PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

Bugs in Wyze Cams Could Let Attackers Takeover Devices and Access Video Feeds

jeudi 31 mars 2022 à 15:27
Three security vulnerabilities have been disclosed in the popular Wyze Cam devices that grant malicious actors to execute arbitrary code and access camera feeds as well as unauthorizedly read the SD cards, the latter of which remained unresolved for nearly three years after the initial discovery. The security flaws relate to an authentication bypass (CVE-2019-9564), a remote code execution bug

New Python-based Ransomware Targeting JupyterLab Web Notebooks

jeudi 31 mars 2022 à 15:11
Researchers have disclosed what they say is the first-ever Python-based ransomware strain specifically designed to target exposed Jupyter notebooks, a web-based interactive computing platform that allows editing and running programs via a browser. "The attackers gained initial access via misconfigured environments, then ran a ransomware script that encrypts every file on a given path on the

Hackers Increasingly Using 'Browser in a Browser' Technique in Ukraine Related Attacks

jeudi 31 mars 2022 à 15:02
A Belarusian threat actor known as Ghostwriter (aka UNC1151) has been spotted leveraging the recently disclosed browser-in-the-browser (BitB) technique as part of their credential phishing campaigns exploiting the ongoing Russo-Ukrainian conflict. The method, which masquerades as a legitimate domain by simulating a browser window within the browser, makes it possible to mount convincing social

Unpatched Java Spring Framework 0-Day RCE Bug Threatens Enterprise Web Apps Security

jeudi 31 mars 2022 à 07:52
A zero-day remote code execution (RCE) vulnerability has come to light in the Spring framework shortly after a Chinese security researcher briefly leaked a proof-of-concept (PoC) exploit on GitHub before deleting their account. According to cybersecurity firm Praetorian, the unpatched flaw impacts Spring Core on Java Development Kit (JDK) versions 9 and later and is a bypass for another

QNAP Warns of OpenSSL Infinite Loop Vulnerability Affecting NAS Devices

jeudi 31 mars 2022 à 05:23
Taiwanese company QNAP this week revealed that a selected number of its network-attached storage (NAS) appliances are affected by a recently-disclosed bug in the open-source OpenSSL cryptographic library. "An infinite loop vulnerability in OpenSSL has been reported to affect certain QNAP NAS," the company said in an advisory published on March 29, 2022. "If exploited, the vulnerability allows