Piergiorgio Venuti

Stealing Windows Credentials Using Google Chrome

Read More

Condividi


RSS

Piu’ articoli…

Categorie …

Tags

RSS Feed sconosciuto

RSS Feed sconosciuto

RSS Full Disclosure

  • APPLE-SA-08-06-2026-2 macOS Sequoia 15.7.9 13 Agosto 2026
    Posted by Apple Product Security via Fulldisclosure on Aug 13APPLE-SA-08-06-2026-2 macOS Sequoia 15.7.9 macOS Sequoia 15.7.9 addresses the following issues. Information about the security content is also available at https://support.apple.com/en-us/148171. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Screen Sharing Available for: macOS Sequoia Impact: An attacker […]
  • APPLE-SA-08-06-2026-3 macOS Sonoma 14.8.9 13 Agosto 2026
    Posted by Apple Product Security via Fulldisclosure on Aug 13APPLE-SA-08-06-2026-3 macOS Sonoma 14.8.9 macOS Sonoma 14.8.9 addresses the following issues. Information about the security content is also available at https://support.apple.com/en-us/148172. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Screen Sharing Available for: macOS Sonoma Impact: An attacker […]
  • Dangling DNS record for bastion.certb.cdp.bethesda.net 6 Agosto 2026
    Posted by shed riot on Aug 06# Summary The hostname resolved to an address within a dynamic cloud IP pool. The address had been released and was no longer controlled by the organisation operating the hostname. This condition is referred to as an "afterlife" issue. Unlike a conventional CNAME-based subdomain takeover, the DNS record pointed […]
  • CL.0 desync in www.microsoft.com 6 Agosto 2026
    Posted by shed riot on Aug 06# Summary I reported the issue to the Microsoft Security Response Center twice: * VULN-165381, MSRC case 102964 * VULN-165876, MSRC case 103259 In both cases, they do not appear to have even looked at the PoCs, and so have failed to adequately investigate before reaching a decision. # […]
  • CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated Authentication Bypass (PoC) 6 Agosto 2026
    Posted by Öner Efe Güngör on Aug 06Hello Full Disclosure, I&apos;d like to share an independent lab Proof-of-Concept for CVE-2026-15013. ### CVE-2026-15013 – miniOrange SAML SSO
  • [KIS-2026-16] Telenia Software TVox <= 26.5.3 (nice) Local Privilege Escalation Vulnerability 6 Agosto 2026
    Posted by Egidio Romano on Aug 06------------------------------------------------------------------------------- Telenia Software TVox
  • [KIS-2026-15] Telenia Software TVox <= 26.5.3 (action_audio.php) OS Command Injection Vulnerability 6 Agosto 2026
    Posted by Egidio Romano on Aug 06------------------------------------------------------------------------------------- Telenia Software TVox
  • [KIS-2026-14] Telenia Software TVox <= 26.5.3 (set_env.php) Authentication Bypass Vulnerability 6 Agosto 2026
    Posted by Egidio Romano on Aug 06--------------------------------------------------------------------------------- Telenia Software TVox
  • [KIS-2026-13] vBulletin <= 6.2.1 (runMaths) Remote Code Execution Vulnerability 6 Agosto 2026
    Posted by Egidio Romano on Aug 06----------------------------------------------------------------- vBulletin
  • [SYSS-2026-050]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190) 6 Agosto 2026
    Posted by Matthias Deeg via Fulldisclosure on Aug 06Advisory ID: SYSS-2026-050 Product: DCMTK (DICOM ToolKit) Manufacturer: OFFIS e.V. / DCMTK Community Affected Version(s): 3.7.0 Tested Version(s): 3.7.0 Vulnerability Type: Integer Overflow or Wraparound (CWE-190) Risk Level: Medium Solution Status: Fixed Manufacturer Notification: 2026-07-02 Solution Date: 2026-07-03 Public Disclosure:...

Customers