Aggregator
North Korea Hackers Get Cash Fast in Linux Cyber Heists
2 months 3 weeks ago
The thieves modify transaction messages to initiate unauthorized withdrawals, even when there are insufficient funds.
Dark Reading Staff
CVE-2012-3480 | GNU C Library 2.16 numeric error (RHSA-2012:1208 / EDB-37631)
2 months 3 weeks ago
A vulnerability was found in GNU C Library 2.16. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to numeric error.
This vulnerability was named CVE-2012-3480. Local access is required to approach this attack. Furthermore, there is an exploit available.
vuldb.com
UMC Recovers EHR; Other Systems Offline 3 Weeks Post-Attack
2 months 3 weeks ago
Nearby Texas Tech University Health Sciences Center's IT Systems Also Still Offline
Nearly three weeks after a ransomware attack, UMC Health System has restored electronic health records, but the Texas-based public health system is still working to recover other patient care IT systems. Nearby Texas Tech University Health Sciences Center is still dealing with a related outage.
Nearly three weeks after a ransomware attack, UMC Health System has restored electronic health records, but the Texas-based public health system is still working to recover other patient care IT systems. Nearby Texas Tech University Health Sciences Center is still dealing with a related outage.
CVE-2017-6996 | Apple tvOS up to 10.2.0 AVEVideoEncoder Application memory corruption (EDB-42555 / BID-98571)
2 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Apple tvOS up to 10.2.0. This issue affects some unknown processing of the component AVEVideoEncoder. The manipulation as part of Application leads to memory corruption.
The identification of this vulnerability is CVE-2017-6996. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
AI vs. AI: 人工智能时代的网络安全攻防战
2 months 3 weeks ago
网络犯罪分子正利用人工智能(AI)发动更为复杂、规模化和先进的定向网络攻击。AI为攻击者提供了动力,使他们能够创造出逃避检测的变形恶意软件、极具说服力的网络钓鱼手段,并实现了高级攻击的自动化。Deep
《API安全技术应用指南(2024版)》报告暨代表性厂商评估调研启动
2 months 3 weeks ago
随着SaaS化和云服务的兴起,基于API的软件集成已成为构建现代应用程序的关键方法。然而,API自身的安全性,如不安全的协议框架、开发缺陷和漏洞,不仅给应用程序和Web应用带来严重的安全隐患,还因为大
Amazon says 175 million customers now use passkeys to log in
2 months 3 weeks ago
Amazon has seen massive adoption of passkeys since the company quietly rolled them out a year ago, announcing today that over 175 million customers use the security feature. [...]
Lawrence Abrams
Amazon says 175 million customer now use passkeys to log in
2 months 3 weeks ago
Amazon has seen massive adoption of passkeys since the company quietly rolled them out a year ago, announcing today that over 175 million customers use the security feature. [...]
Lawrence Abrams
CVE-2017-9511 | Atlassian FishEye/Crucible up to 4.4.0 on Windows MultiPathResource path traversal (ID 803830)
2 months 3 weeks ago
A vulnerability classified as problematic has been found in Atlassian FishEye and Crucible up to 4.4.0 on Windows. This affects the function MultiPathResource. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2017-9511. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-13990 | Oracle Database 12.2.0.1/18c/19c MapViewer xml external entity reference
2 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Oracle Database 12.2.0.1/18c/19c. Affected is an unknown function of the component MapViewer. The manipulation leads to xml external entity reference.
This vulnerability is traded as CVE-2019-13990. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-13990 | Oracle Communications IP Service Activator 7.3.0/7.4.0 Netwok Processor Configuration Management xml external entity reference
2 months 3 weeks ago
A vulnerability, which was classified as very critical, has been found in Oracle Communications IP Service Activator 7.3.0/7.4.0. Affected by this issue is some unknown functionality of the component Netwok Processor Configuration Management. The manipulation leads to xml external entity reference.
This vulnerability is handled as CVE-2019-13990. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-13990 | Oracle Banking Payments 14.1.x/14.2.x/14.3.x/14.4.0 Core xml external entity reference
2 months 3 weeks ago
A vulnerability was found in Oracle Banking Payments 14.1.x/14.2.x/14.3.x/14.4.0. It has been rated as very critical. Affected by this issue is some unknown functionality of the component Core. The manipulation leads to xml external entity reference.
This vulnerability is handled as CVE-2019-13990. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-13990 | Oracle FLEXCUBE Investor Servicing 12.1.0/12.3.0/12.4.0/14.0.0/14.1.0 Infrastructure xml external entity reference
2 months 3 weeks ago
A vulnerability has been found in Oracle FLEXCUBE Investor Servicing 12.1.0/12.3.0/12.4.0/14.0.0/14.1.0 and classified as very critical. Affected by this vulnerability is an unknown functionality of the component Infrastructure. The manipulation leads to xml external entity reference.
This vulnerability is known as CVE-2019-13990. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
api漏洞系列-API权限升级
2 months 3 weeks ago
How U.S. Port Strikes Disrupt Supply Chains
2 months 3 weeks ago
Top Supply Chain Risks and Mitigation Strategies
2 months 3 weeks ago
AI Ethics: Enable AI Innovation With Governance Platforms
2 months 3 weeks ago
Embrace New Computing Technologies to Enable Innovation
2 months 3 weeks ago
Succession Planning: Template for CHROs and HR Leaders
2 months 3 weeks ago