Vendor Blames Delta's Outage Severity on Its 'Own Response and IT Infrastructure' CrowdStrike has countersued customer Delta Air Lines, accusing the airline of employing a lawsuit and seeking damages in "a desperate attempt to shift blame" for Delta's own IT inadequacies having exacerbated its outage, unlike "other major airlines" that quickly resumed operations.
Russian SVR Targeting Government, Academia, Defense Organizations Globally A Russian-state hacking group is posing as Microsoft employees and sending malicious configuration files as email attachments to target organizations across the world. The campaign has the hallmarks of a Midnight Blizzard phishing campaign although its use of an RDP configuration file is novel.
New Compliance Tool Say Many AI Firms Fail to Meet Security, Fairness Standards Large language models developed by Meta and Mistral AI are among a dozen artificial intelligence models that fail to meet the cybersecurity and fairness requirements of the European Union AI Act, which went into effect on Aug. 1, said developers of a new open-source AI evaluation tool.
Vendor Blames Delta's Outage Severity on Its 'Own Response and IT Infrastructure' CrowdStrike has countersued customer Delta Air Lines, accusing the airline of employing a lawsuit and seeking damages in "a desperate attempt to shift blame" for Delta's own IT inadequacies having exacerbated its outage, unlike "other major airlines" that quickly resumed operations.
Russian SVR Targeting Government, Academia, Defense Organizations Globally A Russian-state hacking group is posing as Microsoft employees and sending malicious configuration files as email attachments to target organizations across the world. The campaign has the hallmarks of a Midnight Blizzard phishing campaign although its use of an RDP configuration file is novel.
New Compliance Tool Say Many AI Firms Fail to Meet Security, Fairness Standards Large language models developed by Meta and Mistral AI are among a dozen artificial intelligence models that fail to meet the cybersecurity and fairness requirements of the European Union AI Act, which went into effect on Aug. 1, said developers of a new open-source AI evaluation tool.
A vulnerability classified as problematic was found in WPGlobus Translate Options Plugin up to 2.2.0 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-9434. The attack can be launched remotely. There is no exploit available.
A vulnerability classified as problematic has been found in WP Simple Anchors Links Plugin up to 1.0.0 on WordPress. Affected is the function wpanchor of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-9446. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in Gift Cards Plugin up to 4.4.4 on WordPress. It has been rated as problematic. This issue affects some unknown processing of the component SVG File Upload Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-9165. The attack may be initiated remotely. There is no exploit available.
A vulnerability was found in Get Quote for Woocommerce Plugin up to 1.0.0 on WordPress. It has been declared as problematic. This vulnerability affects unknown code of the component Quote Handler. The manipulation leads to missing authorization.
This vulnerability was named CVE-2024-9430. The attack can be initiated remotely. There is no exploit available.
A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects an unknown part of the file birdsupdate.php. The manipulation of the argument id leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-10561. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in SourceCodester Airport Booking Management System 1.0 and classified as critical. Affected by this issue is the function details of the component Passport Number Handler. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2024-10559. The attack needs to be approached locally. Furthermore, there is an exploit available.
A vulnerability has been found in code-projects Blood Bank Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /file/updateprofile.php. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-10557. The attack can be launched remotely. Furthermore, there is an exploit available.