Aggregator
Kill
CISA Warns of Active Exploitation of Microsoft SharePoint Vulnerability (CVE-2024-38094)
CVE-2002-0337 | RealNetworks RealPlayer 8.0 MP3 File resource consumption (XFDB-8320 / BID-4200)
IBM Addresses AI, Quantum Security Risks with New Platform
IBM is rolling out Guardian Data Security Center, a framework designed to give enterprises the tools they need to address the emerging cyberthreats that come the ongoing development of generative AI and quantum computing.
The post IBM Addresses AI, Quantum Security Risks with New Platform appeared first on Security Boulevard.
HPE security advisory (AV24-605)
CVE-2002-0336 | Galacticomm Worldgroup Lite Personal Server up to 3.20 FTP Server LIST memory corruption (XFDB-8297 / BID-4185)
Meow
情报分析的关键工具:情报报告与情报简报
如何从社交网络获取情报
Microsoft обновляет Windows: новое меню и 8 исправлений под капотом
「原生」鸿蒙,华为 AI 生态的「最后一片拼图」
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation, as confirmed by Fortinet.
- CVE-2024-47575 Fortinet FortiManager Missing Authentication Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
CISA encourages users and administrators to see Fortinet Advisory FG-IR-24-423 and apply necessary patches and mitigations. Additionally, see Investigating FortiManager Zero-Day Exploitation (CVE-2024-47575) from Google Threat Intelligence for more information.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Keep your secrets secret: 5 core tips — and a call to action on modernizing
Many organizations have experienced significant data breaches after inadvertently exposing secrets such as tokens, API keys, digital certificates, and user credentials that attackers gained access to. Many factors have made it harder to avoid secrets exposure, including the adoption of cloud services and DevOps practices, the increase in distributed work environments, the rise of automated workflows, and the use of unmonitored tools and external services.
The post Keep your secrets secret: 5 core tips — and a call to action on modernizing appeared first on Security Boulevard.