Aggregator
North Korea actors use OtterCookie malware in Contagious Interview campaign
8 months 1 week ago
North Korea-linked threat actors are using the OtterCookie backdoor to target software developers with fake job offers. North Korea-linked threat actors were spotted using new malware called OtterCookie as part of the Contagious Interview campaign that targets software developer community with fake job offers. The Contagious Interview campaign was first detailed by Palo Alto Networks […]
Pierluigi Paganini
North Korea actors use OtterCookie malware in Contagious Interview campaign
8 months 1 week ago
North Korea actors use OtterCookie malware in Contagious Interview campaign
Ransomware Group Hits Substance Abuse Treatment Service
8 months 1 week ago
American Addiction Centers Says 422,424 Individuals' Private Details Exposed
Substance abuse treatment company American Addiction Centers is warning nearly half a million patients that ransomware-wielding attackers stole their personal details, including names and Social Security numbers. The Rhysida ransomware operation claimed to perpetrate the attack.
Substance abuse treatment company American Addiction Centers is warning nearly half a million patients that ransomware-wielding attackers stole their personal details, including names and Social Security numbers. The Rhysida ransomware operation claimed to perpetrate the attack.
Feds Identify Ninth Telecom Victim in Salt Typhoon Hack
8 months 1 week ago
Officials Say Chinese Hackers Maintained 'Broad and Full' Access to Telecom Systems
Federal officials told reporters Friday that ongoing investigations into the Salt Typhoon cyberespionage campaign have identified a ninth victim company affected by the attack, in which hackers maintained "broad and full" access to vulnerable communications infrastructure across the country.
Federal officials told reporters Friday that ongoing investigations into the Salt Typhoon cyberespionage campaign have identified a ninth victim company affected by the attack, in which hackers maintained "broad and full" access to vulnerable communications infrastructure across the country.
US Finalizes Rule Throttling Bulk Data Sales to China
8 months 1 week ago
Rule Aims to Stymie Weaponization of Americans' Data
The U.S. federal government finalized Friday regulations throttling the bulk commercial transfer to China and Russia of data pinpointing Americans' location, their health data, or biometric and genomic identifiers. The rule implements a February executive order from President Joe Biden.
The U.S. federal government finalized Friday regulations throttling the bulk commercial transfer to China and Russia of data pinpointing Americans' location, their health data, or biometric and genomic identifiers. The rule implements a February executive order from President Joe Biden.
White House Clears HIPAA Security Rule Update
8 months 1 week ago
HHS Proposes Encryption, Security Standards for Healthcare Firms
The U.S. Department of Health and Human Services is proposing new rules for healthcare organizations that aim to bolster protections for Americans by requiring companies to encrypt sensitive patient data and conduct routine compliance evaluations amid increased threats targeting the sector.
The U.S. Department of Health and Human Services is proposing new rules for healthcare organizations that aim to bolster protections for Americans by requiring companies to encrypt sensitive patient data and conduct routine compliance evaluations amid increased threats targeting the sector.
DoS в PAN-OS: обновите свои межсетевые экраны как можно скорее
8 months 1 week ago
Уязвимость CVE-2024-3393 затронула сотни устройств по всему миру.
CVE-2021-28420 | Seo Panel 4.8.0 alerts.php from_time cross site scripting (EDB-49935)
8 months 1 week ago
A vulnerability was found in Seo Panel 4.8.0 and classified as problematic. This issue affects some unknown processing of the file alerts.php. The manipulation of the argument from_time leads to cross site scripting.
The identification of this vulnerability is CVE-2021-28420. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
从被动接收到主动参与:我的 AI 辅助学习方法论
8 months 1 week ago
Matrix 首页推荐 Matrix 是少数派的写作社区,我们主张分享真实的产品体验,有实用价值的经验与思考。我们会不定期挑选 Matrix 最优质的文章,展示来自用户的最真实的体验和观点。 文章代表
CVE-2004-1288 | Siag o3read .3 o3read.c parse_html memory corruption (EDB-25010 / Nessus ID 16411)
8 months 1 week ago
A vulnerability has been found in Siag o3read .3 and classified as very critical. Affected by this vulnerability is the function parse_html of the file o3read.c. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2004-1288. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Space Bears
8 months 1 week ago
cohenido
CVE-2010-5029 | Codefabrik Ecomat CMS 5.0 index.php show sql injection (EDB-14104 / BID-40491)
8 months 1 week ago
A vulnerability was found in Codefabrik Ecomat CMS 5.0 and classified as critical. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument show leads to sql injection.
This vulnerability is handled as CVE-2010-5029. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
15,000+ Four-Faith Routers Exposed to New Exploit Due to Default Credentials
8 months 1 week ago
A high-severity flaw impacting select Four-Faith industrial routers has come under active exploitation in the wild, according to new findings from VulnCheck.
The vulnerability, tracked as CVE-2024-12856 (CVSS score: 7.2), has been described as an operating system (OS) command injection bug affecting router models F3x24 and F3x36.
The severity of the shortcoming is lower due to the fact that it
The Hacker News
15,000+ Four-Faith Routers Exposed to New Exploit Due to Default Credentials
8 months 1 week ago
Vulnerability / Threat IntelligenceA high-severity flaw impacting select Four-Faith routers has co
CVE-2010-2099 | e107 CMS up to 0.7.2 access control (EDB-12715 / Nessus ID 46692)
8 months 1 week ago
A vulnerability was found in e107 CMS up to 0.7.2 and classified as critical. This issue affects some unknown processing. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2010-2099. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Кибератака на Cyberhaven: хакеры внедрили вредоносное обновление в расширение Chrome
8 months 1 week ago
Mandiant присоединился к расследованию взлома.
“美亚柏科杯” 数据安全管理员职业技能竞赛总决赛在厦门盛大开幕
8 months 1 week ago
第三届全国数据安全职业技能竞赛暨第三届全国安防行业职业技能竞赛“美亚柏科杯”网络安全管理员职业技能竞赛总决赛在福建省厦门市美亚柏科培训基地盛大开幕。
“美亚柏科杯” 数据安全管理员职业技能竞赛总决赛在厦门盛大开幕
8 months 1 week ago
鹭岛风情天下秀,网安人才共潮涌。12月26日,由中国安全防范产品行业协会(以下简称中安协)和中国就业培训技术指导中心联合主办,国投智能(厦门)信息股份有限公司承办,厦门市美亚柏科信息安全研究所有限公司
CVE-2021-28418 | Seo Panel 4.8.0 settings.php category cross site scripting (EDB-49932)
8 months 1 week ago
A vulnerability, which was classified as problematic, was found in Seo Panel 4.8.0. This affects an unknown part of the file settings.php. The manipulation of the argument category leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2021-28418. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com