Tag

#Deserialization

7 published stories tagged with Deserialization.

highDefensive GuidanceJul 23, 20263 min read

Unauthorized action execution possible via deserialization flaw in Johnson Controls Victor software

A high-severity deserialization flaw has been identified in Johnson Controls' victor software running on Windows.

criticalExploited VulnerabilitiesJul 21, 20262 min read

Exploitation of SharePoint deserialization flaw enables remote code execution and machine key theft

Attackers are exploiting a critical deserialization flaw in on-premise Microsoft SharePoint deployments to execute code and steal machine keys.

criticalExploited VulnerabilitiesJul 16, 20262 min read

Attackers exploit unauthenticated remote code execution vulnerabilities in Microsoft SharePoint environments

馃毃 Critical remote code execution is being actively exploited in Microsoft SharePoint environments.

highExploited VulnerabilitiesJul 16, 20262 min read

Authenticated Site Owners exploit SharePoint deserialization flaw to execute remote code

Attackers are actively exploiting a critical remote code execution flaw in Microsoft SharePoint.

highExploited VulnerabilitiesJul 8, 20263 min read

UNK_MassTraction exploits Roundcube vulnerabilities to target university physics and engineering departments

A suspected China-aligned threat group, tracked as UNK_MassTraction, is targeting physics and engineering departments at US and Canadian universities.

highExploited VulnerabilitiesJul 2, 20262 min read

Attackers exploit Microsoft SharePoint deserialization flaw to achieve remote code execution

Attackers are actively exploiting a high-severity deserialization flaw in Microsoft SharePoint to execute code remotely.

highAPT / Nation-StateJul 1, 20262 min read

Remote Code Execution Vulnerability in Microsoft SharePoint Under Active Exploitation by Attackers

Attackers are actively exploiting a high-severity deserialization vulnerability in Microsoft SharePoint.