PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

Difference Between Agent-Based and Network-Based Internal Vulnerability Scanning

jeudi 16 juin 2022 à 13:00
For years, the two most popular methods for internal scanning: agent-based and network-based were considered to be about equal in value, each bringing its own strengths to bear. However, with remote working now the norm in most if not all workplaces, it feels a lot more like agent-based scanning is a must, while network-based scanning is an optional extra. This article will go in-depth on the

High-Severity RCE Vulnerability Reported in Popular Fastjson Library

jeudi 16 juin 2022 à 10:25
Cybersecurity researchers have detailed a recently patched high-severity security vulnerability in the popular Fastjson library that could be potentially exploited to achieve remote code execution. Tracked as CVE-2022-25845 (CVSS score: 8.1), the issue relates to a case of deserialization of untrusted data in a supported feature called "AutoType." It was patched by the project maintainers in 

MaliBot: A New Android Banking Trojan Spotted in the Wild

jeudi 16 juin 2022 à 06:00
A new strain of Android malware has been spotted in the wild targeting online banking and cryptocurrency wallet customers in Spain and Italy, just weeks after a coordinated law enforcement operation dismantled FluBot. The information stealing trojan, codenamed MaliBot by F5 Labs, is as feature-rich as its counterparts, allowing it to steal credentials and cookies, bypass multi-factor

Critical Flaw in Cisco Secure Email and Web Manager Lets Attackers Bypass Authentication

jeudi 16 juin 2022 à 05:28
Cisco on Wednesday rolled out fixes to address a critical security flaw affecting Email Security Appliance (ESA) and Secure Email and Web Manager that could be exploited by an unauthenticated, remote attacker to sidestep authentication. Assigned the CVE identifier CVE-2022-20798, the bypass vulnerability is rated 9.8 out of a maximum of 10 on the CVSS scoring system and stems from improper

Panchan: A New Golang-based Peer-To-Peer Botnet Targeting Linux Servers

mercredi 15 juin 2022 à 15:05
A new Golang-based peer-to-peer (P2P) botnet has been spotted actively targeting Linux servers in the education sector since its emergence in March 2022. Dubbed Panchan by Akamai Security Research, the malware "utilizes its built-in concurrency features to maximize spreadability and execute malware modules" and "harvests SSH keys to perform lateral movement." <!--adsense--> The feature-packed