September 3, 2023 at 04:16PM

■■■■□ Malicious actors could leverage a sneaky malware detection evasion technique and bypass endpoint security solutions by manipulating the Windows Container Isolation Framework. https://thehackernews.com/2023/08/hackers-can-exploit-windows-container.html https://t.me/cKure/12826

September 3, 2023 at 11:40AM

■■■□□ Data-Leak: Forever 21 has about 500 retail locations and an online store. It’s the second data breach in recent years after a massive theft of credit card numbers from its store point-of-sale machines in 2017. https://techcrunch.com/2023/08/31/forever-21-data-breach-half-million/ https://t.me/cKure/12825

September 3, 2023 at 10:29AM

■■■■□ CVE-2023–28072: Local Privilege Escalation in Alienware Command Center. https://medium.com/@matterpreter/cve-2023-28072-local-privilege-escalation-in-alienware-command-center-a836607762ba https://t.me/cKure/12824

September 2, 2023 at 03:09PM

■■□□□ CVE-2023-36250: CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file when creating a new record. https://github.com/BrunoTeixeira1996/CVE-2023-36250 https://t.me/cKure/12823

September 2, 2023 at 02:27PM

■■□□□ Session Hijacking Visual Exploitation is a tool that allows for the hijacking of user sessions by injecting malicious JavaScript code. https://github.com/doyensec/Session-Hijacking-Visual-Exploitation https://t.me/cKure/12820