[FD] Spammers Using storage[.]googleapis[.]com ?!!?

2021-08-03 Thread Nick Boyce
I notice that among the spam in my Gmail spam folder, there are a number of "address-check" type messages (i.e. that just seek confirmation my address exists), which attempt to get their response by performing a scripted redirect via a web property belonging to Google .. and I tend to think "Hu

[FD] Stb_truetype library heap buffer overflows (many CVEs, no CVEs yet)

2021-08-03 Thread Marcin Kozlowski
Hi list, Posting here for transparency reasons. A 16k stars project, used in, I can imagine game engines, UI, Android/iOS/embedded. Used in another 30k stars project and 11k from even Google (also possibly not fixed). OpenCV 55k stars seems to be also affected (new branch only). Attack vector thro

[FD] Backdoor.Win32.WinShell.40 / Unauthenticated Remote Command Execution

2021-08-03 Thread malvuln
Discovery / credits: Malvuln - malvuln.com (c) 2021 Original source: https://malvuln.com/advisory/c98e23742807f3cb5a095f34e0eb0e52.txt Contact: malvul...@gmail.com Media: twitter.com/malvuln Threat: Backdoor.Win32.WinShell.40 Vulnerability: Unauthenticated Remote Command Execution Description: The