Aggregator
CVE-2024-52450 | Official Pro Coders nBlocks Plugin up to 1.0.2 on WordPress filename control
CVE-2024-52440 | Bueno Labs Xpresslane Fast Checkout Plugin up to 1.0.0 on WordPress deserialization
CVE-2024-52439 | Mark O'Donnell Team Rosters Plugin up to 4.6 on WordPress deserialization
CVE-2024-52443 | Nerijus Masikonis Geolocator Plugin up to 1.1 on WordPress deserialization
CVE-2024-52445 | Modeltheme QRMenu Restaurant QR Menu Lite Plugin up to 1.0.3 on WordPress deserialization
ИТ-миллиардеры обязаны поделиться с вузами: три критерия аккредитации
CVE-2024-52441 | Rajesh Thanoch Quick Learn Plugin up to 1.0.1 on WordPress Object Prototype prototype pollution
CVE-2024-52448 | WebCodingPlace Ultimate Classified Listings Plugin up to 1.4 on WordPress path traversal
CVE-2024-52449 | Navneil Naicer Bootscraper Plugin up to 2.1.0 on WordPress path traversal
CVE-2004-1335 | Linux Kernel up to 2.4.28/2.6.9 ip_options_get memory corruption (EDB-692 / Nessus ID 22609)
CVE-2024-45690 | Moodle oauth2 resource injection
印度外包巨头创始人称周末是一种错误
CVE-2024-8403 | Mitsubishi Electric MELSEC iQ-F FX5-ENET IP SLMP Packet improper validation of specified type of input
CVE-2024-10855 | Sirv Plugin up to 7.3.0 on WordPress authorization
CVE-2024-11179 | MStore API Plugin up to 4.15.7 on WordPress sql injection
CVE-2024-10665 | Yaad Sarig Payment Gateway for WC Plugin up to 2.2.4 on WordPress Log authorization
FACT SHEET: U.S. Department of Commerce & U.S. Department of State Launch the International Network of AI Safety Institutes at Inaugural Convening in San Francisco
USDA Releases Success Story Detailing the Implementation of Phishing-Resistant Multi-Factor Authentication
Today, the Cybersecurity and Infrastructure Security Agency (CISA) and the U.S. Department of Agriculture (USDA) released Phishing-Resistant Multi-Factor Authentication (MFA) Success Story: USDA’s FIDO Implementation. This report details how USDA successfully implemented phishing-resistant authentication for its personnel in situations where USDA could not exclusively rely on personal identity verification (PIV) cards.
USDA turned to Fast IDentity Online (FIDO) capabilities, a set of authentication protocols that uses cryptographic keys on user devices, to offer a secure way to authenticate user identities without passwords. USDA’s adoption of FIDO highlights the importance of organizations moving away from password authentication and adopting more secure MFA technologies.
This report offers examples to help organizations strengthen their cybersecurity posture through use cases, recommended actions, and resources. USDA successfully implemented MFA by adopting a centralized model, making incremental improvements, and addressing specific use cases. Organizations facing challenges with phishing-resistant authentication are encouraged to review this report.
For more information about phishing-resistant MFA, visit Phishing-Resistant MFA is Key to Peace of Mind and Implementing Phishing-Resistant MFA.
CISA and Partners Release Update to BianLian Ransomware Cybersecurity Advisory
Today, CISA, the Federal Bureau of Investigation (FBI), and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) released updates to #StopRansomware: BianLian Ransomware Group on observed tactics, techniques, and procedures (TTPs) and indicators of compromise attributed to data extortion group, BianLian.
The advisory, originally published May 2023, has been updated with additional TTPs obtained through FBI and ASD’s ACSC investigations and industry threat intelligence as of June 2024.
BianLian is likely based in Russia, with Russia-based affiliates, and has affected organizations in multiple U.S. critical infrastructure sectors since June 2022. They have also targeted Australian critical infrastructure sectors, professional services, and property development.
CISA and partners encourage infrastructure organizations and small- to medium-sized organizations implement mitigations in this advisory to reduce the likelihood and impact of BianLian and other ransomware incidents. These mitigations align with the Cross-Sector Cybersecurity Performance Goals developed by CISA and the National Institute of Standards and Technology.
This advisory is part of CISA’s ongoing #StopRansomware effort.