Aggregator
Change Healthcare Attack Cost Estimate Reaches Nearly $2.9B
1 year 8 months ago
Most IT Restored, But UHG Is Still Catching Up and Aiming to Win Back Clients
UnitedHealth Group has raised its estimates to nearly $2.9 billion for the total costs this fiscal year of the cyberattack on its Change Healthcare IT services unit. UHG said it is also working to catch up with claims processing and to win back clients disenfranchised by the attack.
UnitedHealth Group has raised its estimates to nearly $2.9 billion for the total costs this fiscal year of the cyberattack on its Change Healthcare IT services unit. UHG said it is also working to catch up with claims processing and to win back clients disenfranchised by the attack.
Iranian Hackers Using Brute Force on Critical Infrastructure
1 year 8 months ago
Advisory Warns Iranian Threat Actors Use 'Push Bombing' to Target Critical Sectors
Iranian cyber actors are increasingly using brute force techniques, such as password spraying and multifactor authentication push bombing, to target critical infrastructure sectors, according to a cybersecurity advisory released Wednesday by the Cybersecurity and Infrastructure Security Agency.
Iranian cyber actors are increasingly using brute force techniques, such as password spraying and multifactor authentication push bombing, to target critical infrastructure sectors, according to a cybersecurity advisory released Wednesday by the Cybersecurity and Infrastructure Security Agency.
UK Reports 50% Spike in 'Nationally Significant' Incidents
1 year 8 months ago
New NCSC Chief Also Warns of Threefold Increase in Severe Cyberattacks
The U.K. experienced a 50% spike in cybersecurity incidents posing national security risks this year, according to NCSC CEO Richard Horne. Growing advancements in emerging tech are widening the gap between offensive and defensive cyber capabilities, he warned.
The U.K. experienced a 50% spike in cybersecurity incidents posing national security risks this year, according to NCSC CEO Richard Horne. Growing advancements in emerging tech are widening the gap between offensive and defensive cyber capabilities, he warned.
Fortinet Edge Devices Under Attack - Again
1 year 8 months ago
Hackers May Have Reverse-Engineered February Patch
Hackers may have circumvented a months-old patch for Fortinet gateway devices leading to a warning from the U.S. federal government over its active exploitation. Some security researchers say a February patch may not have fully squashed a flaw.
Hackers may have circumvented a months-old patch for Fortinet gateway devices leading to a warning from the U.S. federal government over its active exploitation. Some security researchers say a February patch may not have fully squashed a flaw.
Iran's APT34 Abuses MS Exchange to Spy on Gulf Gov'ts
1 year 8 months ago
A MOIS-aligned threat group has been using Microsoft Exchange servers to exfiltrate sensitive data from Gulf-state government agencies.
Nate Nelson, Contributing Writer
“网事”永恒,重温那年的经典时刻 | FCIS 2024 大会十周年
1 year 8 months ago
FCIS 2024 网络安全创新大会·十周年活动——FreeBuf安全视界·CIS特刊正式开启。
VPN на macOS: как обновления системы открыли двери для утечек
1 year 8 months ago
Некоторые приложения игнорируют правила маршрутизации.
CVE-2024-33064 | Qualcomm Snapdragon Auto MDM9628/QCA6564A/QCA6564AU/QCA6574A/QCA6574AU Beacon buffer over-read
1 year 8 months ago
A vulnerability was found in Qualcomm Snapdragon Auto MDM9628/QCA6564A/QCA6564AU/QCA6574A/QCA6574AU. It has been rated as critical. This issue affects some unknown processing of the component Beacon Handler. The manipulation leads to buffer over-read.
The identification of this vulnerability is CVE-2024-33064. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23379 | Qualcomm Snapdragon Auto/Snapdragon Mobile up to WSA8835 fastrpc map double free
1 year 8 months ago
A vulnerability was found in Qualcomm Snapdragon Auto and Snapdragon Mobile. It has been classified as critical. Affected is an unknown function of the component fastrpc map. The manipulation leads to double free.
This vulnerability is traded as CVE-2024-23379. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-33049 | Qualcomm Snapdragon Auto up to X65 5G Modem-RF System Beacon Frame buffer over-read
1 year 8 months ago
A vulnerability was found in Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Wearables and Snapdragon Wired Infrastructure and Networking. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Beacon Frame Handler. The manipulation leads to buffer over-read.
This vulnerability is known as CVE-2024-33049. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-33073 | Qualcomm Snapdragon Auto up to X75 5G Modem-RF System ML IE BSS buffer over-read
1 year 8 months ago
A vulnerability was found in Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile and Snapdragon Wired Infrastructure and Networking. It has been rated as critical. Affected by this issue is some unknown functionality of the component ML IE. The manipulation of the argument BSS leads to buffer over-read.
This vulnerability is handled as CVE-2024-33073. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-33065 | Qualcomm Snapdragon Compute/Snapdragon Industrial IOT up to WSA8845H Camera Driver memory corruption
1 year 8 months ago
A vulnerability classified as critical was found in Qualcomm Snapdragon Compute and Snapdragon Industrial IOT. This vulnerability affects unknown code of the component Camera Driver. The manipulation leads to memory corruption.
This vulnerability was named CVE-2024-33065. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-33066 | Qualcomm Snapdragon Wired Infrastructure and Networking up to X65 5G Modem-RF System Log File memory corruption
1 year 8 months ago
A vulnerability, which was classified as very critical, has been found in Qualcomm Snapdragon Wired Infrastructure and Networking. This issue affects some unknown processing of the component Log File Handler. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2024-33066. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-33069 | Qualcomm Snapdragon Auto up to X55 5G Modem-RF System Management Frame use after free
1 year 8 months ago
A vulnerability, which was classified as critical, was found in Qualcomm Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Mobile and Snapdragon Wearables. Affected is an unknown function of the component Management Frame Handler. The manipulation leads to use after free.
This vulnerability is traded as CVE-2024-33069. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-33070 | Qualcomm Snapdragon Auto MDM9628/QCA6564A/QCA6564AU/QCA6574A/QCA6574AU Response Frame buffer over-read
1 year 8 months ago
A vulnerability has been found in Qualcomm Snapdragon Auto MDM9628/QCA6564A/QCA6564AU/QCA6574A/QCA6574AU and classified as critical. Affected by this vulnerability is an unknown functionality of the component Response Frame Handler. The manipulation leads to buffer over-read.
This vulnerability is known as CVE-2024-33070. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38399 | Qualcomm Snapdragon Auto up to WSA8835 User Packet use after free
1 year 8 months ago
A vulnerability was found in Qualcomm Snapdragon Auto, Snapdragon Compute and Snapdragon Mobile and classified as critical. Affected by this issue is some unknown functionality of the component User Packet Handler. The manipulation leads to use after free.
This vulnerability is handled as CVE-2024-38399. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-33071 | Qualcomm Snapdragon Auto MDM9628/QCA6564A/QCA6564AU/QCA6574A/QCA6574AU MBSSID IE buffer over-read
1 year 8 months ago
A vulnerability was found in Qualcomm Snapdragon Auto MDM9628/QCA6564A/QCA6564AU/QCA6574A/QCA6574AU. It has been classified as critical. This affects an unknown part of the component MBSSID IE Handler. The manipulation leads to buffer over-read.
This vulnerability is uniquely identified as CVE-2024-33071. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38397 | Qualcomm Snapdragon Auto up to X75 5G Modem-RF System Response Frame buffer over-read
1 year 8 months ago
A vulnerability classified as critical has been found in Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile and Snapdragon Wired Infrastructure and Networking. Affected is an unknown function of the component Response Frame Handler. The manipulation leads to buffer over-read.
This vulnerability is traded as CVE-2024-38397. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47558 | Xerox FreeFlow Core up to 7.0.10 path traversal
1 year 8 months ago
A vulnerability was found in Xerox FreeFlow Core up to 7.0.10 and classified as critical. This issue affects some unknown processing. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2024-47558. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com