Friday , November 22 2024

infosecbulletin

Sophos Web Appliance Critical Flaw Let Attacker Execute Arbitrary Code

Sophos has released a new security advisory that has fixed 3 of its significant vulnerabilities, allowing threat actors to execute arbitrary code injection on Sophos Web Appliance (SWA). CVE(s): CVE-2023-1671 – Pre-Auth Command Injection CVE-2022-4934 – Post-Auth Command Injection CVE-2020-36692 – Reflected XSS via POST method CVE-2023-1671 – Pre-Auth Command Injection in Sophos …

Read More »

Pay $20K To Infect Android Devices Via Google Play Store – Darkweb Report

In recent times, it has been observed by the security researchers at Kaspersky’s SecureList that the official Google Play store’s security has become increasingly vulnerable to the schemes of the threat actors. These shady actors have exploited various loopholes to develop tools that can effectively Trojanize the existing Android applications, making them …

Read More »

Black Hat Asia 2023

The Black Hat Trainings offer attendees individual technical courses on topics ranging from the latest in penetration testing to exploiting web applications and even defending and building SCADA systems. Often designed exclusively for Black Hat, these hands-on attack and defense courses are taught by industry and subject matter experts from …

Read More »

Cybersecurity for Critical Assets (CS4CA) APAC 2023

The critical infrastructure that provides our energy, utilities, healthcare and other basic foundations of our societies is fundamentally changing. As we continue to move our traditional technologies online, our IT and OT systems face increasingly significant risks. Meanwhile, challenges emerging from an increasing cybersecurity skills gap, new regulations and today’s …

Read More »