Aggregator
PlatformEngineering.com: Strengthening Security in the Software Development Lifecycle
1 year 4 months ago
The Techstrong Group is thrilled to announce the launch of PlatformEngineering.com, a new platform dedicated to advancing the platform engineering discipline. This addition to the Techstrong family—including Security Boulevard—promises to be a critical resource for organizations seeking to enhance their software delivery pipelines while ensuring robust security measures. The Intersection of Platform Engineering and Cybersecurity..
The post PlatformEngineering.com: Strengthening Security in the Software Development Lifecycle appeared first on Security Boulevard.
Alan Shimel
Google Chrome security advisory (AV24-651)
1 year 4 months ago
Canadian Centre for Cyber Security
Бояться нельзя использовать: где поставить запятую в отношениях с ИИ на работе
1 year 4 months ago
Slack: сотрудники не доверяют нейросетям даже под давлением начальства.
Scoperta CRON#TRAP, campagna che emula ambienti Linux per ottenere persistenza
1 year 4 months ago
CVE-2024-9476 | Grafana OSS/Enterprise prior 11.2.3+security-01/11.3.0+security-01 privileges assignment
1 year 4 months ago
A vulnerability has been found in Grafana OSS and Enterprise and classified as problematic. This vulnerability affects unknown code. The manipulation leads to incorrect privilege assignment.
This vulnerability was named CVE-2024-9476. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
AI Threat to Escalate in 2025, Google Cloud Warns
1 year 4 months ago
2025 could see our biggest AI fears materialize, according to a Google Cloud forecast report
CVE-2024-45594 | Decidim up to 0.28.2 cross site scripting
1 year 4 months ago
A vulnerability, which was classified as problematic, was found in Decidim up to 0.28.2. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-45594. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-49506 | openSUSE Tumbleweed up to 1.0.1/1.2.3 temp file
1 year 4 months ago
A vulnerability, which was classified as problematic, has been found in openSUSE Tumbleweed up to 1.0.1/1.2.3. Affected by this issue is some unknown functionality. The manipulation leads to insecure temporary file.
This vulnerability is handled as CVE-2024-49506. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-49504 | SUSE openSUSE Tumbleweed up to 28.0 access control
1 year 4 months ago
A vulnerability classified as critical was found in SUSE openSUSE Tumbleweed up to 28.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2024-49504. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-10013 | Progress Telerik UI for WinForms 2024.2.514/2024.3.924 deserialization
1 year 4 months ago
A vulnerability classified as critical has been found in Progress Telerik UI for WinForms 2024.2.514/2024.3.924. Affected is an unknown function. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2024-10013. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9477 | AirTies Air4443 up to 1.6.1.6 cross site scripting
1 year 4 months ago
A vulnerability was found in AirTies Air4443 up to 1.6.1.6. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
The identification of this vulnerability is CVE-2024-9477. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-50854 | Tenda G3 15.11.0.20 formSetPortMapping stack-based overflow
1 year 4 months ago
A vulnerability was found in Tenda G3 15.11.0.20. It has been classified as critical. This affects the function formSetPortMapping. The manipulation leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2024-50854. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-10012 | Progress Telerik UI for WPF 2024.3.924 deserialization
1 year 4 months ago
A vulnerability was found in Progress Telerik UI for WPF 2024.3.924. It has been declared as very critical. This vulnerability affects unknown code. The manipulation leads to deserialization.
This vulnerability was named CVE-2024-10012. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50853 | Tenda G3 15.11.0.20 formSetDebugCfg command injection
1 year 4 months ago
A vulnerability was found in Tenda G3 15.11.0.20 and classified as critical. Affected by this issue is the function formSetDebugCfg. The manipulation leads to command injection.
This vulnerability is handled as CVE-2024-50853. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-7295 | Progress Telerik Report Server prior 10.3.24.1112 hard-coded credentials
1 year 4 months ago
A vulnerability has been found in Progress Telerik Report Server 10.0.24.130/10.0.24.514/10.1.24.514/10.1.24.709/10.2.24.806 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to hard-coded credentials.
This vulnerability is known as CVE-2024-7295. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50852 | Tenda G3 15.11.0.20 formSetUSBPartitionUmount command injection
1 year 4 months ago
A vulnerability, which was classified as critical, was found in Tenda G3 15.11.0.20. Affected is the function formSetUSBPartitionUmount. The manipulation leads to command injection.
This vulnerability is traded as CVE-2024-50852. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-49505 | openSUSE Tumbleweed up to 1.82 cross site scripting
1 year 4 months ago
A vulnerability, which was classified as problematic, has been found in openSUSE Tumbleweed up to 1.82. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-49505. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-11159 | Mozilla Thunderbird up to 128.4.2/132.0.0 OpenPGP missing encryption
1 year 4 months ago
A vulnerability classified as problematic was found in Mozilla Thunderbird up to 128.4.2/132.0.0. This vulnerability affects unknown code of the component OpenPGP. The manipulation leads to missing encryption of sensitive data.
This vulnerability was named CVE-2024-11159. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
亚马逊披露 2023 年 5 月 MOVEit 攻击后员工数据泄露
1 year 4 months ago
error code: 521