Aggregator
Elaborate Deepfake Operation Takes a Meeting With US Senator
1 year 6 months ago
The threat actors managed to gain access to Sen. Ben Cardin (D-Md.) by posing as a Ukrainian official, before quickly being outed.
Kristina Beek, Associate Editor, Dark Reading
Treat Your Enterprise Data Like a Digital Nomad
1 year 6 months ago
By combining agility with compliance, and security with accessibility, businesses will treat their data as a well-prepared traveler, ready for any adventure.
Apu Pavithran
Ransomware attackers hop from on-premises systems to cloud to compromise Microsoft 365 accounts
1 year 6 months ago
Storm-0501, an affiliate of several high-profile ransomware-as-a-service outfits, has been spotted compromising targets’ cloud environments and on-premises systems. “Storm-0501 is the latest threat actor observed to exploit weak credentials and over-privileged accounts to move from organizations’ on-premises environment to cloud environments. They stole credentials and used them to gain control of the network, eventually creating persistent backdoor access to the cloud environment and deploying ransomware to the on-premises,” Microsoft shared last week. Common tactics and … More →
The post Ransomware attackers hop from on-premises systems to cloud to compromise Microsoft 365 accounts appeared first on Help Net Security.
Zeljka Zorz
Community Clinic of Maui discloses a data breach following May Lockbit ransomware attack
1 year 6 months ago
Community Clinic of Maui experienced a data breach impacting over 120,000 people following a LockBit ransomware attack. In May, the Community Clinic of Maui experienced a major IT outage that impacted thousands of patients following a cyber attack. In June, the Lockbit ransomware gang took credit for the attack. The Community Clinic of Maui, also known as Mālama […]
Pierluigi Paganini
CVE-2024-43827 | Linux Kernel up to 6.10.2 AMD Display enable_phantom_plane null pointer dereference (081ff4c0ef18/c96140000915)
1 year 6 months ago
A vulnerability was found in Linux Kernel up to 6.10.2. It has been rated as critical. This issue affects the function enable_phantom_plane of the component AMD Display. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2024-43827. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43829 | Linux Kernel up to 6.1.102/6.6.43/6.10.2 drm_cvt_mode null pointer dereference
1 year 6 months ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.1.102/6.6.43/6.10.2. Affected is the function drm_cvt_mode. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2024-43829. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45299 | alfio-event alf.io up to 2.0-M4 Content Security Policy escape output (GHSA-mcx6-25f8-8rqw)
1 year 6 months ago
A vulnerability was found in alfio-event alf.io up to 2.0-M4. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Content Security Policy Handler. The manipulation leads to escaping of output.
This vulnerability is handled as CVE-2024-45299. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46329 | Vonets VAP11G-300 3.3.23.6.9 SystemCommand command injection
1 year 6 months ago
A vulnerability was found in Vonets VAP11G-300 3.3.23.6.9 and classified as critical. Affected by this issue is the function SystemCommand. The manipulation leads to command injection.
This vulnerability is handled as CVE-2024-46329. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-46330 | Vonets VAP11G-300 3.3.23.6.9 iptablesWebsFilterRun command injection
1 year 6 months ago
A vulnerability was found in Vonets VAP11G-300 3.3.23.6.9. It has been classified as critical. This affects the function iptablesWebsFilterRun. The manipulation leads to command injection.
This vulnerability is uniquely identified as CVE-2024-46330. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2024-46328 | Vonets VAP11G-300 3.3.23.6.9 hard-coded credentials
1 year 6 months ago
A vulnerability was found in Vonets VAP11G-300 3.3.23.6.9. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to hard-coded credentials.
This vulnerability was named CVE-2024-46328. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-46327 | Vonets VAP11G-300 3.3.23.6.9 Http_handle path traversal
1 year 6 months ago
A vulnerability was found in Vonets VAP11G-300 3.3.23.6.9. It has been rated as critical. This issue affects the function Http_handle. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2024-46327. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2014-7111 | Android Excellence 1.4.1 X.509 Certificate cryptographic issues (VU#582497)
1 year 6 months ago
A vulnerability was found in Android Excellence 1.4.1 and classified as critical. This issue affects some unknown processing of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
The identification of this vulnerability is CVE-2014-7111. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-46751 | Linux Kernel up to 6.10.9 btrfs reference count (ef9a8b73c8b6/28cb13f29faf)
1 year 6 months ago
A vulnerability classified as problematic has been found in Linux Kernel up to 6.10.9. Affected is an unknown function of the component btrfs. The manipulation leads to improper update of reference count.
This vulnerability is traded as CVE-2024-46751. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46727 | Linux Kernel up to 6.10.8 AMD Display otg_master null pointer dereference (aad4d3d3d3b6/871cd9d881fa)
1 year 6 months ago
A vulnerability was found in Linux Kernel up to 6.10.8. It has been declared as critical. Affected by this vulnerability is the function otg_master of the component AMD Display. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2024-46727. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
G.O.S.S.I.P 阅读推荐 2024-09-30 MPFUZZ
1 year 6 months ago
CVE-2016-1865 | Apple watchOS up to 2.2.1 Kernel null pointer dereference (HT206904 / Nessus ID 92494)
1 year 6 months ago
A vulnerability, which was classified as problematic, has been found in Apple watchOS up to 2.2.1. This issue affects some unknown processing of the component Kernel. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2016-1865. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-4506 | NeoRecruit 1.4 on Joomla index.php id sql injection (EDB-4305 / XFDB-36216)
1 year 6 months ago
A vulnerability, which was classified as critical, was found in NeoRecruit 1.4 on Joomla. This affects an unknown part of the file index.php. The manipulation of the argument id leads to sql injection.
This vulnerability is uniquely identified as CVE-2007-4506. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
THN Cybersecurity Recap: Last Week's Top Threats and Trends (September 23-29)
1 year 6 months ago
Hold onto your hats, folks, because the cybersecurity world is anything but quiet! Last week, we dodged a bullet when we discovered vulnerabilities in CUPS that could've opened the door to remote attacks. Google's switch to Rust is paying off big time, slashing memory-related vulnerabilities in Android.
But it wasn't all good news – Kaspersky's forced exit from the US market left users with more
The Hacker News
CVE-2024-6051 | Vercom Redlink SDK up to 1.13 resource injection
1 year 6 months ago
A vulnerability was found in Vercom Redlink SDK up to 1.13. It has been classified as problematic. Affected is an unknown function. The manipulation leads to improper control of resource identifiers.
This vulnerability is traded as CVE-2024-6051. Local access is required to approach this attack. There is no exploit available.
vuldb.com