PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

Critical SQL Injection Flaws Expose Gentoo Soko to Remote Code Execution

mercredi 28 juin 2023 à 09:24
Multiple SQL injection vulnerabilities have been disclosed in Gentoo Soko that could lead to remote code execution (RCE) on vulnerable systems. "These SQL injections happened despite the use of an Object-Relational Mapping (ORM) library and prepared statements," SonarSource researcher Thomas Chauchefoin said, adding they could result in RCE on Soko because of a "misconfiguration of the database.

Critical SQL Injection Flaws Expose Gentoo Soko to Remote Code Execution

mercredi 28 juin 2023 à 09:24

New Mockingjay Process Injection Technique Could Let Malware Evade Detection

mardi 27 juin 2023 à 16:22
A new process injection technique dubbed Mockingjay could be exploited by threat actors to bypass security solutions to execute malicious code on compromised systems. "The injection is executed without space allocation, setting permissions or even starting a thread," Security Joes researchers Thiago Peixoto, Felipe Duarte, and Ido Naor said in a report shared with The Hacker News. "The

New Mockingjay Process Injection Technique Could Let Malware Evade Detection

mardi 27 juin 2023 à 16:22

New Ongoing Campaign Targets npm Ecosystem with Unique Execution Chain

mardi 27 juin 2023 à 16:10
Cybersecurity researchers have discovered a new ongoing campaign aimed at the npm ecosystem that leverages a unique execution chain to deliver an unknown payload to targeted systems. "The packages in question seem to be published in pairs, each pair working in unison to fetch additional resources which are subsequently decoded and/or executed," software supply chain security firm Phylum said in