Aggregator
CISA's New SIEM Guidance Tackles Visibility and Blind Spots
8 months 2 weeks ago
US, Australian Cyber Agencies Say Visibility Gaps Threaten Detection and Response
The Cybersecurity and Infrastructure Security Agency issued new guidance urging organizations to streamline Security Information and Event Management platform integration by prioritizing impactful log data and reducing blind spots that continue to plague even mature security operations centers.
The Cybersecurity and Infrastructure Security Agency issued new guidance urging organizations to streamline Security Information and Event Management platform integration by prioritizing impactful log data and reducing blind spots that continue to plague even mature security operations centers.
Tenable Bolsters AI Controls With Apex Security Acquisition
8 months 2 weeks ago
Apex Security Detection Tools Help Tenable Spot Accidental and Malicious AI Misuse
Tenable is acquiring Israeli startup Apex Security to extend AI security features that go beyond asset discovery. With user-level controls and risk mitigation for AI usage, Tenable aims to accelerate its exposure management roadmap by integrating Apex into Tenable One later this year.
Tenable is acquiring Israeli startup Apex Security to extend AI security features that go beyond asset discovery. With user-level controls and risk mitigation for AI usage, Tenable aims to accelerate its exposure management roadmap by integrating Apex into Tenable One later this year.
Tiffany, Dior Suffer South Korean Customer Data Breaches
8 months 2 weeks ago
Retailers Report a Spurt in Breaches
Jewelry retailer Tiffany & Co. said hackers stole South Korean customers' data from a third-party vendor's platform, a disclosure that came shortly after sister brand Dior announced a similar breach. Hackers stole the personal information of South Korean shoppers.
Jewelry retailer Tiffany & Co. said hackers stole South Korean customers' data from a third-party vendor's platform, a disclosure that came shortly after sister brand Dior announced a similar breach. Hackers stole the personal information of South Korean shoppers.
Webinar | How to Build a Platform-Based Defense Against Evolving Cyber Threats
8 months 2 weeks ago
Palo Alto Networks on How to Construct a Defense for Modern Threats
The rapid evolution of cyber threats, amplified by the integration of AI into adversarial tactics, calls for a shift in defensive strategies. Traditional approaches are no longer sufficient to address the sophistication, scale, and speed of modern attacks.
The rapid evolution of cyber threats, amplified by the integration of AI into adversarial tactics, calls for a shift in defensive strategies. Traditional approaches are no longer sufficient to address the sophistication, scale, and speed of modern attacks.
解读 | 公安部《网络安全等级保护测评高风险判定实施指引》
8 months 2 weeks ago
等保制度持续深化实施,公安部最新高风险判例清单速取!
Mozilla releases Firefox 139.0.1 update to fix artifacts on Nvidia GPUs
8 months 2 weeks ago
Mozilla has rolled out an emergency Firefox 139.0.1 update after the Tuesday release caused graphical artifacts on PCs with NVIDIA GPUs. [...]
Mayank Parmar
Microsoft Authenticator now warns to export passwords before July cutoff
8 months 2 weeks ago
The Microsoft Authenticator app is now issuing notifications warning that the password autofill feature is being deprecated in July, suggesting users move to Microsoft Edge instead. [...]
Lawrence Abrams
CVE-2023-6530 | TJ Shortcodes Plugin 0.1.3 on WordPress Shortcode cross site scripting
8 months 2 weeks ago
A vulnerability classified as problematic was found in TJ Shortcodes Plugin 0.1.3 on WordPress. Affected by this vulnerability is an unknown functionality of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2023-6530. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-6391 | Custom User CSS Plugin up to 0.2 on WordPress Setting cross-site request forgery
8 months 2 weeks ago
A vulnerability was found in Custom User CSS Plugin up to 0.2 on WordPress. It has been rated as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2023-6391. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-7199 | Relevanssi Plugin/Relevanssi Premium Plugin on WordPress Request authorization
8 months 2 weeks ago
A vulnerability classified as problematic has been found in Relevanssi Plugin and Relevanssi Premium Plugin on WordPress. Affected is an unknown function of the component Request Handler. The manipulation leads to authorization bypass.
This vulnerability is traded as CVE-2023-7199. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23940 | Trend Micro Security uiAirSupport up to 6.0.2092 uncontrolled search path
8 months 2 weeks ago
A vulnerability was found in Trend Micro Security uiAirSupport up to 6.0.2092. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to uncontrolled search path.
This vulnerability is known as CVE-2024-23940. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-24140 | SourceCodester Daily Habit Tracker App 1.0 tracker sql injection
8 months 2 weeks ago
A vulnerability was found in SourceCodester Daily Habit Tracker App 1.0 and classified as critical. This issue affects some unknown processing. The manipulation of the argument tracker leads to sql injection.
The identification of this vulnerability is CVE-2024-24140. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2023-51840 | DoraCMS 2.1.8 hard-coded key (Issue 262)
8 months 2 weeks ago
A vulnerability was found in DoraCMS 2.1.8. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to use of hard-coded cryptographic key
.
This vulnerability is handled as CVE-2023-51840. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2024-24134 | SourceCodester Online Food Menu 1.0 Update Menu Section Menu Name/Description cross site scripting
8 months 2 weeks ago
A vulnerability classified as problematic was found in SourceCodester Online Food Menu 1.0. This vulnerability affects unknown code of the component Update Menu Section. The manipulation of the argument Menu Name/Description leads to cross site scripting.
This vulnerability was named CVE-2024-24134. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-22647 | SEO Panel 4.10.0 information exposure
8 months 2 weeks ago
A vulnerability was found in SEO Panel 4.10.0 and classified as problematic. This issue affects some unknown processing. The manipulation leads to information exposure through error message.
The identification of this vulnerability is CVE-2024-22647. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-22938 | BossCMS 1.3.0 admin.class.php init permission
8 months 2 weeks ago
A vulnerability was found in BossCMS 1.3.0. It has been rated as critical. Affected by this issue is the function init of the file admin.class.php. The manipulation leads to permission issues.
This vulnerability is handled as CVE-2024-22938. Attacking locally is a requirement. There is no exploit available.
vuldb.com
CVE-2023-51982 | CrateDB 5.5.1 Admin UI X-Real IP improper authentication (Issue 15231)
8 months 2 weeks ago
A vulnerability classified as critical was found in CrateDB 5.5.1. This vulnerability affects unknown code of the component Admin UI. The manipulation of the argument X-Real IP leads to improper authentication.
This vulnerability was named CVE-2023-51982. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2023-51843 | react-dashboard 1.4.0 cross site scripting (Issue 65)
8 months 2 weeks ago
A vulnerability has been found in react-dashboard 1.4.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2023-51843. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-51837 | Ylianst MeshCentral 1.1.16 certificate validation
8 months 2 weeks ago
A vulnerability was found in Ylianst MeshCentral 1.1.16 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper certificate validation.
This vulnerability is handled as CVE-2023-51837. The attack may be launched remotely. There is no exploit available.
vuldb.com