Russian State-Sponsored Actors Target Cleared Defense Contractor Networks

Historically, Russian state-sponsored cyber actors have used common but effective tactics to gain access to target networks, including spearphishing, credential harvesting, brute force/password spray techniques, and known vulnerability exploitation against…

Continue ReadingRussian State-Sponsored Actors Target Cleared Defense Contractor Networks

TP-Link Archer C90 DNS Response Stack-based Buffer Overflow Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer C90 1.0.6 Build 20200114 rel.73164(5553) routers. Authentication is not required to exploit this vulnerability. More https://www.zerodayinitiative.com/advisories/ZDI-22-080/

Continue ReadingTP-Link Archer C90 DNS Response Stack-based Buffer Overflow Vulnerability