2024-04-12 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
\[Mise à jour du 10 mai 2024\] Le CERT-FR est intervenu pour le traitement d'une compromission par rançongiciel au sein d'une entité française. Dans le cadre de cette attaque, la vulnérabilité a été exploitée pour ensuite réaliser une latéralisation dans le système d'information de la victime et...
P0
2024-02-09 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
\[Mise à jour du 19 mars 2024\] Le CERT-FR a connaissance de codes d'exploitation publics et de nouvelles tentatives d'exploitation. Le 8 février 2024, Fortinet a publié l'avis de sécurité concernant la vulnérabilité critique CVE-2024-21762 affectant le VPN SSL de FortiOS. Cette vulnérabilité...
P5
2023-11-14 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Palo Alto discovered that Azure CLI commands were found to leak sensitive credentials and environment variables in GitHub Actions logs. This issue affects both public and private repositories, potentially exposing secrets to unauthorized parties. The problem stems from the Azure CLI's design to echo back accessed/created/updated/deleted resource information, which can include sensitive data. Later research by Orca Security revealed that AWS CLI and Google Cloud CLI were affected by the same iss…
P0
2023-08-01 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Is it worth switching to Microsoft Defender Antivirus? Spoiler alert: We think yes! Explore why Defender is a solid AV solution.
P0
2022-12-15 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
In Azure Serverless Functions, a new container is generated by the host for every function, which is then terminated and deleted after several minutes. Palo Alto discovered that an API call was available to bind one path to another within the container (called "init_server_pkg_mount_BindMount") that could be called by a low-privileged user but executed with root privileges. This could enable a malicious tenant to escalate their privileges to root, and then escape their container by abusing the …
P0
2022-08-17 12:14 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Links between ATMZOW JS-sniffer and Hancitor
P0
2022-06-21 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Dive into the types of threats we’ve thwarted with Managed Antivirus and how IT teams are seeing more value from making the switch.
P0
2022-06-07 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Executing Cloud Functions or Cloud Run in any project and in any organization allowed bypassing the GKE Authorized Networks (aka Kubernetes control plane firewalls) of a cluster in a different project or organization.
P0
2022-04-12 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
The AWS VPN Client application is affected by an arbitrary file write as SYSTEM, which can lead to privilege escalation and an information disclosure vulnerability that allows the user's Net-NTLMv2 hash to be leaked via a UNC path in a VPN configuration file.
P10
2021-12-21 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Our partners at United Systems and F1 Solutions talk about their respective journeys with our Managed Microsoft Defender solution.
P0
2016-11-14 16:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
How do you protect computers from attackers if you’re not familiar with hacking techniques? The historical answer to this question has been antivirus and firewalls. However, the last several years have demonstrated hackers can slip past these preventative technologies and cause devastating results to the victims.
P0