Device Bound Session Credentials (DBSC) is Chrome's answer to session cookie theft, usually by InfoStealer malware. Instead of a cookie being a bearer token that works anywhere it's pasted, DBSC binds the session to a private key that lives in your device's hardware and
The Adform platform was briefly hijacked to distribute a crypto-stealing script. Here’s everything we know about the incident, plus tips on how to protect yourself.
SAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs.
The post SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities appeared first on SecurityWeek.
Google suspend une fonction d’IA de Google Earth après des alertes sur les fausses images et la désinformation.
The Water Watch Center launched at DEF CON aims to help under-resourced utilities protect their systems against hackers.
The post US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ appeared first on SecurityWeek.
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.