Security
Headlines
HeadlinesLatestCVEs

Tag

#mac

CVE-2021-33436

NoMachine for Windows prior to version 6.15.1 and 7.5.2 suffer from local privilege escalation due to the lack of safe DLL loading. This vulnerability allows local non-privileged users to perform DLL Hijacking via any writable directory listed under the system path and ultimately execute code as NT AUTHORITY\SYSTEM.

CVE
#vulnerability#mac#windows#auth
Azure Database for PostgreSQL Flexible Server Privilege Escalation and Remote Code Execution

MSRC was informed by Wiz, a cloud security vendor, under Coordinated Vulnerability Disclosure (CVD) of an issue with the Azure Database for PostgreSQL Flexible Server that could result in unauthorized cross-account database access in a region. By exploiting an elevated permissions bug in the Flexible Server authentication process for a replication user, a malicious user could leverage an improperly anchored regular expression to bypass authentication to gain access to other customers’ databases.

QNAP Advises to Mitigate Remote Hacking Flaws Until Patches are Available

Network-attached storage (NAS) appliance maker QNAP on Wednesday said it's working on updating its QTS and QuTS operating systems after Netatalk last month released patches to contain seven security flaws in its software. Netatalk is an open-source implementation of the Apple Filing Protocol (AFP), allowing Unix-like operating systems to serve as file servers for Apple macOS computers. <!-

A Peek into Visa's AI Tools Against Fraud

Visa has invested heavily in data analytics and artificial intelligence over the past five years to secure the movement of money and keep fraud rates low.

Synopsys to Acquire WhiteHat Security from NTT

Acquisition expands security software-as-a-service capabilities.

Emotet is Back From ‘Spring Break’ With New Nasty Tricks

The Botnet appears to use a new delivery method for compromising Windows systems after Microsoft disables VBA macros by default.

Miele Benchmark Programming Tool 1.1.49 / 1.2.71 Privilege Escalation

Miele Benchmark Programming Tool versions 1.1.49 and 1.2.71 suffer from a privilege escalation vulnerability.

Trojan-Downloader.Win32.Agent Insecure Permissions

Trojan-Downloader.Win32.Agent malware suffers from an insecure permissions vulnerability.

Backdoor.Win32.Cafeini.b Man-In-The-Middle

Backdoor.Win32.Cafeini.b malware suffers from a man-in-the-middle vulnerability.

Trojan-Downloader.Win32.Small.ahlq Insecure Permissions

Trojan-Downloader.Win32.Small.ahlq malware suffers from an insecure permissions vulnerability.