Tag: SQL INJECTION
Keypoints :
Cyble Research and Intelligence Labs (CRIL) analyzed vulnerabilities disclosed between January 8 and 14, 2025.…Threat Actor: Unknown | unknown Victim: SAP | SAP
Key Point :
Two critical vulnerabilities (CVE-2025-0070 and CVE-2025-0066) could allow attackers to steal credentials and read decrypted information.…Threat Actor: UNC5337 | UNC5337 Victim: Ivanti | Ivanti
Key Point :
UNC5337 has exploited CVE-2025-0282, a critical vulnerability allowing code execution without authentication.…Threat Actor: (authenticated attacker, unauthenticated attacker) | threat actor Victim: (Palo Alto Networks, SonicWall, Aviatrix) | Palo Alto Networks, SonicWall, Aviatrix
Key Point :
Palo Alto Networks addressed multiple vulnerabilities in its Expedition tool, including SQL injection and XSS flaws.…Threat Actor: MirrorFace (Earth Kasha) | MirrorFace Victim: Japanese National Police Agency | Japanese National Police Agency
Key Point :
MirrorFace has conducted three major cyberattack campaigns targeting government, academia, media, and advanced industries.…Threat Actor: Unknown | unknown Victim: Radykal | Radykal
Key Point :
Two critical vulnerabilities identified: CVE-2024-51919 (arbitrary file upload) and CVE-2024-51818 (SQL injection).…Summary: A critical SQL injection vulnerability (CVE-2024-45387) has been discovered in Apache Traffic Control, posing severe risks to sensitive data and service integrity. Organizations are urged to upgrade to version 8.0.2 to mitigate potential threats.
Threat Actor: Malicious Actors | Malicious Actors Victim: Apache Traffic Control Users | Apache Traffic Control Users
Key Point :
Vulnerability CVE-2024-45387 has a CVSS score of 9.9, indicating critical severity.…Summary: Security researchers have identified critical vulnerabilities in the WPLMS and VibeBP plugins for WordPress, which could lead to unauthorized access and data breaches. These vulnerabilities have now been patched, but users are urged to update their systems immediately.
Threat Actor: Unknown | unknown Victim: WPLMS and VibeBP Users | WPLMS and VibeBP Users
Key Point :
Critical vulnerabilities included arbitrary file uploads, privilege escalation, and SQL injection.…### #HackingOperations #MoneyLaundering #SQLInjection
Summary: Vitalii Antonenko, a Ukrainian hacker, was sentenced to nearly six years in prison for his involvement in a complex hacking and money laundering operation that compromised numerous payment card data. He will also face supervised release and restitution payments following his prison term.…
### #OpenSourceSecurity #BusinessIntelligenceRisks #DataProtectionAwareness
Summary: The Apache Software Foundation has released Apache Superset 4.1.0 to address three critical security vulnerabilities that could allow attackers to bypass security controls and access sensitive data. Users are urged to upgrade to this version to mitigate risks associated with these vulnerabilities.…