New Linux CVE with score or 9.9 of 10, regarding unauthenticated remote code execution (RCE) vulnerability expected to be revealed on 30th September 2024, with more details on 6th October. Watch @evilsocket for updates.
@Scott_Helme@troyhunt@haveibeenpwned@securityheaders This doesn't seem to take 301 redirects into account. https://t.co/jsgzLIlQ8a has a security.txt file, but all non-www. requests are being redirected to www.
🛑 [NEWS] @RevolutApp has suffered a serious #DataBreach which may have led to the compromise of over 50,000 customers’ personal information > @philmuncaster reports https://t.co/OhkJvCL02a
A 15-year-old developer account hijacking #vulnerability has been disclosed in the PEAR #PHP repository that could've allowed attackers to launch supply-chain attacks by releasing new malicious versions of existing packages.
Details: https://t.co/zv3HkttXlw
#infosec#hackernews
LAPSUS$ extortion group claims to have breached @Okta. They have released 8 photos as proof.
The photos we are sharing has been edited so no sensitive information or user identities are displayed.
Image 1 - 4 attached below.
How to test your apps for #log4shell vulnerability
1. Generate a DNS token https://t.co/vCzVG0O03i
2. Wrap that token in
Prefix: ${jndi:ldap://
Suffix: /a}
3. Use that value in search forms, profile data, settings etc. of your apps
4. Get notified when you triggered a reaction
"This model enables 0day devs to generate substantial earnings by renting the 0day out while waiting for a definitive buyer...renting parties could test proposed 0day & later decide whether to purchase the exploit on an exclusive or non-exclusive basis"
https://t.co/ZwnjQluyQb
it looks like Twitch has been hacked in a massive breach. A 125GB file reportedly includes Twitch source code, details on creator $$$ payouts, and even a Steam competitor. Full details here: https://t.co/wgI7wOYYxY