Aggregator
Feds Fine Mental Health Clinic $100K in 2020 HIPAA Case
9 months 1 week ago
LA County Clinic Delayed Access to Patient's Medical Records During Pandemic
Federal regulators have fined a Los Angeles county mental health clinic $100,000 for failure to provide a patient with timely access to her requested health records during the COVID-19 pandemic. The case is the U.S. government's 51st HIPAA patient right-of-access enforcement action.
Federal regulators have fined a Los Angeles county mental health clinic $100,000 for failure to provide a patient with timely access to her requested health records during the COVID-19 pandemic. The case is the U.S. government's 51st HIPAA patient right-of-access enforcement action.
Coast Guard Warns of Continued Risks in Chinese Port Cranes
9 months 1 week ago
Military Says Ship-to-Shore Cranes Made in China Include Dangerous Security Flaws
The United States Coast Guard is continuing to warn of significant security risks embedded in ship-to-shore cranes developed by companies with ties to Beijing while issuing new sensitive requirements for ports operating Chinese-made cranes across the country.
The United States Coast Guard is continuing to warn of significant security risks embedded in ship-to-shore cranes developed by companies with ties to Beijing while issuing new sensitive requirements for ports operating Chinese-made cranes across the country.
Nightwing CEO on Post-Raytheon Independence, Cyber Expertise
9 months 1 week ago
Nightwing's John DeSimone Talks Growth, Threats, National Security and AI Strategy
Nightwing CEO John DeSimone reveals how the company’s independence from Raytheon allows it to better serve customers, invest in intelligence, advanced AI and data solutions, address sophisticated cyberthreats, and maintain a no-fail mission approach in the face of rising security threats.
Nightwing CEO John DeSimone reveals how the company’s independence from Raytheon allows it to better serve customers, invest in intelligence, advanced AI and data solutions, address sophisticated cyberthreats, and maintain a no-fail mission approach in the face of rising security threats.
Feds Seize PopeyeTools Marketplace, Charge Alleged Operators
9 months 1 week ago
Justice Department Dismantles Cybercrime Hub, Announces Charges and Seizes Crypto
The Justice Department has seized PopeyeTools, a notorious cybercrime marketplace, while announcing criminal charges for three alleged operators behind the website, which generated over $1.7 million in revenue, according to a Wednesday announcement.
The Justice Department has seized PopeyeTools, a notorious cybercrime marketplace, while announcing criminal charges for three alleged operators behind the website, which generated over $1.7 million in revenue, according to a Wednesday announcement.
Let's Give Thanks for How Far We've Come - and Forge Ahead!
9 months 1 week ago
Cybersecurity Training and Education Must Evolve to Keep Pace With the Profession
Over the past few decades, cybersecurity has evolved from a niche concern into a global priority, creating a vast and dynamic career field. While we celebrate the journey, let's also focus on how today's cybersecurity professionals will shape the future.
Over the past few decades, cybersecurity has evolved from a niche concern into a global priority, creating a vast and dynamic career field. While we celebrate the journey, let's also focus on how today's cybersecurity professionals will shape the future.
Feds Fine Mental Health Clinic $100K in 2020 HIPAA Case
9 months 1 week ago
LA County Clinic Delayed Access to Patient's Medical Records During Pandemic
Federal regulators have fined a Los Angeles county mental health clinic $100,000 for failure to provide a patient with timely access to her requested health records during the COVID-19 pandemic. The case is the U.S. government's 51st HIPAA patient right-of-access enforcement action.
Federal regulators have fined a Los Angeles county mental health clinic $100,000 for failure to provide a patient with timely access to her requested health records during the COVID-19 pandemic. The case is the U.S. government's 51st HIPAA patient right-of-access enforcement action.
Coast Guard Warns of Continued Risks in Chinese Port Cranes
9 months 1 week ago
Military Says Ship-to-Shore Cranes Made in China Include Dangerous Security Flaws
The United States Coast Guard is continuing to warn of significant security risks embedded in ship-to-shore cranes developed by companies with ties to Beijing while issuing new sensitive requirements for ports operating Chinese-made cranes across the country.
The United States Coast Guard is continuing to warn of significant security risks embedded in ship-to-shore cranes developed by companies with ties to Beijing while issuing new sensitive requirements for ports operating Chinese-made cranes across the country.
Nightwing CEO on Post-Raytheon Independence, Cyber Expertise
9 months 1 week ago
Nightwing's John DeSimone Talks Growth, Threats, National Security and AI Strategy
Nightwing CEO John DeSimone reveals how the company’s independence from Raytheon allows it to better serve customers, invest in intelligence, advanced AI and data solutions, address sophisticated cyberthreats, and maintain a no-fail mission approach in the face of rising security threats.
Nightwing CEO John DeSimone reveals how the company’s independence from Raytheon allows it to better serve customers, invest in intelligence, advanced AI and data solutions, address sophisticated cyberthreats, and maintain a no-fail mission approach in the face of rising security threats.
Feds Seize PopeyeTools Marketplace, Charge Alleged Operators
9 months 1 week ago
Justice Department Dismantles Cybercrime Hub, Announces Charges and Seizes Crypto
The Justice Department has seized PopeyeTools, a notorious cybercrime marketplace, while announcing criminal charges for three alleged operators behind the website, which generated over $1.7 million in revenue, according to a Wednesday announcement.
The Justice Department has seized PopeyeTools, a notorious cybercrime marketplace, while announcing criminal charges for three alleged operators behind the website, which generated over $1.7 million in revenue, according to a Wednesday announcement.
Securing the Software Supply Chain: Checkmarx One Expands its Offerings
9 months 1 week ago
The software supply chain is under siege. Threat actors increasingly exploit weaknesses in code
Ubuntu系统软件中的5个漏洞潜藏了10年才被发现
9 months 1 week ago
Ubuntu系统中的实用程序Needrestart近日被曝出存在5个本地权限提升(LPE)漏洞,这些漏洞已经潜藏了10年才被发现。
Forums Refresh
9 months 1 week ago
Over the past year we have been hard at work on refreshing the Kali Forums, and today we are proud t
CVE-2024-50968 | itsourcecode Agri-Trading Online Shopping System 1.0 Add to Cart quantity behavioral workflow
9 months 1 week ago
A vulnerability was found in itsourcecode Agri-Trading Online Shopping System 1.0. It has been classified as problematic. Affected is an unknown function of the component Add to Cart. The manipulation of the argument quantity with the input -0 leads to enforcement of behavioral workflow.
This vulnerability is traded as CVE-2024-50968. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2017-13227 | Google Android 8.0/8.1 Autofill Service information disclosure
9 months 1 week ago
A vulnerability was found in Google Android 8.0/8.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Autofill Service. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2017-13227. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-49758 | LibreNMS up to 24.9.x ExamplePlugin cross site scripting
9 months 1 week ago
A vulnerability was found in LibreNMS up to 24.9.x. It has been classified as problematic. This affects an unknown part of the component ExamplePlugin. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-49758. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-49754 | LibreNMS up to 24.9.x API-Access Page token cross site scripting
9 months 1 week ago
A vulnerability was found in LibreNMS up to 24.9.x. It has been rated as problematic. This issue affects some unknown processing of the component API-Access Page. The manipulation of the argument token leads to cross site scripting.
The identification of this vulnerability is CVE-2024-49754. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-49759 | LibreNMS up to 24.9.x Manage User Access Page bill_name cross site scripting
9 months 1 week ago
A vulnerability classified as problematic has been found in LibreNMS up to 24.9.x. Affected is an unknown function of the component Manage User Access Page. The manipulation of the argument bill_name leads to cross site scripting.
This vulnerability is traded as CVE-2024-49759. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41784 | IBM Sterling Secure Proxy 6.0.0.0/6.0.0.1/6.0.0.2/6.0.0.3/6.1.0.0 URL path traversal
9 months 1 week ago
A vulnerability was found in IBM Sterling Secure Proxy 6.0.0.0/6.0.0.1/6.0.0.2/6.0.0.3/6.1.0.0. It has been classified as problematic. Affected is an unknown function of the component URL Handler. The manipulation leads to path traversal: '...' (triple dot).
This vulnerability is traded as CVE-2024-41784. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50352 | LibreNMS up to 24.9.x Device Overview Page name cross site scripting
9 months 1 week ago
A vulnerability was found in LibreNMS up to 24.9.x. It has been classified as problematic. This affects an unknown part of the component Device Overview Page. The manipulation of the argument name leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-50352. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com