Aggregator
招聘启事 | 中国信息安全测评中心招聘安全测评人员
恶意 PyPI 包窃取了 AWS 密钥
CISA Releases Nineteen Industrial Control Systems Advisories
CISA released nineteen Industrial Control Systems (ICS) advisories on November 14, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
- ICSA-24-319-01 Siemens RUGGEDCOM CROSSBOW
- ICSA-24-319-02 Siemens SIPORT
- ICSA-24-319-03 Siemens OZW672 and OZW772 Web Server
- ICSA-24-319-04 Siemens SINEC NMS
- ICSA-24-319-05 Siemens Solid Edge
- ICSA-24-319-06 Siemens SCALANCE M-800 Family
- ICSA-24-319-07 Siemens Engineering Platforms
- ICSA-24-319-08 Siemens SINEC INS
- ICSA-24-319-09 Siemens Spectrum Power 7
- ICSA-24-319-10 Siemens TeleControl Server
- ICSA-24-319-11 Siemens SIMATIC CP
- ICSA-24-319-12 Siemens Mendix Runtime
- ICSA-24-319-13 Rockwell Automation Verve Asset Manager
- ICSA-24-319-14 Rockwell Automation FactoryTalk Updater
- ICSA-24-319-15 Rockwell Automation Arena Input Analyzer
- ICSA-24-319-16 Hitachi Energy MSM
- ICSA-24-319-17 2N Access Commander
- ICSA-24-291-01 Elvaco M-Bus Metering Gateway CMe3100 (Update A)
- ICSMA-24-319-01 Baxter Life2000 Ventilation System
CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
- CVE-2024-9463 Palo Alto Networks Expedition OS Command Injection Vulnerability
- CVE-2024-9465 Palo Alto Networks Expedition SQL Injection Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
AI Can ‘Hear’ When a Lithium Battery Is About to Catch Fire
国家计算机病毒应急处理中心监测发现13款违规移动应用
Understanding IP Reputation: Why It Matters for Your Business and How to Improve It
Learn what is IP reputation and what kinds of causes can bring poor reputation. Check out the benefits and improvement ideas for better IP reputation for your business.
The post Understanding IP Reputation: Why It Matters for Your Business and How to Improve It appeared first on Security Boulevard.
Защитник-предатель: почему BitLocker стал союзником хакеров?
WIRTE:与哈马斯有关的网络间谍组织现在正在使用 SameCoin Wiper 恶意软件
屏蔽运营商获取本机号码自动登录域名
Hackaday Supercon 2024: Microcontrollers Are Just Radios in Disguise
RustyAttr 木马:Lazarus Group 的新 macOS 恶意软件轻松逃避防病毒
NFC Tools PRO模拟器v8.8.0
$6000 за твою карьеру: 183 млн профессионалов проснулись знаменитыми в даркнете
【安全圈】与哈马斯有关的黑客对以色列实体实施破坏性攻击
【安全圈】微软已通过最新更新修复Windows 11任务管理器进程数量显示为0的问题
【安全圈】日常搞笑!微软最新更新会错误提醒Windows 11 23H2版已经结束支持
【安全圈】B2B数据聚合公司DemandScience泄露超1亿人数据
More From Our Main Blog: The State of Cloud Ransomware in 2024
In this new report, learn how threat actors are leveraging cloud services to target web services with ransomware attackers.
The post The State of Cloud Ransomware in 2024 appeared first on SentinelOne.