Aggregator
CVE-2004-0312 | Linksys WAP55AG 1.0.7 information disclosure (EDB-23721 / XFDB-15257)
1 year 8 months ago
A vulnerability was found in Linksys WAP55AG 1.0.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2004-0312. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2016-10034 | Zend Framework up to 2.4.10/2.5.x/2.6.x/2.7.1 zend-mail setFrom command injection (EDB-40979 / Nessus ID 108931)
1 year 8 months ago
A vulnerability has been found in Zend Framework up to 2.4.10/2.5.x/2.6.x/2.7.1 and classified as critical. This vulnerability affects the function setFrom of the component zend-mail. The manipulation leads to command injection.
This vulnerability was named CVE-2016-10034. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2013-1648 | Open-Xchange Server 6.20.7/6.22.0/6.22.1 Gopher input validation (EDB-24791 / ID 803182)
1 year 8 months ago
A vulnerability, which was classified as problematic, was found in Open-Xchange Server 6.20.7/6.22.0/6.22.1. Affected is an unknown function of the component Gopher. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2013-1648. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
白泽ers Happy 1024 Day!程序员专属节日,代码改变世界!
1 year 8 months ago
白泽ers Happy 1024 Day!
CVE-2002-0686 | Iplanet Web Server 4.1 NS-rel-doc-name memory corruption (VU#612843 / XFDB-9506)
1 year 8 months ago
A vulnerability was found in Iplanet Web Server 4.1. It has been classified as critical. This affects an unknown part. The manipulation of the argument NS-rel-doc-name leads to memory corruption.
This vulnerability is uniquely identified as CVE-2002-0686. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
Unforeseen Risks to Medical Devices in Ransomware Attacks
1 year 8 months ago
While ransomware attacks against medical devices don't happen often, disruptive cyber incidents that affect the availability of the IT systems that medical devices rely on are a big concern that needs the industry's critical attention, said Jessica Wilkerson of the FDA.
Breach Roundup: CISA Proposes Security for Bulk Data Sales
1 year 8 months ago
Also: Payment Card Theft Trends, Internet Archive Update
This week, bulk data transfers to China, credit card theft, the Internet Archive still recovering and the Change Healthcare tally is now 100M. Ukraine fought phishers, civil society against the UN cybercrime treaty, TA866 and virtual hard drives spread malware. Google verified Sir Isaac Newton.
This week, bulk data transfers to China, credit card theft, the Internet Archive still recovering and the Change Healthcare tally is now 100M. Ukraine fought phishers, civil society against the UN cybercrime treaty, TA866 and virtual hard drives spread malware. Google verified Sir Isaac Newton.
Hackers Probing Newly Disclosed Fortinet Zero-Day
1 year 8 months ago
Mandiant Says High-Severity Flaw Could Give Attackers Remote Unauthenticated Access
Researchers at Mandiant say a new threat cluster, first observed June 27, has been exploiting a Fortinet zero-day that the network edge device manufacturer publicly disclosed Wednesday. Researchers said they can't assess the threat actor's motivation or location.
Researchers at Mandiant say a new threat cluster, first observed June 27, has been exploiting a Fortinet zero-day that the network edge device manufacturer publicly disclosed Wednesday. Researchers said they can't assess the threat actor's motivation or location.
Socure to Fortify Identity Services With $136M Effectiv Buy
1 year 8 months ago
Effectiv's 30-Person Team to Streamline Identity Services, Help Socure Grow Revenue
Socure has acquired Effectiv, integrating its engineering team of 30 to strengthen identity verification capabilities. The $136 million deal aims to speed up customer onboarding, enhance transaction monitoring, and deliver cross-platform solutions, with the product integration expected in 45 days.
Socure has acquired Effectiv, integrating its engineering team of 30 to strengthen identity verification capabilities. The $136 million deal aims to speed up customer onboarding, enhance transaction monitoring, and deliver cross-platform solutions, with the product integration expected in 45 days.
LinkedIn Fined 310 Million Euros for Privacy Violations
1 year 8 months ago
Irish Data Protection Commission Cites Social Platform for GDPR Violations
The Irish Data Protection Commission imposed a 310 million euro fine on LinkedIn for violating a European privacy law stemming from the company's use of customer data. It ordered the social media platform to bring its data processing under compliance.
The Irish Data Protection Commission imposed a 310 million euro fine on LinkedIn for violating a European privacy law stemming from the company's use of customer data. It ordered the social media platform to bring its data processing under compliance.
Apple creates Private Cloud Compute VM to let researchers find bugs
1 year 8 months ago
Apple created a Virtual Research Environment to allow public access to testing the security of its Private Cloud Compute system, and released the source code for some "key components" to help researchers analyze the privacy and safety features on the architecture. [...]
Ionut Ilascu
Open Source LLM Tool Sniffs Out Python Zero-Days
1 year 8 months ago
Vulnhuntr is a Python static code analyzer that uses Claude AI to find and explain complex, multistep vulnerabilities.
Dark Reading Staff
CVE-2002-0685 | PGP Freeware 7.0.3 Message Decoder memory corruption (VU#821139 / XFDB-9525)
1 year 8 months ago
A vulnerability was found in PGP Freeware 7.0.3 and classified as critical. Affected by this issue is some unknown functionality of the component Message Decoder. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2002-0685. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2002-0684 | ISC BIND 4.9.8 DNS Resolver getnetbyname/getnetbyaddr memory corruption (VU#542971 / Nessus ID 11318)
1 year 8 months ago
A vulnerability, which was classified as critical, was found in ISC BIND 4.9.8. Affected is the function getnetbyname/getnetbyaddr of the component DNS Resolver. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2002-0684. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Unforeseen Risks to Medical Devices in Ransomware Attacks
1 year 8 months ago
While ransomware attacks against medical devices don't happen often, disruptive cyber incidents that affect the availability of the IT systems that medical devices rely on are a big concern that needs the industry's critical attention, said Jessica Wilkerson of the FDA.
Live Webinar | CISO Leadership Blueprint to Managing Budgets, Third-Party Risks & Breaches
1 year 8 months ago
Electric Vehicle Charging Stations at Risk From Hack Attacks
1 year 8 months ago
Many Charging Cable Interfaces Have Exposed SSH and HTTP Ports, Researchers Warn
Researchers demonstrated that multiple brands of EV charging stations have vulnerabilities due to manufacturers often leaving open and unsecured SSH and HTTP ports. The risks of these vulnerabilities range from an expanded attack surface to a launching pad for assaults on the power grid.
Researchers demonstrated that multiple brands of EV charging stations have vulnerabilities due to manufacturers often leaving open and unsecured SSH and HTTP ports. The risks of these vulnerabilities range from an expanded attack surface to a launching pad for assaults on the power grid.
Cryptohack Roundup: Nigeria Drops Charges on Binance Exec
1 year 8 months ago
Also: Indian Hackers Gets 5 Years in Prison for Stealing $20M
Every week, ISMG rounds up cybersecurity incidents in digital assets. This week, the Nigerian government dropped charges on Binance executive Tigran Gambaryan, an Indian hacker faces five years in prison for stealing $20 million, a $4.5M Tapioca DAO exploit, Transak data breach.
Every week, ISMG rounds up cybersecurity incidents in digital assets. This week, the Nigerian government dropped charges on Binance executive Tigran Gambaryan, an Indian hacker faces five years in prison for stealing $20 million, a $4.5M Tapioca DAO exploit, Transak data breach.
Breach Roundup: CISA Proposes Security for Bulk Data Sales
1 year 8 months ago
Also: Payment Card Theft Trends, Internet Archive Update
This week, bulk data transfers to China, credit card theft, the Internet Archive still recovering and the Change Healthcare tally is now 100M. Ukraine fought phishers, civil society against the UN cybercrime treaty, TA866 and virtual hard drives spread malware. Google verified Sir Isaac Newton.
This week, bulk data transfers to China, credit card theft, the Internet Archive still recovering and the Change Healthcare tally is now 100M. Ukraine fought phishers, civil society against the UN cybercrime treaty, TA866 and virtual hard drives spread malware. Google verified Sir Isaac Newton.