Aggregator
Updates: ISO 27001 Mapping and Model Calibration | Kovrr
3 months 1 week ago
Articles related to cyber risk quantification, cyber risk management, and cyber resilience.
The post Updates: ISO 27001 Mapping and Model Calibration | Kovrr appeared first on Security Boulevard.
Cyber Risk Quantification
Ransomware actors pivot away from major brands in Q2 2024
3 months 1 week ago
Unaffiliated ‘lone wolf’ threat actors carry out a greater share of attacks
as they attempt to obfuscate their identity in Q2 2024.
Bill Siegel
Ransomware actors pivot away from major brands in Q2 2024
3 months 1 week ago
Unaffiliated ‘lone wolf’ threat actors carry out a greater share of attacks
as they attempt to obfuscate their identity in Q2 2024.
The post Ransomware actors pivot away from major brands in Q2 2024 appeared first on Security Boulevard.
Bill Siegel
How to Deter Multidimensional Threats in the Connected World
3 months 1 week ago
Our National Framework proposes a whole-of-society effort to tackle multidimensional threats in the connected world. Explore our high-level findings.
CVE-2024-7300 | Bolt CMS 3.7.1 Showcase Creation showcases textarea cross site scripting
3 months 1 week ago
A vulnerability classified as problematic has been found in Bolt CMS 3.7.1. Affected is an unknown function of the file /bolt/editcontent/showcases of the component Showcase Creation Handler. The manipulation of the argument textarea leads to cross site scripting. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is traded as CVE-2024-7300. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
Vendor was contacted early and confirmed that the affected release tree is end-of-life.
vuldb.com
CVE-2024-7299 | Bolt CMS 3.7.1 Entry Preview /preview/page body cross site scripting
3 months 1 week ago
A vulnerability was found in Bolt CMS 3.7.1. It has been rated as problematic. This issue affects some unknown processing of the file /preview/page of the component Entry Preview Handler. The manipulation of the argument body leads to cross site scripting. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
The identification of this vulnerability is CVE-2024-7299. The attack may be initiated remotely. Furthermore, there is an exploit available.
Vendor was contacted early and confirmed that the affected release tree is end-of-life.
vuldb.com
Sophisticated Phishing Campaign Targets Microsoft OneDrive Users
3 months 1 week ago
The OneDrive campaign uses social engineering to trick users into executing a PowerShell script
DNS 解析数据大局观
3 months 1 week ago
在海量的解析服务器处观测海量数据,可以观察到什么?
CVE-2024-4188 | OpenText Documentum Server up to 23.4 unprotected transport of credentials (KB0815868)
3 months 1 week ago
A vulnerability was found in OpenText Documentum Server up to 23.4. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to unprotected transport of credentials.
This vulnerability was named CVE-2024-4188. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-37165 | Discourse up to 3.2.2/3.3.0.beta2 Onebox Data cross site scripting
3 months 1 week ago
A vulnerability was found in Discourse up to 3.2.2/3.3.0.beta2. It has been classified as problematic. This affects an unknown part of the component Onebox Data Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-37165. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38909 | Studio 42 elFinder 2.1.64 access control
3 months 1 week ago
A vulnerability was found in Studio 42 elFinder 2.1.64 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2024-38909. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-39320 | Discourse up to 3.2.4/3.3.0.beta4 Setting allowed_iframes injection
3 months 1 week ago
A vulnerability has been found in Discourse up to 3.2.4/3.3.0.beta4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Setting Handler. The manipulation of the argument allowed_iframes leads to injection.
This vulnerability is known as CVE-2024-39320. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23091 | HotelDruid up to 1.31 funzioni.php weak password hash
3 months 1 week ago
A vulnerability, which was classified as problematic, was found in HotelDruid up to 1.31. Affected is an unknown function of the file funzioni.php. The manipulation leads to password hash with insufficient computational effort.
This vulnerability is traded as CVE-2024-23091. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-37299 | Discourse up to 3.2.4/3.3.0.beta4 Tag Group Name resource consumption
3 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Discourse up to 3.2.4/3.3.0.beta4. This issue affects some unknown processing of the component Tag Group Name Handler. The manipulation leads to resource consumption.
The identification of this vulnerability is CVE-2024-37299. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41109 | Pimcore admin-ui-classic-bundle up to 1.3.9/1.4.5/1.5.1 /admin/index/statistics information disclosure
3 months 1 week ago
A vulnerability classified as problematic was found in Pimcore admin-ui-classic-bundle up to 1.3.9/1.4.5/1.5.1. This vulnerability affects unknown code of the file /admin/index/statistics. The manipulation leads to information disclosure.
This vulnerability was named CVE-2024-41109. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Active exploitation of the ServiceNow RCE
3 months 1 week ago
Background ServiceNow provides a platform for corporate transformation. ServiceNow can be used for various purposes, including HR and employee administration, […]
The post Active exploitation of the ServiceNow RCE appeared first on HawkEye.
HawkEye
Specula: ни одна версия Outlook не устоит перед новой атакой
3 months 1 week ago
Реестр Windows стал ахиллесовой пятой популярного почтового клиента.
SideWinder phishing campaign targets maritime facilities in multiple countries
3 months 1 week ago
The APT group SideWinder launched a new espionage campaign targeting ports and maritime facilities in the Indian Ocean and Mediterranean Sea. SideWinder (also known as Razor Tiger, Rattlesnake, and T-APT-04) has been active since at least 2012, the group mainly targeted Police, Military, Maritime, and the Naval forces of Central Asian countries. In the 2022 […]
Pierluigi Paganini
Active exploitation of the ServiceNow RCE
3 months 1 week ago
HawkEye