Aggregator
Feds Fine Mental Health Clinic $100K in 2020 HIPAA Case
4 days 5 hours ago
LA County Clinic Delayed Access to Patient's Medical Records During Pandemic
Federal regulators have fined a Los Angeles county mental health clinic $100,000 for failure to provide a patient with timely access to her requested health records during the COVID-19 pandemic. The case is the U.S. government's 51st HIPAA patient right-of-access enforcement action.
Federal regulators have fined a Los Angeles county mental health clinic $100,000 for failure to provide a patient with timely access to her requested health records during the COVID-19 pandemic. The case is the U.S. government's 51st HIPAA patient right-of-access enforcement action.
Coast Guard Warns of Continued Risks in Chinese Port Cranes
4 days 5 hours ago
Military Says Ship-to-Shore Cranes Made in China Include Dangerous Security Flaws
The United States Coast Guard is continuing to warn of significant security risks embedded in ship-to-shore cranes developed by companies with ties to Beijing while issuing new sensitive requirements for ports operating Chinese-made cranes across the country.
The United States Coast Guard is continuing to warn of significant security risks embedded in ship-to-shore cranes developed by companies with ties to Beijing while issuing new sensitive requirements for ports operating Chinese-made cranes across the country.
Nightwing CEO on Post-Raytheon Independence, Cyber Expertise
4 days 5 hours ago
Nightwing's John DeSimone Talks Growth, Threats, National Security and AI Strategy
Nightwing CEO John DeSimone reveals how the company’s independence from Raytheon allows it to better serve customers, invest in intelligence, advanced AI and data solutions, address sophisticated cyberthreats, and maintain a no-fail mission approach in the face of rising security threats.
Nightwing CEO John DeSimone reveals how the company’s independence from Raytheon allows it to better serve customers, invest in intelligence, advanced AI and data solutions, address sophisticated cyberthreats, and maintain a no-fail mission approach in the face of rising security threats.
Feds Seize PopeyeTools Marketplace, Charge Alleged Operators
4 days 5 hours ago
Justice Department Dismantles Cybercrime Hub, Announces Charges and Seizes Crypto
The Justice Department has seized PopeyeTools, a notorious cybercrime marketplace, while announcing criminal charges for three alleged operators behind the website, which generated over $1.7 million in revenue, according to a Wednesday announcement.
The Justice Department has seized PopeyeTools, a notorious cybercrime marketplace, while announcing criminal charges for three alleged operators behind the website, which generated over $1.7 million in revenue, according to a Wednesday announcement.
Let's Give Thanks for How Far We've Come - and Forge Ahead!
4 days 5 hours ago
Cybersecurity Training and Education Must Evolve to Keep Pace With the Profession
Over the past few decades, cybersecurity has evolved from a niche concern into a global priority, creating a vast and dynamic career field. While we celebrate the journey, let's also focus on how today's cybersecurity professionals will shape the future.
Over the past few decades, cybersecurity has evolved from a niche concern into a global priority, creating a vast and dynamic career field. While we celebrate the journey, let's also focus on how today's cybersecurity professionals will shape the future.
Feds Fine Mental Health Clinic $100K in 2020 HIPAA Case
4 days 5 hours ago
LA County Clinic Delayed Access to Patient's Medical Records During Pandemic
Federal regulators have fined a Los Angeles county mental health clinic $100,000 for failure to provide a patient with timely access to her requested health records during the COVID-19 pandemic. The case is the U.S. government's 51st HIPAA patient right-of-access enforcement action.
Federal regulators have fined a Los Angeles county mental health clinic $100,000 for failure to provide a patient with timely access to her requested health records during the COVID-19 pandemic. The case is the U.S. government's 51st HIPAA patient right-of-access enforcement action.
Coast Guard Warns of Continued Risks in Chinese Port Cranes
4 days 5 hours ago
Military Says Ship-to-Shore Cranes Made in China Include Dangerous Security Flaws
The United States Coast Guard is continuing to warn of significant security risks embedded in ship-to-shore cranes developed by companies with ties to Beijing while issuing new sensitive requirements for ports operating Chinese-made cranes across the country.
The United States Coast Guard is continuing to warn of significant security risks embedded in ship-to-shore cranes developed by companies with ties to Beijing while issuing new sensitive requirements for ports operating Chinese-made cranes across the country.
Nightwing CEO on Post-Raytheon Independence, Cyber Expertise
4 days 5 hours ago
Nightwing's John DeSimone Talks Growth, Threats, National Security and AI Strategy
Nightwing CEO John DeSimone reveals how the company’s independence from Raytheon allows it to better serve customers, invest in intelligence, advanced AI and data solutions, address sophisticated cyberthreats, and maintain a no-fail mission approach in the face of rising security threats.
Nightwing CEO John DeSimone reveals how the company’s independence from Raytheon allows it to better serve customers, invest in intelligence, advanced AI and data solutions, address sophisticated cyberthreats, and maintain a no-fail mission approach in the face of rising security threats.
Feds Seize PopeyeTools Marketplace, Charge Alleged Operators
4 days 5 hours ago
Justice Department Dismantles Cybercrime Hub, Announces Charges and Seizes Crypto
The Justice Department has seized PopeyeTools, a notorious cybercrime marketplace, while announcing criminal charges for three alleged operators behind the website, which generated over $1.7 million in revenue, according to a Wednesday announcement.
The Justice Department has seized PopeyeTools, a notorious cybercrime marketplace, while announcing criminal charges for three alleged operators behind the website, which generated over $1.7 million in revenue, according to a Wednesday announcement.
Securing the Software Supply Chain: Checkmarx One Expands its Offerings
4 days 5 hours ago
The software supply chain is under siege. Threat actors increasingly exploit weaknesses in code
Ubuntu系统软件中的5个漏洞潜藏了10年才被发现
4 days 5 hours ago
Ubuntu系统中的实用程序Needrestart近日被曝出存在5个本地权限提升(LPE)漏洞,这些漏洞已经潜藏了10年才被发现。
Forums Refresh
4 days 5 hours ago
Over the past year we have been hard at work on refreshing the Kali Forums, and today we are proud t
CVE-2024-50968 | itsourcecode Agri-Trading Online Shopping System 1.0 Add to Cart quantity behavioral workflow
4 days 5 hours ago
A vulnerability was found in itsourcecode Agri-Trading Online Shopping System 1.0. It has been classified as problematic. Affected is an unknown function of the component Add to Cart. The manipulation of the argument quantity with the input -0 leads to enforcement of behavioral workflow.
This vulnerability is traded as CVE-2024-50968. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2017-13227 | Google Android 8.0/8.1 Autofill Service information disclosure
4 days 5 hours ago
A vulnerability was found in Google Android 8.0/8.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Autofill Service. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2017-13227. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-52613 | tsMuxer nightly-2024-05-12-02-01-18 MOV Video File heap-based overflow (Issue 881)
4 days 5 hours ago
A vulnerability was found in tsMuxer nightly-2024-05-12-02-01-18. It has been classified as critical. This affects an unknown part of the component MOV Video File Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2024-52613. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-11240 | IBPhoenix ibWebAdmin up to 1.0.2 Banco de Dados Tab /database.php db_login_role cross site scripting
4 days 5 hours ago
A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unknown processing of the file /database.php of the component Banco de Dados Tab. The manipulation of the argument db_login_role leads to cross site scripting.
The identification of this vulnerability is CVE-2024-11240. The attack may be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-11246 | code-projects Farmacia 1.0 /adicionar-cliente.php nome/cpf/dataNascimento cross site scripting
4 days 5 hours ago
A vulnerability, which was classified as problematic, was found in code-projects Farmacia 1.0. Affected is an unknown function of the file /adicionar-cliente.php. The manipulation of the argument nome/cpf/dataNascimento leads to cross site scripting.
This vulnerability is traded as CVE-2024-11246. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The initial researcher advisory mentions the parameter "nome" to be affected. But further inspection indicates that other parameters might be affected as well.
vuldb.com
CVE-2024-49758 | LibreNMS up to 24.9.x ExamplePlugin cross site scripting
4 days 5 hours ago
A vulnerability was found in LibreNMS up to 24.9.x. It has been classified as problematic. This affects an unknown part of the component ExamplePlugin. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-49758. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-49754 | LibreNMS up to 24.9.x API-Access Page token cross site scripting
4 days 5 hours ago
A vulnerability was found in LibreNMS up to 24.9.x. It has been rated as problematic. This issue affects some unknown processing of the component API-Access Page. The manipulation of the argument token leads to cross site scripting.
The identification of this vulnerability is CVE-2024-49754. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com