SRA has identified multiple vulnerabilities in VSee Clinic that can lead to unauthorized access to and deletion of files as well as exposure of SFTP credentials.
SRA has identified multiple vulnerabilities in Sangoma Switchvox SMB that can lead to stored and reflected cross-site scripting (XSS), SQL injection (SQLi), remote code execution (RCE), and local file inclusion (LFI).
macOS is a relatively common sight within many modern company environments. Despite this, there don’t seem to be many decent sources around for how to dump local user hashes for offline pasword cracking attacks. This post is a short writeup on how to access and transform hashes into a form hashcat can use.