nopcorn.bsky.social
@nopcorn.bsky.social
Reposted
Exclusive: The backdoor inserted in v1.95.7 adds an "addToQueue" function which exfiltrates the private key through seemingly-legitimate CloudFlare headers.

Calls to this function are then inserted in various places that (legitimately) access the private key.
December 3, 2024 at 11:47 PM
Reposted
Zabbix SQL injection in user.get API (CVE-2024-42327)

support.zabbix.com/plugins/serv...
ZABBIX SUPPORT
support.zabbix.com
December 1, 2024 at 10:15 AM