Remove 2024 Remove Accountability Remove Penetration Testing
article thumbnail

CVE-2024-27295: Directus Flaw Opens Door to Account Takeovers

Penetration Testing

A flaw (CVE-2024-27295) was found in Directus, a versatile open-source content management platform favored by developers for its flexibility and customization options. This vulnerability leaves thousands of projects potentially exposed to account hijacking attacks....

article thumbnail

Urgent GitLab Update Patches Account Takeover Flaw, Other High-Severity Bugs

Penetration Testing

These flaws range from the potential for complete account hijacking to resource-draining denial-of-service... The post Urgent GitLab Update Patches Account Takeover Flaw, Other High-Severity Bugs appeared first on Penetration Testing.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Mastodon Alert: CVE-2024-23832 Unlocks Account Takeover Threat

Penetration Testing

A critical vulnerability in the decentralized social networking platform Mastodon could be exploited to impersonate and take over any remote account.

article thumbnail

Threat Actor Deploys LummaC2 and Rhadamanthys Stealers in Attacks on Taiwanese Facebook Accounts

Penetration Testing

A new phishing campaign, tracked by Cisco Talos, has been targeting Facebook business account users in Taiwan since at least July 2024.

article thumbnail

CVE-2024-34710: Wiki.js Vulnerability Exposes Users to Potential Account Takeover

Penetration Testing

Wiki.js, a popular open-source wiki engine, has patched a critical security vulnerability that could have allowed attackers to inject malicious code and potentially compromise user accounts, including those with elevated privileges. The vulnerability, designated... The post CVE-2024-34710: Wiki.js

article thumbnail

CVE-2024-34082: Grav CMS Vulnerability Opens Door to Account Takeovers

Penetration Testing

Grav, a popular open-source content management system (CMS) known for its speed and flexibility, has a critical security flaw that could expose websites to malicious account takeovers and unauthorized access to sensitive files.

article thumbnail

PoC Exploit Releases for Cisco SSM On-Prem Account Takeover (CVE-2024-20419) Flaw

Penetration Testing

A critical vulnerability, identified as CVE-2024-20419, has been publicly disclosed by security researcher Mohammed Adel, who published a detailed writeup along with proof-of-concept (PoC) exploit code.