July 9, 2024 at 02:29AM

■■■■□ RCE bug in widely used Ghostscript library now exploited in attacks. https://www.bleepingcomputer.com/news/security/rce-bug-in-widely-used-ghostscript-library-now-exploited-in-attacks/ https://t.me/cKure/14372

July 9, 2024 at 12:01AM

■■■■□ Solar 4RAYS threat intel team uncovers a new APT group “Lifting Zmiy” (eng. Lifting Serpent) that targets government organizations in Russia and Eastern Europe. The group hosted their C2 infrastructure on compromised servers, which were used in SCADA networks. https://rt-solar.ru/solar-4rays/blog/4506/ https://t.me/cKure/14371

July 7, 2024 at 06:05PM

■■■■□ How CVE-2022-24785 MomentJS Path Traversal Works: Detailed Exploit Guide. https://0xjay.com/how-cve-2022-24785-momentjs-path-traversal-works-detailed-exploit-guide https://t.me/cKure/14369

July 6, 2024 at 01:33PM

■■■■□ RockYou2024: 10 billion passwords leaked in the largest compilation of all time. https://cybernews.com/security/rockyou2024-largest-password-compilation-leak/ https://t.me/cKure/14366

July 6, 2024 at 01:28PM

Rockyou-2024 has been released on July 4, 2024, in a 45 GB zip file. Previous Rockyou-2021 had 8.4 billion passwords, and the new version has 1.5 billion (added by hacker ‘ObamaCare’), making it a 10 billion word-list. https://t.me/cKure/14362