Author: cyberknight
-
CVE-2024-45492
CVE-2024-45492 is a critical vulnerability found in the widely used libexpat XML parsing library, specifically affecting versions prior to 2.6.3. This flaw originates from an integer overflow in the `nextScaffoldPart` function in 32-bit systems. Attackers can exploit this vulnerability to remotely execute arbitrary code or cause a denial of service, making it especially dangerous. It…
-
CVE-2024-45491
The CVE-2024-45491 vulnerability is an integer overflow issue identified in libexpat versions prior to 2.6.3. This vulnerability occurs in the `dtdCopy` function of the `xmlparse.c` file, specifically impacting 32-bit platforms. The problem arises when an attacker can exploit this overflow in systems where `UINT_MAX` equals `SIZE_MAX`. The vulnerability is critical, with a CVSS score of…
-
CVE-2024-45490
The CVE-2024-45490 vulnerability is a security flaw identified in versions of the Expat library (specifically libexpat) prior to version 2.6.3. The vulnerability occurs in the xmlparse.c file, which is responsible for parsing XML data. The issue arises when the function XML_ParseBuffer fails to reject negative lengths during buffer parsing. This oversight can potentially lead to…
-
RansomHub
RansomHub is a cybercriminal group operating a ransomware-as-a-service (RaaS) model that emerged in early 2024. It evolved from cybercriminal groups formerly known as Cyclops and Knight, and has recently attracted high-profile affiliates from other prominent variants such as LockBit and ALPHV. Here are some key points about the RansomHub cybercriminal group: RansomHub’s combination of sophisticated…
-
List of Advanced Persistent Threats (APTs)
See more details on:
-
APT27
APT27, also known as Advanced Persistent Threat 27, is a Chinese cyber espionage group known for conducting sophisticated cyberattacks primarily targeting organizations for intelligence gathering. The group, which is also referred to as Emissary Panda, LuckyMouse, and Bronze Union, has been active since at least 2010 and is believed to be associated with the Chinese…
-
Windows TCP/IP Remote Code Execution Vulnerability (CVE-2024-38063)
A critical security vulnerability identified as CVE-2024-38063 has been discovered in the Windows TCP/IP stack, affecting all supported versions of Windows and Windows Server, including Server Core installations. This vulnerability allows remote code execution (RCE) without user interaction, classifying it as a zero-click exploit. The flaw, which Microsoft has rated as critical with a CVSS…
-
Post-quantum cryptography (PQC)
Post-quantum cryptography (PQC) is the development and study of cryptographic algorithms designed to remain secure against the computational power of quantum computers. Classical cryptographic systems like RSA and ECC (Elliptic Curve Cryptography) rely on problems like integer factorization and discrete logarithms, which can be efficiently solved by quantum algorithms such as Shor’s algorithm. This could…
-
Almost 2.7 billion records of personal information for people in the United States were leaked from National Public Data
In April 2024, National Public Data (NPD), a data provider company that performs background checks and fraud prevention, experienced a major data breach that exposed nearly 2.7 billion records. This breach compromised highly sensitive personal information, including full names, Social Security numbers, addresses, and dates of birth. The breach was initially reported when a hacker…
-
Zabbix vulnerability – Remote code execution within ping script (CVE-2024-22116)
CVE-2024-22116 is a critical arbitrary code execution vulnerability in Zabbix Server. This vulnerability affects versions 6.4.0 to 6.4.15 and 7.0.0alpha1 to 7.0.0rc2. The issue stems from improper control over script parameters in the Ping script execution feature within the Monitoring Hosts section of Zabbix Server. Attackers with restricted administrative privileges can exploit this vulnerability to…
-
Zscaler security vulnerability (CVE-2024-23483)
CVE-2024-23483 is a vulnerability identified in the Zscaler Client Connector on macOS systems running versions below 4.2. It is categorized as an OS command injection flaw, stemming from improper input validation. The vulnerability allows remote attackers to exploit the lack of safeguards by injecting OS commands, potentially enabling unauthorized access and control over the affected…
-
The Epic Fail of CrowdStrike: The Global Crash on July 19, 2024
Introduction On July 19, 2024, a critical update from CrowdStrike’s Falcon platform led to widespread system failures, causing significant disruptions across multiple sectors globally. The flawed update impacted Windows systems, resulting in major outages and operational interruptions. Incident Overview CrowdStrike, a leading cybersecurity firm, issued an update that inadvertently caused Windows systems to crash. This…