Aggregator
CVE-2018-25372 | Softneta MedDream PACS Server Premium 6.7.1.1 POST userSignup.php email sql injection (Exploit 45344 / EUVD-2018-21895)
Cisco refines its risk-based vulnerability disclosure for the AI era
Security teams already struggle with long lists of vulnerabilities and limited time to patch them. Cisco believes AI could increase that pressure by accelerating vulnerability discovery and increasing the number of findings security teams need to review. The company said it is moving further toward a risk-based disclosure approach, placing greater attention on issues under active exploitation or those considered more likely to be used in attacks. “Cisco is actively leveraging advanced AI Models to … More →
The post Cisco refines its risk-based vulnerability disclosure for the AI era appeared first on Help Net Security.
Mexican University UT Sierra Hidalguense Named in Alleged Student Database Leak
CVE-2018-25368 | NordVPN up to 6.14.31 Password memory allocation (Exploit 45304 / EUVD-2018-21891)
CVE-2018-25359 | Splinterware System Scheduler Pro 5.12 WService.exe default permission (Exploit 45072 / EUVD-2018-21881)
CVE-2018-25366 | Globalscape CuteFTP 5.0.4 buffer overflow (Exploit 45259 / EUVD-2018-21889)
CVE-2018-25360 | Agatasoft Auto PingMaster 1.5 stack-based overflow (Exploit 45151 / EUVD-2018-21884)
Submit #813927: TOTOLink CA750-PoE V6.2c.510 Command Injection [Accepted]
Submit #813926: TOTOLink CA750-PoE V6.2c.510 Command Injection [Accepted]
Submit #813924: TOTOLink CA750-PoE V6.2c.510 Command Injection [Accepted]
Submit #813923: TOTOLink CA750-PoE V6.2c.510 Command Injection [Accepted]
Submit #813922: TOTOLink CA750-PoE V6.2c.510 Command Injection [Accepted]
25th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 25th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES 7-Eleven, the global convenience store chain, confirmed a breach after an unauthorized access to systems used for franchisee documents. ShinyHunters claimed responsibility and said it stole more than 600,000 Salesforce records containing personal […]
The post 25th May – Threat Intelligence Report appeared first on Check Point Research.