Security Affairs newsletter Round 471 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-49606 | A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory corruption and could lead to remote code execution. An attacker needs to make an unauthenticated HTTP request to trigger this vulnerability. NVD description · AI analysis pending | 9.8 | 63% | PoC ×2 |
| — | |
| CVE-2024-3661 | DHCP can add routes to a client’s routing table via the classless static route option (121). DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN. NVD description · AI analysis pending | 7.6 | 4% | PoC ×5 |
| — |
Full article408 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
Cybercrime
Traficom: Android malware that steals bank information
BTC-e Operator Pleads Guilty to Money Laundering Conspiracy
LockBit leader unmasked and sanctioned
New series of measures issued against the administrator of LockBit
Generative AI: Raising the stakes for fraud in online gambling
Massive webshop fraud ring steals credit cards from 850,000 people
Zscaler Investigates Hacking Claims After Data Offered for Sale
Dell discloses data breach of customers’ physical addresses
Threat actor says he scraped 49M Dell customer addresses before the company found out
University System of Georgia: 800K exposed in 2023 MOVEit attack
Malware
Surge of JavaScript Malware in sites with vulnerable versions of LiteSpeed Cache Plugin
Mal.Metrica Redirects Users to Scam Sites
Protecting Networks from Opportunistic Ivanti Pulse Secure Vulnerability Exploitation
Hacking
French cyberwarriors ready to test their defense against hackers and malware during the Olympics
Technical Deep Dive: Understanding the Anatomy of a Cyber Intrusion
TunnelVision (CVE-2024-3661): How Attackers Can Decloak Routing-Based VPNs For a Total VPN Leak
LLM PENTEST: LEVERAGING AGENT INTEGRATION FOR RCE
Alleged Europol Breach by IntelBroker
Russian hackers hijack Ukrainian TV to broadcast Victory Day parade
Von der Leyen’s campaign website hit by cyberattack
Intelligence and Information Warfare
UNDERSTANDING CHINA’S TAIWAN CYBER STRATEGY
Fighting disinformation gets harder, just when it matters most
MoD data breach: State involvement cannot be ruled out in armed forces hack, says Grant Shapps
APT28 campaign targeting Polish government institutions
A (Strange) Interview With the Russian-Military-Linked Hackers Targeting US Water Utilities
Signal’s Katherine Maher Problem
Cybersecurity
Russia’s Anti-Satellite Nuke Could Leave Lower Orbit Unusable, Test Vehicle May Already Be Deployed
BIG VULNERABILITIES IN NEXT-GEN BIG-IP
Chrome Zero-Day Alert — Update Your Browser to Patch New Vulnerability
European Parliament’s recruitment application compromised in data breach
Encrypted services Apple, Proton and Wire helped Spanish police identify activist
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
you might also like
leave a comment
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/163036/breaking-news/security-affairs-newsletter-round-471-by-pierluigi-paganini-international-edition.html