FBI Ties Suspects to at Least 45 Attacks and Theft of Cryptocurrency Worth Millions The U.S. government on Wednesday unsealed criminal charges against five suspected members of the "loosely organized, financially motivated cybercriminal group" Scattered Spider. The suspects have been tied to 45 attacks, disrupting businesses and stealing cryptocurrency worth millions of dollars.
Also: Bitfinex Launderer Razzlekhan Gets 18-Month Sentence This week, sentences in FTX, Bitfinex and Helix cases, a $25.5M Thala hack, the WazirX hack and South Korea probed UpBit. U.S. lawmakers want a crackdown on Tornado. U.S. Prosecutors may scale back crypto cases. BIT Mining fined $10M and the Chinese Communist Party expelled a key blockchain figure
A vulnerability, which was classified as problematic, has been found in Keycloak. This issue affects some unknown processing of the component Vault File Handler. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2024-10492. Access to the local network is required for this attack to succeed. There is no exploit available.
A vulnerability classified as problematic was found in Keycloak. This vulnerability affects unknown code of the component Build Process. The manipulation leads to information disclosure.
This vulnerability was named CVE-2024-10451. Access to the local network is required for this attack. There is no exploit available.
Microsoft has confirmed that, since November 12, some Windows 10 users have been unable to update or uninstall packaged applications like Microsoft Teams. [...]
A vulnerability classified as problematic has been found in Keycloak. This affects the function SearchQueryUtils. The manipulation leads to inefficient regular expression complexity.
This vulnerability is uniquely identified as CVE-2024-10270. The attack needs to be initiated within the local network. There is no exploit available.
A vulnerability was found in Keycloak. It has been rated as critical. Affected by this issue is some unknown functionality of the component mTLS Handler. The manipulation leads to improper authentication.
This vulnerability is handled as CVE-2024-10039. The attack needs to be done within the local network. There is no exploit available.
A vulnerability was found in Keycloak up to 26. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Proxy Header Handler. The manipulation leads to denial of service.
This vulnerability is known as CVE-2024-9666. The attack can only be initiated within the local network. There is no exploit available.
A vulnerability was found in authentik. It has been classified as problematic. Affected is an unknown function of the file /-/metrics/. The manipulation of the argument SECRET_KEY leads to observable timing discrepancy.
This vulnerability is traded as CVE-2024-52307. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.1.117/6.6.61/6.11.8 and classified as critical. This issue affects the function scan_work of the component nvme-multipath. The manipulation leads to deadlock.
The identification of this vulnerability is CVE-2024-53093. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 6.11.8 and classified as problematic. This vulnerability affects the function afs_wake_up_async_call. The manipulation leads to uncontrolled recursion.
This vulnerability was named CVE-2024-53090. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.6.61/6.11.8. This affects the function sendpage_ok of the component RDMA. The manipulation leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2024-53094. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Gibbon up to 27.0.00. Affected by this issue is some unknown functionality of the file /Gibbon/modules/User Admin/user_manage_editProcess.php.. The manipulation of the argument email leads to cross site scripting.
This vulnerability is handled as CVE-2024-51337. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 6.6.61/6.11.8. Affected by this vulnerability is the function tls_sw_ctx_rx of the component bpf. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2024-53091. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in Linux Kernel up to 6.6.61/6.11.8. Affected is the function tcp_write_timer_handler of the component SMB Client. The manipulation leads to improper update of reference count.
This vulnerability is traded as CVE-2024-53095. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.11.8. It has been rated as critical. This issue affects some unknown processing of the component LoongArch. The manipulation leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2024-53089. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.11.8. It has been declared as problematic. This vulnerability affects the function vp_modern_avq_cleanup. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2024-53092. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.