been indexed from RedPacket Security Read the original article: Charts Plugin for WordPress cross-site scripting | CVE-2023-5062

Skyworth directory traversal | CVE-2023-40930

NAME__________Skyworth directory traversal Platforms Affected:Skyworth Skyworth OS 3.0 Risk Level:6.8 Exploitability:Unproven Consequences:Gain Access DESCRIPTION__________ Skyworth… This article has been indexed from RedPacket Security Read the original article: Skyworth directory traversal | CVE-2023-40930

8 Base Ransomware Victim: FabricATE Engineering

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: 8 Base Ransomware Victim: FabricATE Engineering

8 Base Ransomware Victim: The Envelope Works Ltd

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: 8 Base Ransomware Victim: The Envelope Works Ltd

Karakurt Ransomware Victim: Yakima Valley Radiology

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Karakurt Ransomware Victim: Yakima Valley Radiology

Karakurt Ransomware Victim: Hospice of Huntington

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: Karakurt Ransomware Victim: Hospice of Huntington

Government of Bermuda links cyberattack to Russian hackers

The Government of British overseas territory Bermuda has linked a cyberattack affecting all its departments’… This article has been indexed from RedPacket Security Read the original article: Government of Bermuda links cyberattack to Russian hackers

Hotel hackers redirect guests to fake Booking.com to steal cards

Security researchers discovered a multi-step information stealing campaign where hackers breach the systems of hotels,… This article has been indexed from RedPacket Security Read the original article: Hotel hackers redirect guests to fake Booking.com to steal cards

HackerOne Bug Bounty Disclosure: b-email-verification-bypass-for-manual-connection-setup-service-credentials-b-yozzo

Company Name: b’Nord Security’ Company HackerOne URL: https://hackerone.com/nordsecurity Submitted By:b’yozzo_’ Link to Submitters Profile:https://hackerone.com/b’yozzo_’ Report… This article has been indexed from RedPacket Security Read the original article: HackerOne Bug Bounty Disclosure: b-email-verification-bypass-for-manual-connection-setup-service-credentials-b-yozzo

LockBit 3.0 Ransomware Victim: milbermakris[.]com

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: milbermakris[.]com

LockBit 3.0 Ransomware Victim: carthagehospital[.]com

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: carthagehospital[.]com

LockBit 3.0 Ransomware Victim: clearcreek[.]org

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: clearcreek[.]org

LockBit 3.0 Ransomware Victim: sinloc[.]com

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: sinloc[.]com

LockBit 3.0 Ransomware Victim: tuvsud[.]com

NOTE: No files or stolen information are [exfiltrated/downloaded/taken/hosted/seen/reposted/disclosed] by RedPacket Security. Any legal issues relating… This article has been indexed from RedPacket Security Read the original article: LockBit 3.0 Ransomware Victim: tuvsud[.]com

Nozomi Networks Guardian and CMC denial of service | CVE-2023-32649

NAME__________Nozomi Networks Guardian and CMC denial of service Platforms Affected:Nozomi Networks Guardian/CMC 22.6.1 Risk Level:7.5… This article has been indexed from RedPacket Security Read the original article: Nozomi Networks Guardian and CMC denial of service | CVE-2023-32649

Mastodon spoofing | CVE-2023-42451

NAME__________Mastodon spoofing Platforms Affected:Mastodon Mastodon 4.2.0-beta1 Risk Level:7.7 Exploitability:Unproven Consequences:Gain Access DESCRIPTION__________ Mastodon could allow… This article has been indexed from RedPacket Security Read the original article: Mastodon spoofing | CVE-2023-42451