Severity High Analysis Summary Cyber espionage actors, aka APT32 (OceanLotus Group), are carrying out intrusions into private sector companies across multiple industries and have also targeted […]
Severity Medium Analysis Summary CVE-2021-20269 Linux Kernel could allow a local authenticated attacker to obtain sensitive information, caused by incorrect permissions on vmcore-dmesg.txt file in kexec-tools. […]
Severity High Analysis Summary APT C-35 aka (Donot Team) has been actively dropping malicious RTF sample for template injection. The group has a history of attacking […]
Severity High Analysis Summary A campaign has been uncovered that looks like the work of Iran-based APT group Helix Kitten, aka OilRig and APT34. Initial analysis […]
Severity High Analysis Summary CVE-2020-13959 Apache Velocity Tools is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the default error page for […]
Severity High Analysis Summary CVE-2021-22992 F5 BIG-IP is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the is_hdr_criteria_matches function. By sending a […]
Severity High Analysis Summary APT C-35 aka (Donot Team) has been actively dropping malicious RTF sample for template injection. The group has a history of attacking […]
Severity High Analysis Summary CVE-2021-27077 Microsoft Windows could allow a local authenticated attacker to gain elevated privileges on the system, caused by a flaw in the […]
Severity High Analysis Summary CVE-2021-21488 SAP NetWeaver Knowledge Management is vulnerable to a denial of service, caused by an insecure deserialization flaw. By sending a specially-crafted […]