Remove pl
article thumbnail

Drupal addressed CVE-2020-13671 Remote Code Execution flaw

Security Affairs

The vulnerability could be exploited by an attacker by uploading files with certain types of extensions (phar, php, pl, py, cgi, html, htm, phtml, js, and asp) to the server to achieve remote code execution. The vulnerability, tracked as CVE-2020-13671, has been classified as critical according to the NIST Common Misuse Scoring System.

Hacking 112
article thumbnail

Microsoft will add new file types to the list of blocked ones in Outlook on the Web

Security Affairs

appref-ms ” extension used by Windows ClickOnce, the “. udl ” extension used by Microsoft Data Access Components (MDAC), the “. wsb ” extension used by Windows sandbox, and the “ cer “, “ crt ” and “ der ” extensions associated with digital certificates. ” reads the post published by Microsoft.”While

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Drupal emergency updates fix critical arbitrary PHP code execution

Security Affairs

The flaw could be exploited by an attacker by uploading files with certain types of extensions (phar, php, pl, py, cgi, html, htm, phtml, js, and asp) to the server to achieve remote code execution. The vulnerability, tracked as CVE-2020-13671, has been classified as critical according to the NIST Common Misuse Scoring System.

Hacking 106
article thumbnail

Credential-stealing malware disguises itself as Telegram, targets social media users

Malwarebytes

nl/pl/sa/sg/es/se/ae/co.uk/com/com.au/com.br/mx/tr It uses specific methods for each browser to exfiltrate the data stored in the target browsers: Google Chrome Mozilla Firefox Internet Explorer Microsoft Edge. The target websites it looks for are: www.facebook.com www.instagram.com www.amazon.ca/cn/eg/fr/de/in/it/co.jp/nl/pl/sa/sg/es/se/ae/co.uk/com/com.au/com.br/mx/tr

Media 129
article thumbnail

SentinelOne released free decryptor for ThiefQuest ransomware

Security Affairs

The ransomware currently targets the following file extensions, as reported by ZDNet : pdf,doc,jpg,txt,pages,pem,cer,crt,php,py,h,m,hpp,cpp,cs,pl,p,p3,html,webarchive,zip,xsl,xslx,docx,ppt,pptx,keynote,js,sqlite3,wallet,dat.

article thumbnail

New EvilQuest ransomware targets macOS users

Security Affairs

The ransomware currently targets the following file extensions, as reported by ZDNet : pdf,doc,jpg,txt,pages,pem,cer,crt,php,py,h,m,hpp,cpp,cs,pl,p,p3,html,webarchive,zip,xsl,xslx,docx,ppt,pptx,keynote,js,sqlite3,wallet,dat.

article thumbnail

Winnti APT continues to target game developers in Russia and abroad

Security Affairs

The files were used two months later, on August 20, 2020, in attacks that also leveraged a self-contained loader for Cobalt Strike Beacon PL shellcode. The discovery lead the experts into believing that they detected traces of preparation for, and subsequent successful implementation of, an attack on Battlestate Games.

Malware 79