CISA Publishes Anatomy of Advanced Ivanti VPN Malware Hackers using Trojans connected to a malware family deployed by Chinese nation-state hackers are actively exploiting a now-patched vulnerability in Ivanti Connect Secure appliances. The malware "contains capabilities of a rootkit, dropper, backdoor, bootkit, proxy and tunneler."
Customer Credentials Possibly Compromised at EHR Vendor Acquired by Oracle in 2022 Oracle is dealing with a hacking incident involving legacy patient data of Cerner electronic health record customers. Oracle, which acquired Cerner in 2022, is reportedly telling clients the hack involved compromised credentials for systems scheduled to migrate to the cloud.
Hackers Claim on BreachForums to Have Stolen 'Highly Sensitive' Data Israeli cybersecurity firm Check Point rejected Monday a hacker's assertion that he stole "highly sensitive" information offered for sale on an online marketplace for illicit data. The incident "doesn't pose any risk or have any security implications to our customers or employees."
New Turing Institute Report Urges Government to Create AI Crime Task Force British law enforcement agencies are ill-equipped to tackle artificial intelligence-enabled cybercrime, a report by The Alan Turing Institute says, pointing to an "enormous gap" between police technical capabilities and the growing sophistication of threat actors.
VMware Workstation users report that the software's automatic update functionality is broken after Broadcom redirected the download URL to its generic support page, triggering certificate errors. [...]
A vulnerability classified as problematic has been found in ownCloud up to 5.0.5. This affects an unknown part. The manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2014-9043. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in ownCloud up to 7.0.1. This vulnerability affects unknown code. The manipulation leads to information disclosure.
This vulnerability was named CVE-2014-9044. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in ownCloud up to 5.0.5. This issue affects some unknown processing. The manipulation leads to improper authentication.
The identification of this vulnerability is CVE-2014-9045. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in ownCloud up to 5.0.5. Affected is the function OC_Util::getUrlContent. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2014-9046. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in ownCloud up to 5.0.5 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2014-9047. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in ownCloud up to 5.0.5 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2014-9048. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in ownCloud up to 7.0.1. It has been classified as problematic. This affects an unknown part of the component Session. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2014-9049. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in ownCloud up to 5.0.18/6.0.6/7.0.4 and classified as critical. This issue affects some unknown processing of the component Blacklist Filter. The manipulation as part of UTF-8 Encoding leads to injection.
The identification of this vulnerability is CVE-2015-3013. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in ownCloud Server up to 7.0.5/8.0.3 on Windows. This vulnerability affects unknown code of the component routing. The manipulation leads to path traversal.
This vulnerability was named CVE-2015-4716. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.