Aggregator
Splunk Enterprise Flaws Allow Attackers to Run Unauthorized JavaScript Code
Splunk released security advisories addressing multiple vulnerabilities affecting various versions of Splunk Enterprise and Splunk Cloud Platform. The flaws range from cross-site scripting (XSS) vulnerabilities to access control bypasses, with CVSS scores ranging from 4.6 to 7.5. Critical Vulnerabilities Identified The security advisories reveal six distinct vulnerabilities that primarily affect Splunk Web components. Two cross-site […]
The post Splunk Enterprise Flaws Allow Attackers to Run Unauthorized JavaScript Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2024-50281 | Linux Kernel up to 6.11.7 dcp null pointer dereference (c75e0272289e/04de7589e0a9 / Nessus ID 216493)
CVE-2024-50271 | Linux Kernel up to 6.1.116/6.6.60/6.11.7 Signal inc_rlimit_get_ucounts comparison (Nessus ID 211777 / WID-SEC-2024-3497)
CVE-2024-50279 | Linux Kernel up to 6.11.7 dm cache cache_preresume out-of-bounds (Nessus ID 211777 / WID-SEC-2024-3497)
CVE-2024-50278 | Linux Kernel up to 6.11.7 dm cache cache_create out-of-bounds (Nessus ID 211777 / WID-SEC-2024-3497)
CVE-2024-50284 | Linux Kernel up to 6.1.116/6.3/6.6.60/6.11.7 ksmbd xa_store allocation of resources (Nessus ID 211777 / WID-SEC-2024-3497)
CVE-2024-50287 | Linux Kernel up to 6.11.7 tpg_precalculate_line divide by zero (Nessus ID 211777 / WID-SEC-2024-3497)
CVE-2024-50290 | Linux Kernel up to 6.11.7 cx24116 buffer overflow (Nessus ID 211777 / WID-SEC-2024-3497)
CVE-2024-50266 | Linux Kernel up to 6.11.7 clk-branch.c denial of service (d055f6f2bdfb/f903663a8dcd / Nessus ID 216493)
CVE-2024-50265 | Linux Kernel up to 6.11.7 ocfs2_xa_remove null pointer dereference (Nessus ID 211777 / WID-SEC-2024-3497)
Античный грек спросил "сколько окружностей?" — человечество отвечало 23 века. И пришло к ответу, переписав математику с нуля
The energy sector is ground zero for global cyber activity
A new study from the Karlsruhe Institute of Technology shows how geopolitical tensions shape cyberattacks on power grids, fuel systems, and other critical infrastructure. How the research was done Researchers reviewed major cyber threat databases including MITRE ATT&CK Groups, CSIS, ThaiCERT, Malpedia, EuRepoC, and the AI Incident Database. Each source reports information differently. Some use structured formats like JSON or tables that are easy to analyze. Others rely on long descriptive text that is harder … More →
The post The energy sector is ground zero for global cyber activity appeared first on Help Net Security.
Reducing Mean Time to Remediation (MTTR) with Automated Policy Workflows
Shutdown Snares Federal Cybersecurity Personnel
The U.S. federal government shutdown has slashed staff at the nation's cyber defense agency and other key cyber entities, freezing daily operations, stalling grants and weakening threat coordination as state and local systems brace for lapses in federal support.
Google Drive Desktop Gets AI-Powered Ransomware Detection to Block Cyberattacks
Google has unveiled a groundbreaking AI-powered ransomware detection system for its Drive desktop application, representing a significant advancement in cybersecurity protection for organizations worldwide. This innovative feature automatically halts file synchronization when malicious encryption attempts are detected, preventing widespread data corruption across enterprise networks. Google Drive desktop ransomware detection alert with file syncing paused and […]
The post Google Drive Desktop Gets AI-Powered Ransomware Detection to Block Cyberattacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Gunra
You must login to view this content
Biotech platforms keep missing the mark on security fundamentals
A new security posture report on the biotech sector shows how quickly attackers could reach sensitive health data with only basic reconnaissance. Researchers needed less than two hours per company to uncover exposed genomic records, unprotected APIs, and misconfigured systems, according to Sekurno. Real-world timeline showing how attackers could pivot from passive reconnaissance to accessing sensitive genomic data in under 2 hours. APIs exposing sensitive data APIs were the most common weakness, accounting for 34% … More →
The post Biotech platforms keep missing the mark on security fundamentals appeared first on Help Net Security.
0xr0BIT создал TaskHound для аудита. Или для атак. Зависит от того, кто его запустит
Multiple Splunk Enterprise Vulnerabilities Let Attackers Execute Unauthorized JavaScript code
Splunk has released patches for multiple vulnerabilities in its Enterprise and Cloud Platform products, some of which could allow attackers to execute unauthorized JavaScript code, access sensitive information, or cause a denial-of-service (DoS) condition. The advisories, published on October 1, 2025, detail six security flaws, with severity ratings ranging from Medium to High. The most […]
The post Multiple Splunk Enterprise Vulnerabilities Let Attackers Execute Unauthorized JavaScript code appeared first on Cyber Security News.