Aggregator
Microsoft Pushes Governance, Sheds Unused Apps in Security Push
4 months ago
Microsoft outlined steps it's taken over the past year under its Security Future Initiative, which was launched late last year in the wake of a high-profile attack by Chinese attackers and only months before another serious breach by a Russia-link threat group.
The post Microsoft Pushes Governance, Sheds Unused Apps in Security Push appeared first on Security Boulevard.
Jeffrey Burt
Cicada3301
4 months ago
cohenido
Threat Actors Shift to JavaScript-Based Phishing Attacks
4 months ago
Cybercriminals are increasingly prioritizing script-based phishing techniques over one based on traditional malicious documents
Amber Albatross arrives with stealer capabilities | Red Canary Threat Intelligence
4 months ago
Red Canary
Join KubeCrash Fall 2024 for Platform Engineering the Cloud Native Way
4 months ago
I’m excited to be back at KubeCrash this fall! Mark your calendars to join us on Wednesday, October 9th starting at 10 AM ET, as KubeCrash pulls together a day packed with actionable insights and practical takeaways on platform engineering in 2024.
The post Join KubeCrash Fall 2024 for Platform Engineering the Cloud Native Way appeared first on Security Boulevard.
Stevie Caldwell
Hackers deploy AI-written malware in targeted attacks
4 months ago
While cybercriminals have used generative AI technology to create convincing emails, government agencies have warned about the potential abuse of AI tools to creating malicious software, despite the safeguards and restrictions that vendors implemented. [...]
Bill Toulas
CVE-2024-8067 | Perforce Helix up to 2024.1 Patch 1 Windows ANSI API Unicode best fit argument injection
4 months ago
A vulnerability, which was classified as critical, was found in Perforce Helix up to 2024.1 Patch 1. Affected is an unknown function of the component Windows ANSI API Unicode Handler. The manipulation of the argument best fit leads to argument injection.
This vulnerability is traded as CVE-2024-8067. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-41725 | Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE cross site scripting (icsa-24-268-04)
4 months ago
A vulnerability, which was classified as problematic, has been found in Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE and ProGauge MAGLINK LX4 CONSOLE. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-41725. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43692 | Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE Resource Sub Page authentication bypass (icsa-24-268-04)
4 months ago
A vulnerability classified as very critical was found in Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE and ProGauge MAGLINK LX4 CONSOLE. This vulnerability affects unknown code of the component Resource Sub Page. The manipulation leads to authentication bypass using alternate channel.
This vulnerability was named CVE-2024-43692. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43423 | Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE hard-coded password (icsa-24-268-04)
4 months ago
A vulnerability classified as very critical has been found in Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE and ProGauge MAGLINK LX4 CONSOLE. This affects an unknown part. The manipulation leads to use of hard-coded password.
This vulnerability is uniquely identified as CVE-2024-43423. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45373 | Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE privileges management (icsa-24-268-04)
4 months ago
A vulnerability was found in Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE and ProGauge MAGLINK LX4 CONSOLE. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper privilege management.
This vulnerability is handled as CVE-2024-45373. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43693 | Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE POST Request command injection (icsa-24-268-04)
4 months ago
A vulnerability was found in Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE and ProGauge MAGLINK LX4 CONSOLE. It has been declared as very critical. Affected by this vulnerability is an unknown functionality of the component POST Request Handler. The manipulation leads to command injection.
This vulnerability is known as CVE-2024-43693. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
James Cameron 加入 Stability AI 董事会
4 months ago
传奇电影人 James Cameron 加入了 AI 创业公司 Stability AI 的董事会。CEO Prem Akkaraju 表示,James Cameron 生活在未来,等待我们追赶上。Stability AI 的使命是改变下个世纪的视觉媒体,为创作者提供全栈 AI 管线,让他们梦想成真。James Cameron 将有助于它实现这一使命。Stability AI 董事会的其它成员包括了 Greycroft 联合创始人 Dana Settle、Coatue Management COO Colin Bryant,以及担任执行主席的前 Facebook 总裁 Sean Parker。Stability AI 的文本图像模型 Stable Diffusion 是 Hugging Face 上最受欢迎的图像模型,下载量愈 1.5 亿次。
CVE-2024-45066 | Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE POST Request command injection (icsa-24-268-04)
4 months ago
A vulnerability was found in Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE and ProGauge MAGLINK LX4 CONSOLE. It has been classified as very critical. Affected is an unknown function of the component POST Request Handler. The manipulation leads to command injection.
This vulnerability is traded as CVE-2024-45066. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8310 | OPW Fuel Managements Systems SiteSentinel prior 17Q2.1 missing authentication (icsa-24-268-01)
4 months ago
A vulnerability was found in OPW Fuel Managements Systems SiteSentinel and classified as very critical. This issue affects some unknown processing. The manipulation leads to missing authentication.
The identification of this vulnerability is CVE-2024-8310. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42831 | Elaine Marketing Automation up to 6.18.17 wrapper_dialog.php dialog cross site scripting
4 months ago
A vulnerability has been found in Elaine Marketing Automation up to 6.18.17 and classified as problematic. This vulnerability affects unknown code of the file /system/interface/wrapper_dialog.php. The manipulation of the argument dialog leads to cross site scripting.
This vulnerability was named CVE-2024-42831. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
VDB-278391 | Google Cloud Storage XML API Audit Log insufficient logging
4 months ago
A vulnerability, which was classified as problematic, was found in Google Cloud Storage XML API and Cloud Console Private API Service. This affects an unknown part of the component Audit Log Handler. The manipulation leads to insufficient logging.
It is possible to initiate the attack remotely. There is no exploit available.
The real existence of this vulnerability is still doubted at the moment.
This product is a managed service. This means that users are not able to maintain vulnerability countermeasures themselves.
vuldb.com
Cybersecurity Incident Affects Arkansas City Water Treatment Facility
4 months ago
Arkansas City’s water treatment facility faced a cyber incident on Sunday and has since switched to manual operations
CVE-2023-26688 | CS-Cart MultiVendor 4.16.1 Administration Interface product_data cross site scripting
4 months ago
A vulnerability, which was classified as problematic, has been found in CS-Cart MultiVendor 4.16.1. Affected by this issue is some unknown functionality of the component Administration Interface. The manipulation of the argument product_data leads to cross site scripting.
This vulnerability is handled as CVE-2023-26688. The attack may be launched remotely. There is no exploit available.
vuldb.com