A vulnerability was found in PGP Freeware 7.0.3 and classified as critical. Affected by this issue is some unknown functionality of the component Message Decoder. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2002-0685. The attack may be launched remotely. There is no exploit available.
A vulnerability, which was classified as critical, was found in ISC BIND 4.9.8. Affected is the function getnetbyname/getnetbyaddr of the component DNS Resolver. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2002-0684. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
While ransomware attacks against medical devices don't happen often, disruptive cyber incidents that affect the availability of the IT systems that medical devices rely on are a big concern that needs the industry's critical attention, said Jessica Wilkerson of the FDA.
Many Charging Cable Interfaces Have Exposed SSH and HTTP Ports, Researchers Warn Researchers demonstrated that multiple brands of EV charging stations have vulnerabilities due to manufacturers often leaving open and unsecured SSH and HTTP ports. The risks of these vulnerabilities range from an expanded attack surface to a launching pad for assaults on the power grid.
Also: Indian Hackers Gets 5 Years in Prison for Stealing $20M Every week, ISMG rounds up cybersecurity incidents in digital assets. This week, the Nigerian government dropped charges on Binance executive Tigran Gambaryan, an Indian hacker faces five years in prison for stealing $20 million, a $4.5M Tapioca DAO exploit, Transak data breach.
Also: Payment Card Theft Trends, Internet Archive Update This week, bulk data transfers to China, credit card theft, the Internet Archive still recovering and the Change Healthcare tally is now 100M. Ukraine fought phishers, civil society against the UN cybercrime treaty, TA866 and virtual hard drives spread malware. Google verified Sir Isaac Newton.
Mandiant Says High-Severity Flaw Could Give Attackers Remote Unauthenticated Access Researchers at Mandiant say a new threat cluster, first observed June 27, has been exploiting a Fortinet zero-day that the network edge device manufacturer publicly disclosed Wednesday. Researchers said they can't assess the threat actor's motivation or location.
While ransomware attacks against medical devices don't happen often, disruptive cyber incidents that affect the availability of the IT systems that medical devices rely on are a big concern that needs the industry's critical attention, said Jessica Wilkerson of the FDA.
Also: Payment Card Theft Trends, Internet Archive Update This week, bulk data transfers to China, credit card theft, the Internet Archive still recovering and the Change Healthcare tally is now 100M. Ukraine fought phishers, civil society against the UN cybercrime treaty, TA866 and virtual hard drives spread malware. Google verified Sir Isaac Newton.
Mandiant Says High-Severity Flaw Could Give Attackers Remote Unauthenticated Access Researchers at Mandiant say a new threat cluster, first observed June 27, has been exploiting a Fortinet zero-day that the network edge device manufacturer publicly disclosed Wednesday. Researchers said they can't assess the threat actor's motivation or location.
Effectiv's 30-Person Team to Streamline Identity Services, Help Socure Grow Revenue Socure has acquired Effectiv, integrating its engineering team of 30 to strengthen identity verification capabilities. The $136 million deal aims to speed up customer onboarding, enhance transaction monitoring, and deliver cross-platform solutions, with the product integration expected in 45 days.
Irish Data Protection Commission Cites Social Platform for GDPR Violations The Irish Data Protection Commission imposed a 310 million euro fine on LinkedIn for violating a European privacy law stemming from the company's use of customer data. It ordered the social media platform to bring its data processing under compliance.
A vulnerability was found in Kashipara Responsive School Management System 3.2.0. It has been declared as critical. This vulnerability affects unknown code of the file /smsa/view_students.php of the component Student Details Handler. The manipulation leads to improper access controls.
This vulnerability was named CVE-2024-41250. The attack can be initiated remotely. There is no exploit available.
A vulnerability was found in Oracle MySQL Server up to 8.0.37/8.4.0 and classified as critical. This issue affects some unknown processing of the component DDL. The manipulation leads to improper authorization.
The identification of this vulnerability is CVE-2024-21127. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Oracle MySQL Server up to 8.0.39/8.4.2/9.0.1 and classified as critical. Affected by this issue is some unknown functionality of the component DDL. The manipulation leads to improper authorization.
This vulnerability is handled as CVE-2024-21198. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.