Aggregator
CVE-2024-8450 | PLANET Technology GS-4210-24P2S Hardware 3.0 SNMPv1 Service hard-coded credentials
CVE-2024-8449 | PLANET Technology GS-4210-24P2S Hardware 3.0 Serial Console hard-coded credentials
CVE-2024-8452 | PLANET Technology GS-4210-24P2S Hardware 3.0 SNMPv3 Service risky encryption
CVE-2024-45200 | Nintendo Mario Kart 8 Deluxe up to 3.0.2 Local Multiplayer KartLANPwn stack-based overflow
CVE-2024-42496 | Techno Support Company Smart-tab Android App credentials storage
CVE-2024-41999 | Techno Support Company Smart-tab Android app debug code
CVE-2024-9328 | SourceCodester Advocate Office Management System 1.0 /control/edit_client.php id sql injection
CVE-2014-7109 | Nesvarnik 1 X.509 Certificate cryptographic issues (VU#582497)
CVE-2007-4507 | PHP 5.2.3 memory corruption (EDB-4304 / Nessus ID 25971)
Sygnia Managed Detection and Response – Delivering Better Detection
Sygnia MDR provides complete visibility across IT and OT environments to stay Continuously Secure in the face of endlessly evolving threats.
The post Sygnia Managed Detection and Response – Delivering Better Detection appeared first on Sygnia.
Windows 11 KB5043145 update causes reboot loops, blue screens
CVE-2016-1865 | Apple Mac OS X up to 10.11.5 Kernel null pointer dereference (HT206903 / Nessus ID 92496)
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
- CVE-2023-25280 D-Link DIR-820 Router OS Command Injection Vulnerability
- CVE-2020-15415 DrayTek Multiple Vigor Routers OS Command Injection Vulnerability
- CVE-2021-4043 Motion Spell GPAC Null Pointer Dereference Vulnerability
- CVE-2019-0344 SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
CISA’s VDP Platform 2023 Annual Report Showcases Success
Today, the Cybersecurity and Infrastructure Security Agency (CISA) released its Vulnerability Disclosure Policy (VDP) Platform 2023 Annual Report, highlighting the service’s remarkable success in 2023, its second full year of operation. Throughout 2023, CISA focused on advocating for the increased agency adoption of the VDP Platform, supporting federal civilian executive branch (FCEB) agencies in identifying vulnerabilities in their systems, and engaging the public security researcher community.
Public security researchers play a vital role in securing our federal government's networks. As part of CISA's persistent and ongoing collaboration with the public security researcher community, CISA issued Binding Operational Directive (BOD) 20-01 in 2020, which requires every FCEB agency to establish a VDP. These VDPs follow industry and community best practices, including giving authorization to participating public security researchers and committing to not pursue legal action for good-faith research.
CISA's VDP Platform complements BOD 20-01 by giving FCEB agencies an easy way to establish a VDP and to engage with public security researchers. CISA appreciates the contributions by thousands of public security researchers to date and looks forward to continuing to further broaden this collaboration in the future.
To learn more about the VDP Platform, please visit the Vulnerability Disclosure Policy (VDP) Platform webpage and view the VDP 101 video on CISA’s YouTube channel.