2025-01-06 21:16 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress identified an emerging threat involving Cleo’s LexiCom, VLTransfer, and Harmony software, known as CVE-2024-55956, commonly used to manage file transfers. Read more about this emerging threat on the Huntress Blog.
P25
2024-12-29 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
AWS Neuron SDK has reintroduced a dependency confusion vulnerability three times in four years. The issue stems from using the --extra-index-url parameter in pip install commands, which allows potential installation of malicious packages from PyPI instead of AWS's private repository. Despite previous reports, AWS has not fully addressed the problem, leaving new packages vulnerable to exploitation.
P0
2024-12-11 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in Azure API Management Developer Portal allows arbitrary code execution and secret exfiltration. The issue stems from a workflow that loads untrusted data from opened issues, potentially allowing attackers to inject malicious commands. This could lead to code execution in the runner, granting access to sensitive tokens and permissions.
P0
2024-12-11 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Team Huntress has analyzed Cleo's software vulnerability CVE-2024-55956. Take a look at the technical breakdown of a new family of malware we’ve named Malichus.
P5
2024-11-12 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in GCP's Vertex AI service allows privilege escalation and unauthorized access to sensitive LLM models. Attackers can exfiltrate these models by exploiting misconfigurations in access controls and service bindings. By exploiting custom job permissions, researchers were able to escalate their privileges and gain unauthorized access to all data services in the project. In addition, deploying a poisoned model in Vertex AI led to the exfiltration of all other fine-tuned models, posi…
P10
2024-11-01 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in Amazon DataZone allowed potential attackers to assume roles in AWS accounts by exploiting a confused deputy problem. This could have granted unauthorized access to sensitive data managed by DataZone or other AWS services accessible by the IAM role trusting DataZone. The issue has been resolved, with no customers reportedly impacted.
P0
2024-11-01 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A technique called "repo swatting" allows attackers to delete GitHub and block GitLab accounts by exploiting file upload features and abuse reporting mechanisms. Attackers upload malicious files to a target's repository, then report the account for hosting malicious content, potentially resulting in account deletion. The vulnerability was partially mitigated by October 2024 via changes in upload URL paths and requirement for each uploader to be authenticated (in GitHub).
P0
2024-10-24 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
The AWS Cloud Development Kit (CDK) is a way of deploying infrastructure-as-code. The vulnerability involves AWS CDK’s use of a predictable S3 bucket name format (cdk-{Qualifier}-assets-{Account-ID}-{Region}), where the default “random” qualifier (hnb659fds) is common and easily guessed. If an AWS customer deletes this bucket and reuses CDK, an attacker who claims the bucket can inject malicious CloudFormation templates, potentially gaining admin access. Attackers supposedly only need the AWS a…
P0
2024-10-23 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
**[Mise à jour du 14 janvier 2025]** **Publication des correctifs** Le 14 janvier 2025, Fortinet a publié un avis de sécurité relatif à la vulnérabilité CVE-2024-50566 qui correspond à la vulnérabilité de type jour-zéro pour laquelle une preuve de concept a été publiée en novembre 2024. Des...
P5
2024-10-22 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
Ivanti a publié plusieurs avis de sécurité sur des vulnérabilités affectant CSA qui sont activement exploitées : * le 10 septembre 2024, Ivanti a publié un avis de sécurité concernant la vulnérabilité CVE-2024-8190 qui permet à un attaquant, authentifié en tant qu'administrateur, d'exécuter du...
P5
2024-10-15 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in AWS CloudShell allowed users to gain unintended command-line access to the underlying AWS infrastructure. During a training session, a delegate unexpectedly received the identity context of an EC2 instance role within an ECS cluster, instead of the intended AWS account. This issue potentially bypassed existing controls aimed at preventing lateral movement and access to higher-privileged management roles.
P0
2024-10-09 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in GitLab Pages allowed attackers to take over dangling custom domains pointing to 'instanceX.gitlab.io'. The issue occured when adding an unverified custom domain to GitLab Pages, which serves content for 7 days before disabling. This could lead to cookie stealing, phishing campaigns, and bypassing of Content-Security Policies and CORS.
P0
2024-09-26 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Multiple "pwn request" vulnerabilities were discovered in Google Cloud Data Fusion, which is based on open-source CDAP code. These vulnerabilities affect GitHub Actions and allow for remote code execution (RCE) and compromise of build artifacts. The issues potentially impact both the Google Cloud platform and GitHub's CI/CD infrastructure.
P15
2024-09-16 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Google Cloud Composer is a managed service for Apache Airflow. Tenable discovered that the Cloud Composer package was vulnerable to dependency confusion, which could have allowed attackers to inject malicious code when the package was compiled from source. This could have led to remote code execution on machines running Cloud Composer, which include various other GCP services as well as internal servers at Google. The dependency confusion stemmed from Google's risky recommendation in their docu…
P15
2024-09-16 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
The Document AI service unintentionally allows users to read any Cloud Storage object in the same project, in a way that isn't properly documented. The Document AI service agent is auto-assigned with excessive permissions, allowing it to access all objects from Cloud Storage buckets in the same project. Malicious actors can exploit this to exfiltrate data from Cloud Storage by indirectly leveraging the service agent's permissions. This vulnerability is an instance of transitive access abuse, a …
P0
2024-09-13 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in Azure API Management allowed users with Reader access to escalate privileges to Contributor level by accessing admin user keys via the ARM API. This permitted full management capabilities through the Direct Management API, including reading secrets and modifying configurations.
P0
2024-09-10 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
Le 22 août 2024, Sonicwall a publié un correctif concernant la vulnérabilité critique CVE-2024-40766 affectant les pare-feux Sonicwall génération 5, 6 et 7. Cette vulnérabilité, de type contrôle d'accès défaillant, permet à un attaquant de provoquer un déni de service à distance, une atteinte à...
P5
2024-08-19 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in Azure Kubernetes Services allowed attackers to escalate privileges and access cluster credentials. Affected clusters used Azure CNI for network configuration and Azure for network policy. Attackers could exploit this issue to steal data and cause financial and reputational damage. The vulnerability has been fixed by Microsoft after disclosure by Mandiant.
P0
2024-08-13 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
P10
2024-08-09 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
Le 4 août 2024, Roundcube a publié des correctifs concernant les vulnérabilités critiques CVE-2024-42008 et CVE-2024-42009 affectant son serveur de courriel. Ces vulnérabilités permettent des injections de code indirectes à distance (XSS) qui peuvent, par exemple, conduire à la récupération du...
P5
2024-08-07 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Semperis researchers discovered vulnerabilities in Microsoft applications that allowed privilege elevation in Entra ID beyond expected authorization controls. The most severe finding enabled adding users to privileged roles, including Global Administrator, without proper permissions. The issues affected Device Registration Service, Viva Engage, and Microsoft Rights Management Service. Microsoft has since resolved the vulnerabilities.
P0
2024-08-03 20:24 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress gives you a non-technical breakdown of the SlashAndGab ConnectWise ScreenConnect Vulnerability; dig into the insights on how we discovered it and supported the community along the way.
P0
2024-08-01 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
What is a CVE Numbering Authority (CNA)? Learn how CNAs assign CVE IDs, why they matter for vulnerability management, and how Huntress became one.
P0
2024-07-24 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A privilege escalation vulnerability dubbed "ConfusedFunction" was discovered in Google Cloud Platform's Cloud Functions service. It allows attackers to escalate privileges from Cloud Function permissions to the default Cloud Build service account during function deployment. The vulnerability affects both first and second-generation Cloud Functions.
P10
2024-07-10 05:55 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Delaying security updates and neglecting regular reviews created vulnerabilities that were exploited by attackers, resulting in severe ransomware consequences.
P20
2024-07-01 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
Le 1 juillet 2024, OpenSSH a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-6387. Cette vulnérabilité permet à un attaquant non authentifié d'exécuter du code arbitraire à distance avec les privilèges *root*. L'éditeur précise que les versions 8.5p1 à 9.7p1 sont...
P5
2024-06-14 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
GitHub Copilot Chat VS Code Extension was vulnerable to data exfiltration via prompt injection when analyzing untrusted source code. The vulnerability allowed attackers to access previous conversation turns and append information from the chat history to an image URL, which was then automatically retrieved by Copilot, sending the data to the attacker.
P0
2024-06-11 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
CVE-2024-37293 affects the AWS Deployment Framework's bootstrap process, potentially allowing privilege escalation if an actor has permissions to change CodeBuild projects or Lambda functions. The issue is fixed in version 4.0 and above. AWS recommends immediate upgrade and temporary mitigation by adding a permissions boundary to roles created by ADF in the management account.
P15
2024-06-03 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Tenable Research discovered a vulnerability in Azure allowing attackers to bypass firewall rules based on Service Tags by forging requests from trusted services. It affects over 10 Azure services and enables access to internal/private Azure resources. Microsoft updated documentation to clarify Service Tags' security limitations.
P0
2024-04-29 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in Microsoft Graph allowed attackers to conduct password-spray attacks without detection. The issue involved switching the 'common' authentication endpoint with that of an unrelated tenant, thereby avoiding the appearance of logon attempts in the victim's logs. This technique could allow attackers to validate user credentials through verbose error messages, but actual successful logons using these credentials would still be recorded in the victims' logs (regardless of endpoint).
P0