Aggregator
每周勒索威胁摘要
1 year 4 months ago
1. Blackbasta勒索团伙公布新的受害公司
2. RansomHub勒索团伙公布新的受害公司
3. Cactus勒索团伙公布了新的受害公司
HomuWitch勒索家族分析报告
1 year 4 months ago
HomuWitch勒索病毒最初出现于 2023 年 7 月。与当前大多数勒索软件病毒不同,HomuWitch 的目标是最终用户(个人),而不是机构和公司。经测试验证,目前奇安信天锁已支持对此类攻击的查杀、拦截和解密等立体化防护。
100 миллионов жертв: взлом Change Healthcare сотрясает мир
1 year 4 months ago
США столкнулись с крупнейшей в истории утечкой медицинских данных.
CISOs Should Be Directing IAM Strategy — Here’s Why
1 year 4 months ago
By placing IAM strategy and enforcement under the CISO’s purview, enterprises can ensure that it is treated as a critical component of the overall security strategy.
The post CISOs Should Be Directing IAM Strategy — Here’s Why appeared first on Security Boulevard.
Umaimah Khan
CVE-2024-9488 | Comments Plugin up to 7.6.24 on WordPress improper authentication
1 year 4 months ago
A vulnerability was found in Comments Plugin up to 7.6.24 on WordPress. It has been classified as critical. This affects an unknown part. The manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2024-9488. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-9109 | UPS Live Rates and Access Points Plugin up to 2.3.11 on WordPress Plugin API Key Reset authorization
1 year 4 months ago
A vulnerability classified as problematic was found in UPS Live Rates and Access Points Plugin up to 2.3.11 on WordPress. Affected by this vulnerability is an unknown functionality of the component Plugin API Key Reset Handler. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2024-9109. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-10011 | BuddyPress Plugin up to 14.1.0 on WordPress path traversal
1 year 4 months ago
A vulnerability was found in BuddyPress Plugin up to 14.1.0 on WordPress. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2024-10011. The attack may be initiated remotely. There is no exploit available.
vuldb.com
Согласие или штраф: США устанавливают правила шпионажа за сотрудниками
1 year 4 months ago
Надзорные органы запускают новую эру трудовых отношений в офисах.
CVE-2024-47041 | Google Android kernel syscall.c valid_address out-of-bounds
1 year 4 months ago
A vulnerability was found in Google Android kernel. It has been rated as problematic. Affected by this issue is the function valid_address of the file syscall.c. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2024-47041. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-47035 | Google Android virtio_ring.h vring_init out-of-bounds write
1 year 4 months ago
A vulnerability was found in Google Android. It has been declared as critical. Affected by this vulnerability is the function vring_init of the file external/headers/include/virtio/virtio_ring.h. The manipulation leads to out-of-bounds write.
This vulnerability is known as CVE-2024-47035. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Футболка с обещаниями: одежда из Китая стала инструментом политического обмана
1 year 4 months ago
Тысячи футболок с политическими лозунгами оказались крупной аферой.
CVE-2024-47031 | Google Android ABL Privilege Escalation
1 year 4 months ago
A vulnerability was found in Google Android. It has been classified as problematic. Affected is an unknown function of the component ABL. The manipulation leads to Privilege Escalation.
This vulnerability is traded as CVE-2024-47031. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-47033 | Google Android lwis_allocator.c lwis_allocator_free use after free
1 year 4 months ago
A vulnerability was found in Google Android and classified as problematic. This issue affects the function lwis_allocator_free of the file lwis_allocator.c. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2024-47033. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-47030 | Google Android ACPM information disclosure
1 year 4 months ago
A vulnerability has been found in Google Android and classified as problematic. This vulnerability affects unknown code of the component ACPM. The manipulation leads to information disclosure.
This vulnerability was named CVE-2024-47030. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-47027 | Google Android lib/sm/shared_mem.c sm_mem_compat_get_vmm_obj input validation
1 year 4 months ago
A vulnerability, which was classified as problematic, was found in Google Android. This affects the function sm_mem_compat_get_vmm_obj in the library lib/sm/shared_mem.c. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2024-47027. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-47024 | Google Android virtio_ring.h vring_size out-of-bounds write
1 year 4 months ago
A vulnerability, which was classified as critical, has been found in Google Android. Affected by this issue is the function vring_size of the file external/headers/include/virtio/virtio_ring.h. The manipulation leads to out-of-bounds write.
This vulnerability is handled as CVE-2024-47024. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-47029 | Google Android trusty_shared_memory_manager.cc GetSharedMemory out-of-bounds
1 year 4 months ago
A vulnerability classified as problematic was found in Google Android. Affected by this vulnerability is the function TrustySharedMemoryManager::GetSharedMemory of the file ondevice/trusty/trusty_shared_memory_manager.cc. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2024-47029. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-47025 | Google Android drm_fw.c ppmp_protect_buf information disclosure
1 year 4 months ago
A vulnerability classified as problematic has been found in Google Android. Affected is the function ppmp_protect_buf of the file drm_fw.c. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-47025. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-47034 | Google Android out-of-bounds
1 year 4 months ago
A vulnerability was found in Google Android. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to out-of-bounds read.
The identification of this vulnerability is CVE-2024-47034. Attacking locally is a requirement. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com