Finastra has confirmed it warned customers of a cybersecurity incident after a threat actor began selling allegedly stolen data on a hacking forum. [...]
A vulnerability, which was classified as very critical, was found in ISC BIND 4.9.6/8.1/8.1.1. Affected is an unknown function of the component iquery. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-1999-0009. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
MITRE has shared this year's top 25 list of the most common and dangerous software weaknesses behind more than 31,000 vulnerabilities disclosed between June 2023 and June 2024. [...]
In US Senate testimony, a CrowdStrike exec explained how this advanced persistent threat penetrated telcos in Asia and Africa, gathering SMS messages, unique identifiers, and other metadata along the way.
A vulnerability classified as problematic was found in IDURAR up to 2.0.1. Affected by this vulnerability is an unknown functionality of the file /api/email/update of the component PATCH Request Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2023-52265. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Mitel MiContact Center Business up to 10.0.0.4. This affects an unknown part of the component Ignite. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-35283. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability has been found in Mp3tag up to 3.26d and classified as problematic. This vulnerability affects unknown code in the library tak_deco_lib.dll of the component DLL Handler. The manipulation leads to uncontrolled search path.
This vulnerability was named CVE-2024-7193. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
The vendor was contacted early, responded in a very professional manner and immediately released a fixed version of the affected product.
It is recommended to upgrade the affected component.
The vendor was contacted early, responded in a very professional manner and immediately released a fixed version of the affected product.
Cyera's Valuation Doubles Amid Expansion From DSPM to DLP, Identity Protection Cyera secures $300M in funding from Accel and Sapphire Ventures, doubling its valuation to $3 billion. The company is enhancing its data security platform by integrating DSPM with DLP and identity security capabilities, addressing enterprise demand for comprehensive solutions.
Company Probing Customers Affected After Attacker Claims 400 Gigabyte Data Theft Financial technology firm Finastra is warning customers that it suffered a breach of a secure file transfer system that it uses to relay information to some customers, leading to an unknown quantity of data being exfiltrated by an attacker. The company is still identifying affected customers.