Aggregator
CVE-2013-7478 | events-manager Plugin up to 5.4 on WordPress EM_Ticket::get_post cross site scripting
CVE-2013-7479 | events-manager Plugin up to 5.3.8 on WordPress Search Form cross site scripting
CVE-2013-7480 | events-manager Plugin up to 5.3.6.0 on WordPress Admin Area cross site scripting
CVE-2019-16523 | events-manager Plugin up to 5.9.5 on WordPress Shortcode Stored cross site scripting
Patch Tuesday Update – October 2024
The post Patch Tuesday Update - October 2024 appeared first on Digital Defense.
The post Patch Tuesday Update – October 2024 appeared first on Security Boulevard.
A decade of transformation: ADDO and the State of the Software Supply Chain
The software industry has seen remarkable changes over the past decade, driven by a surge in open source adoption, evolving development methodologies, and the growing integration of AI.
At this year's All Day DevOps (ADDO) event, a panel of industry leaders, including Sonatype's co-founder and CTO Brian Fox, will present "A Decade of Transformation - Unveiling the 10th Annual State of the Software Supply Chain Report."
This session promises to reveal key insights into how the software supply chain has evolved and what the future holds.
The post A decade of transformation: ADDO and the State of the Software Supply Chain appeared first on Security Boulevard.
Microsoft security advisory – October 2024 monthly rollup (AV24–574)
New Mamba 2FA bypass service targets Microsoft 365 accounts
Adobe security advisory (AV24–573)
CVE-2014-7498 | Xaos Space Cinema 2.0.6 X.509 Certificate cryptographic issues (VU#582497)
GoldenJackal Targets Embassies, Steals Data from Air-Gapped Systems
GoldenJackal, a threat group possibly from Russia, has been attacking embassies and other government agencies from Europe, South Asia, and the Middle East with two distinct malicious toolsets designed to steal information from air-gapped systems, ESET researchers said.
The post GoldenJackal Targets Embassies, Steals Data from Air-Gapped Systems appeared first on Security Boulevard.
CVE-2012-5917 | Tom Wilkason SnackAmp 3.1.3 memory corruption (EDB-18692 / XFDB-74528)
Revolutionizing software development: Frank Roe’s keynote at ADDO
The world of software development is rapidly evolving, driven by increasing pressure to deliver faster, yet with fewer resources, and the widespread adoption of generative AI tools.
The post Revolutionizing software development: Frank Roe’s keynote at ADDO appeared first on Security Boulevard.
RansomHub
Ivanti security advisory (AV24-572)
CVE-2024-9412 | Rockwell Automation Verve Asset Manager prior 1.38 placement of user into incorrect group
Microsoft patches two zero-days exploited in the wild (CVE-2024-43573, CVE-2024-43572)
For October 2024 Patch Tuesday, Microsoft has released fixes for 117 security vulnerabilities, including two under active exploitation: CVE-2024-43573, a spoofing bug affecting the Windows MSHTML Platform, and CVE-2024-43572, a remote code execution flaw in the Microsoft Management Console (MMC). About CVE-2024-43573 and CVE-2024-43572 As far as it can be deduced from the accompanying advisory, CVE-2024-43573 is similar to CVE-2024-38112, a vulnerability in MSHTML, a browser engine for the now deprecated Internet Explorer, which has … More →
The post Microsoft patches two zero-days exploited in the wild (CVE-2024-43573, CVE-2024-43572) appeared first on Help Net Security.
Unmasking the invisible threat: Ilkka Turunen’s keynote at ADDO
Open source components are the building blocks of modern applications. But what happens when these very components are weaponized, silently infiltrating your software supply chain?
The post Unmasking the invisible threat: Ilkka Turunen’s keynote at ADDO appeared first on Security Boulevard.