■■■□□ Unknown threat actors are scanning for WordPress websites with Epsilon Framework themes installed on over 150,000 sites and vulnerable to Function Injection attacks that could lead to full site takeovers. These attacks use POST requests to admin-ajax.php and as such do not leave distinct log entries, though they will be visible Wordfence Live Traffic. https://www.bleepingcomputer.com/news/security/hackers-are-actively-probing-millions-of-wordpress-sites/…
All posts in Uncategorized
November 18, 2020 at 11:10AM
● Yet another website: wordlists.assetnote.io https://t.me/cKure/6044
November 17, 2020 at 08:35PM
■■□□□ The EVMs. https://mobile.twitter.com/realDonaldTrump/status/1327732691979137041 https://t.me/cKure/6043
November 17, 2020 at 08:18PM
■■■□□ #DataLeak, #CyberAttack: Renowned Japanese video gaming firm Capcom has acknowledged that the gaming giant lost sensitive data, including sales reports, employee personal details, and financial information in a ransomware attack carried out by Ragnar Locker Gang. The data was leaked online after ransome was not paid. ● What was leaked? 》https://mobile.twitter.com/stardustsummons/status/1328164220488224768 https://t.me/cKure/6042
November 17, 2020 at 08:10PM
■■■■□ Many Drupal sites are vulnerable to the following: Endpoint: /node/1?_format=hal_json https://www.ambionics.io/blog/drupal8-rce https://t.me/cKure/6040
November 17, 2020 at 08:05PM
■■■■□ RCE via Server-Side Template Injection. https://cyc10n3.medium.com/rce-via-server-side-template-injection-ad46f8e0c2ae https://t.me/cKure/6039
November 17, 2020 at 07:55PM
■■■■□ Interesting thread wrt. Fuzzing: https://mobile.twitter.com/Bl1nnnk/status/1328720903975309313 https://t.me/cKure/6038
November 17, 2020 at 07:13PM
■■■□□ #DataLeak: A #UnitedStates based electronics retailer, TronicsXchange has exposed over 2.6 million files, including ID cards and biometric images, after a misconfigured AWS S3 bucket was discovered. https://www.infosecurity-magazine.com:443/news/80000-id-cards-fingerprint-exposed/ https://t.me/cKure/6037
November 17, 2020 at 04:07PM
■■□□□ OceanLotus continues with its cyber espionage operations. https://cybleinc.com/2020/11/17/oceanlotus-continues-with-its-cyber-espionage-operations/ https://t.me/cKure/6035
November 17, 2020 at 02:48PM
■■■□□ 2FA Bypass On Instagram Through A Vulnerable Endpoint. https://medium.com/@aryalsamipofficial59/2fa-bypass-on-instagram-through-a-vulnerable-endpoint-b092498af178 https://t.me/cKure/6033
