Aggregator
CVE-2024-11437 | solwininfotech Timeline Designer Plugin up to 1.4 on WordPress sql injection
CVE-2024-12419 | tobias_conrad Design for Contact Form 7 Style Plugin up to 1.6.9 on WordPress Shortcode do_shortcode code injection
CVE-2024-12538 | binsaifullah Duplicate Post, Page and Any Custom Post plugin up to 3.5.3 on WordPress Password Protected Post dpp_duplicate_as_draft information disclosure
Moxa router flaws pose serious risks to industrial environmets
Moxa router flaws pose serious risks to industrial environmets
MyCERT Advisory Recommends Cybersecurity Practices for Water Systems
CISA says Treasury was the only US agency breached via BeyondTrust
The US Cybersecurity and Infrastructure Security Agency (CISA) has shared on Monday that the Treasury Department was the only US federal agency affected by the recent cybersecurity incident involving compromised BeyondTrust Remote Support SaaS instances. On the same day, BeyondTrust offered an update on the situation: The forensic investigation into the incident is approaching completion, the company said, and noted that no additional affected customers have been identified since the initial cluster of affected instances … More →
The post CISA says Treasury was the only US agency breached via BeyondTrust appeared first on Help Net Security.
盘点有趣的安全类比、安全比喻有哪些?
盘点有趣的安全类比、安全比喻有哪些?
盘点有趣的安全类比、安全比喻有哪些?
盘点有趣的安全类比、安全比喻有哪些?
盘点有趣的安全类比、安全比喻有哪些?
罗马帝国大规模使用铅降低了欧洲居民的智商
罗马帝国大规模使用铅降低了欧洲居民的智商
Akira
Akira
US Treasury Department Sanctions Chinese Company Over Cyberattacks
Three Things AI Enthusiasts Can Teach Your Business About How to Combat the Most Sophisticated Threats
As cybercriminals turn to AI to orchestrate attacks at scale, there’s a distinct group of companies taking bold steps to fight back against advanced cyber threats—what we call “AI Enthusiasts.” These enterprises have not just embraced AI but are actively deploying it to detect and stop the most sophisticated attacks in real time. The results? […]
The post Three Things AI Enthusiasts Can Teach Your Business About How to Combat the Most Sophisticated Threats appeared first on Security Boulevard.
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
- CVE-2024-41713 Mitel MiCollab Path Traversal Vulnerability
- CVE-2024-55550 Mitel MiCollab Path Traversal Vulnerability
- CVE-2020-2883 Oracle WebLogic Server Unspecified Vulnerability
Users and administrators are also encouraged to review the Palo Alto Threat Brief: Operation Lunar Peek related to CVE-2024-0012, the Palo Alto Security Bulletin for CVE-2024-0012, and the Palo Alto Security Bulletin for CVE-2024-9474 for additional information.
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.