Aggregator
UK Passes Data Use and Access Regulation Bill
5 months 3 weeks ago
Government Says Bill Will 'Pump 10 Billion Pounds' Into Economy
The U.K. government passed the Data Use and Access Bill that will introduce a host of privacy changes intended at making data processing more lenient with a motive to promote economic growth. Whether the EU will continue to find British law adequate is an open question.
The U.K. government passed the Data Use and Access Bill that will introduce a host of privacy changes intended at making data processing more lenient with a motive to promote economic growth. Whether the EU will continue to find British law adequate is an open question.
Israel-Iran War: Hacktivist Groups' Claimed Activity Surges
5 months 3 weeks ago
While Exceptions Apply, Such Efforts Often Only Amount to Psychological Operations
Missile exchanges over the skies of Israel and Iran entered their eighth day, wreaking death and destruction. Hacktivists are taking that as their cue to join the fray, although whether their efforts function as anything more than psychological operations is unclear.
Missile exchanges over the skies of Israel and Iran entered their eighth day, wreaking death and destruction. Hacktivists are taking that as their cue to join the fray, although whether their efforts function as anything more than psychological operations is unclear.
Beware the CyberAv3ngers
5 months 3 weeks ago
Iranian OT Hacking Team Has Gone Quiet … Too Quiet
Armed exchanges between Iran and Israel and the prospect of U.S. armed intervention against Tehran has cyber defenders warning about hacking risks to critical infrastructure. Iran's CyberAv3ngers doesn't possess the sophistication of Chinese or Russian actors but it's still a persistent threat.
Armed exchanges between Iran and Israel and the prospect of U.S. armed intervention against Tehran has cyber defenders warning about hacking risks to critical infrastructure. Iran's CyberAv3ngers doesn't possess the sophistication of Chinese or Russian actors but it's still a persistent threat.
Malicious AI Agent in LangSmith May Have Exposed API Data
5 months 3 weeks ago
High-Severity Flaw in LangChain's AI Tooling Hub Now Patched
A flaw in the LangSmith platform, an open-source framework that helps developers build LLM-powered applications, can enable hackers to siphon sensitive data, said Noma Security. Dubbed AgentSmith, the flaw can allow attackers to embed malicious proxy configurations into public AI agents.
A flaw in the LangSmith platform, an open-source framework that helps developers build LLM-powered applications, can enable hackers to siphon sensitive data, said Noma Security. Dubbed AgentSmith, the flaw can allow attackers to embed malicious proxy configurations into public AI agents.
CVE-2022-1563 | WPGraphQL wp-graphql-woocommerce Plugin 0.12.4 on WordPress access control (EUVD-2022-24855)
5 months 3 weeks ago
A vulnerability classified as critical was found in WPGraphQL wp-graphql-woocommerce Plugin 0.12.4 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2022-1563. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-52339 | libebml up to 1.4.4 MemIOCallback.cpp integer overflow (Issue 147 / EUVD-2023-56996)
5 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in libebml up to 1.4.4. Affected is an unknown function of the file MemIOCallback.cpp. The manipulation leads to integer overflow.
This vulnerability is traded as CVE-2023-52339. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20940 | Oracle Knowledge Management up to 12.2.13 Create/Update/Authoring Flow (EUVD-2024-18654)
5 months 3 weeks ago
A vulnerability has been found in Oracle Knowledge Management up to 12.2.13 and classified as critical. This vulnerability affects unknown code of the component Create/Update/Authoring Flow. The manipulation leads to an unknown weakness.
This vulnerability was named CVE-2024-20940. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-20916 | Oracle Enterprise Manager Base Platform 13.5.0.0 Event Management privilege escalation (EUVD-2024-18631)
5 months 3 weeks ago
A vulnerability was found in Oracle Enterprise Manager Base Platform 13.5.0.0 and classified as critical. Affected by this issue is some unknown functionality of the component Event Management. The manipulation leads to privilege escalation.
This vulnerability is handled as CVE-2024-20916. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-20920 | Oracle Solaris 11 Filesystem information disclosure (EUVD-2024-18635)
5 months 3 weeks ago
A vulnerability was found in Oracle Solaris 11. It has been rated as problematic. This issue affects some unknown processing of the component Filesystem. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2024-20920. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2024-20918 | Oracle Java SE up to 8u391/8u391-perf/11.0.21/17.0.9/21.0.1 Hotspot (EUVD-2024-18633 / Nessus ID 208585)
5 months 3 weeks ago
A vulnerability was found in Oracle Java SE up to 8u391/8u391-perf/11.0.21/17.0.9/21.0.1 and classified as critical. This issue affects some unknown processing of the component Hotspot. The manipulation leads to an unknown weakness.
The identification of this vulnerability is CVE-2024-20918. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-20944 | Oracle iSupport up to 12.2.13 Internal Operations (EUVD-2024-18658)
5 months 3 weeks ago
A vulnerability classified as critical was found in Oracle iSupport up to 12.2.13. This vulnerability affects unknown code of the component Internal Operations. The manipulation leads to an unknown weakness.
This vulnerability was named CVE-2024-20944. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-20961 | Oracle MySQL Server 8.0.35 and prior/8.2.0 and prior Optimizer denial of service (EUVD-2024-18675 / Nessus ID 235542)
5 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Oracle MySQL Server 8.0.35 and prior/8.2.0 and prior. Affected by this issue is some unknown functionality of the component Optimizer. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2024-20961. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-20965 | Oracle MySQL Cluster denial of service (EUVD-2024-18679 / Nessus ID 235542)
5 months 3 weeks ago
A vulnerability was found in Oracle MySQL Cluster 7.5.32 and prior/7.6.28 and prior/8.0.35 and prior/8.2.0 and prior and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2024-20965. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-20983 | Oracle MySQL Server 8.0.34 and prior DML denial of service (EUVD-2024-18697 / Nessus ID 235542)
5 months 3 weeks ago
A vulnerability was found in Oracle MySQL Server 8.0.34 and prior. It has been declared as critical. This vulnerability affects unknown code of the component DML. The manipulation leads to denial of service.
This vulnerability was named CVE-2024-20983. The attack can be initiated remotely. There is no exploit available.
vuldb.com
Financial deepfake scams targeted in bipartisan Senate bill
5 months 3 weeks ago
New legislation seeks the creation of a Treasury-led task force to examine and combat AI-fueled scams that trick Americans out of their money.
The post Financial deepfake scams targeted in bipartisan Senate bill appeared first on CyberScoop.
mbracken
CVE-2024-20942 | Oracle Complex Maintenance, Repair, and Overhaul 11.5/12.1/12.2 LOV (EUVD-2024-18656)
5 months 3 weeks ago
A vulnerability classified as critical has been found in Oracle Complex Maintenance, Repair, and Overhaul 11.5/12.1/12.2. This affects an unknown part of the component LOV. The manipulation leads to an unknown weakness.
This vulnerability is uniquely identified as CVE-2024-20942. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-22362 | Drupal up to 9.4.3 Structural Element denial of service (EUVD-2024-0265)
5 months 3 weeks ago
A vulnerability was found in Drupal. It has been classified as problematic. This affects an unknown part of the component Structural Element Handler. The manipulation leads to denial of service. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is uniquely identified as CVE-2024-22362. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20981 | Oracle MySQL Server 8.0.35 and prior/8.2.0 and prior DDL denial of service (EUVD-2024-18695 / Nessus ID 235542)
5 months 3 weeks ago
A vulnerability was found in Oracle MySQL Server 8.0.35 and prior/8.2.0 and prior. It has been classified as critical. This affects an unknown part of the component DDL. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2024-20981. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-20985 | Oracle MySQL Server 8.0.35 and prior/8.2.0 and prior UDF denial of service (EUVD-2024-18699 / Nessus ID 235542)
5 months 3 weeks ago
A vulnerability classified as critical has been found in Oracle MySQL Server 8.0.35 and prior/8.2.0 and prior. This affects an unknown part of the component UDF. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2024-20985. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com