Plus récents

CVE-2022-26134 - Critical severity unauthenticated Remote Code Execution vulnerability in Confluence Server and Data Center.

  • CVE-2022-1802 : Prototype pollution in Top-Level Await implementation

  • CVE-2022-1529 : Untrusted input used in JavaScript object indexing, leading to prototype pollution

mozilla.org/en-US/security/adv

CVE-2022-27224 : Vulnerability in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12. A low privilege authenticated attacker can perform command injection as the root user.

pentestpartners.com/security-b

Microsoft probes complaints of domain controller headaches

Windows update breaks authentication for some server admins

theregister.com/2022/05/12/win

CVE-2022–26923 This vulnerability allowed a low-privileged user to escalate privileges to domain administrator in a default Active Directory environment with the Active Directory Certificate Services server role installed.

research.ifcr.dk/9e098fe298f4

🚩 Wild West Hackin Fest (wildwesthackinfest.com)

Statikk Shiv

Leveraging Electron (electronjs.org) Applications For Post-Exploitation

📰 raw.githubusercontent.com/Fuzz

🚨 CVE-2022-27588 - QNAP VS Series NVR running QVR : this vulnerability allows remote attackers to run arbitrary commands.

qnap.com/en/security-advisory/

CVE-2022-1388 - A vulnerability may allow an unauthenticated attacker with network access to the BIG-IP system to execute arbitrary system commands.

support.f5.com/csp/article/K23

TLStorm 2 - NanoSSL TLS library misuse leads to 5 vulnerabilities in the implementation of TLS communications in multiple models of Aruba and Avaya switches.

armis.com/blog/tlstorm-2-nanos

Plus anciens