Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
“This vulnerability gives an unauthenticated attacker remote control over PaperCut’s trusted configuration, which could be used to execute arbitrary Java code inside the application’s
68-year-old imprisoned after making $1.3 million by pirating IPTV services
Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting.
“This new privacy standard works in tandem
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of
In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions
Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims.
The post In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions appeared first on SecurityWeek.
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active
AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?
ATF Confirms Cyber Incident After Ransomware Group Claims Attack
The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.
The post ATF Confirms Cyber Incident After Ransomware Group Claims Attack appeared first on SecurityWeek.
