Aggregator
Siemens Warns of a Critical Vulnerability in UMC
11 months 3 weeks ago
Heap Overflow Flaw Threatens Industrial Control Systems Globally
Siemens issued a security advisory for a vulnerability affecting industrial control systems in its User Management Component that could enable attackers to execute arbitrary code. The heap-based buffer overflow flaw impacts products used in manufacturing and the energy sector.
Siemens issued a security advisory for a vulnerability affecting industrial control systems in its User Management Component that could enable attackers to execute arbitrary code. The heap-based buffer overflow flaw impacts products used in manufacturing and the energy sector.
Federal Cyber Operations Would Downgrade Under Shutdown
11 months 3 weeks ago
Government Shutdown Could See Thousands of Federal Cyber Workers Furloughed
A looming shutdown could sharply reduce the Cybersecurity and Infrastructure Security Agency's operations, furloughing two-thirds of its workforce and exposing critical federal networks to heightened cyber threats, especially as malicious actors target vulnerable systems during the holiday season.
A looming shutdown could sharply reduce the Cybersecurity and Infrastructure Security Agency's operations, furloughing two-thirds of its workforce and exposing critical federal networks to heightened cyber threats, especially as malicious actors target vulnerable systems during the holiday season.
Editors' Panel: Cybersecurity 2024 - Thanks for the Memories
11 months 3 weeks ago
Looking Back on the Ransomware Attacks, Resilience Lessons and Tech Trends
In the latest weekly update, ISMG editors discussed defining cybersecurity moments of 2024, from the CrowdStrike outage and its implications for vendor resilience to ransomware's continued evolution, and the shifting dynamics in the tech industry affecting startups and M&A activity.
In the latest weekly update, ISMG editors discussed defining cybersecurity moments of 2024, from the CrowdStrike outage and its implications for vendor resilience to ransomware's continued evolution, and the shifting dynamics in the tech industry affecting startups and M&A activity.
Alleged LockBit Coder Faces 41-Count Indictment in US
11 months 3 weeks ago
US Seeks Extradition of Dual Russian and Israeli Citizen Rostislav Panev from Israel
A newly unsealed U.S. federal indictment against Rostislav Panev says the LockBit ransomware operation paid the Israeli national a $10,000 monthly salary for coding and consulting services. Federal prosecutors are seeking Panev's extradition from Israel following his August arrest.
A newly unsealed U.S. federal indictment against Rostislav Panev says the LockBit ransomware operation paid the Israeli national a $10,000 monthly salary for coding and consulting services. Federal prosecutors are seeking Panev's extradition from Israel following his August arrest.
Осторожно, калькулятор: приложение для расчёта ИМТ воровало SMS и пароли
11 months 3 weeks ago
Обычный просчёт индекса массы тела лишает пользователей приватности.
Re @networkservice The Swiss of course, it's a Wyler level. Their 2d digital one that gives 2 axis of level readings at 0.001mm/m resolution simultane...
11 months 3 weeks ago
因欧盟关于USB-C接口的规定 苹果即日起再欧盟下架多款iPhone
11 months 3 weeks ago
CVE-2002-0386 | Oracle Application Server 9.0.2 Administration Module denial of service (EDB-21911 / Nessus ID 11076)
11 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in Oracle Application Server 9.0.2. Affected by this issue is some unknown functionality of the component Administration Module. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2002-0386. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
【AI速读】2010-2024美国发布的《中国军力报告》
11 months 3 weeks ago
2024年12月18日,美国国防部公开发布《涉及中华人民共和国的军事与安全发展》年度报告,俗称《中国军力报告》。这份美国国会授权的报告描绘了中国国家、经济和军事战略的当前进程,并提供了对解放军(PLA
【AI速读】2010-2024美国发布的《中国军力报告》
11 months 3 weeks ago
2024年12月18日,美国国防部公开发布《涉及中华人民共和国的军事与安全发展》年度报告,俗称《中国军力报告》。
CVE-2015-5091 | Adobe Acrobat Reader up to 10.1.14/11.0.11 input validation (APSB15-15 / Nessus ID 84800)
11 months 3 weeks ago
A vulnerability classified as problematic has been found in Adobe Acrobat Reader up to 10.1.14/11.0.11. Affected is an unknown function. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2015-5091. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-5092 | Adobe Acrobat Reader up to 10.1.14/11.0.11 information disclosure (APSB15-15 / Nessus ID 84800)
11 months 3 weeks ago
A vulnerability classified as critical was found in Adobe Acrobat Reader up to 10.1.14/11.0.11. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2015-5092. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-5093 | Adobe Acrobat Reader up to 10.1.14/11.0.11 memory corruption (APSB15-15 / Nessus ID 84800)
11 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Adobe Acrobat Reader up to 10.1.14/11.0.11. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2015-5093. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-5094 | Adobe Acrobat Reader up to 10.1.14/11.0.11 memory corruption (APSB15-15 / Nessus ID 84800)
11 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Adobe Acrobat Reader up to 10.1.14/11.0.11. This affects an unknown part. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2015-5094. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-5087 | Adobe Acrobat Reader up to 10.1.14/11.0.11 memory corruption (APSB15-15 / Nessus ID 84800)
11 months 3 weeks ago
A vulnerability was found in Adobe Acrobat Reader up to 10.1.14/11.0.11 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2015-5087. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-5088 | Adobe Acrobat Reader up to 10.1.14/11.0.11 information disclosure (APSB15-15 / Nessus ID 84800)
11 months 3 weeks ago
A vulnerability was found in Adobe Acrobat Reader up to 10.1.14/11.0.11. It has been classified as critical. This affects an unknown part. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2015-5088. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-5089 | Adobe Acrobat Reader up to 10.1.14/11.0.11 information disclosure (APSB15-15 / Nessus ID 84800)
11 months 3 weeks ago
A vulnerability was found in Adobe Acrobat Reader up to 10.1.14/11.0.11. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to information disclosure.
This vulnerability was named CVE-2015-5089. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-5090 | Adobe Acrobat Reader up to 10.1.14/11.0.11 access control (APSB15-15 / Nessus ID 84800)
11 months 3 weeks ago
A vulnerability was found in Adobe Acrobat Reader up to 10.1.14/11.0.11. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2015-5090. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-0595 | Novell Client OES11 SP2 on Linux nwrights memory corruption (ID 7014932 / Nessus ID 76248)
11 months 3 weeks ago
A vulnerability was found in Novell Client OES11 SP2 on Linux. It has been declared as problematic. This vulnerability affects unknown code of the file /opt/novell/ncl/bin/nwrights. The manipulation leads to memory corruption.
This vulnerability was named CVE-2014-0595. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com