Aggregator
Swap EOL Zyxel routers, upgrade Netgear ones!
There will be no patches for EOL Zyxel routers under attack via CVE-2024-40891, the company has confirmed. Meanwhile, Netgear has issued patches for critical flaws affecting its routers and wireless access points. Zyxel vulnerability: Exploited, no patches CVE-2024-40891, a command injection vulnerability in Zyxel CPE Series telecommunications devices that has been known since July 2024 and is currently being exploited by attackers, will not be patched by the manufacturer since the affected devices “are legacy … More →
The post Swap EOL Zyxel routers, upgrade Netgear ones! appeared first on Help Net Security.
CVE-2024-2352 | 1Panel up to 1.10.1-lts swap baseApi.UpdateDeviceSwap Path command injection (ID 4131)
CVE-2024-38411 | Qualcomm Snapdragon Auto up to WSA8845H use after free
CVE-2024-38416 | Qualcomm Snapdragon Auto up to XR2 5G Platform buffer over-read
CVE-2024-38404 | Qualcomm Snapdragon Auto up to X75 5G Modem-RF System Modem buffer over-read
CVE-2024-38414 | Qualcomm Snapdragon Auto up to WSA8835 Firmware Image buffer over-read
CVE-2024-38413 | Qualcomm Snapdragon Auto up to WSA8845H Frame Packet memory corruption
CVE-2024-38412 | Qualcomm Snapdragon Auto up to WSA8845H IOCTL Call use after free
CVE-2024-38417 | Qualcomm Snapdragon Auto up to X75 5G Modem-RF System IO Control Command buffer over-read
CVE-2024-38418 | Qualcomm Snapdragon Auto up to XR2 5G Platform IOCTL Call toctou
CVE-2024-38420 | Qualcomm Snapdragon Auto up to XR2 5G Platform Hypervisor memory corruption
Multiple IBM Cloud Pak Vulnerabilities Let Attackers Execute Remote Code
IBM has released critical security updates addressing multiple vulnerabilities in its Cloud Pak for Business Automation software. These vulnerabilities, if exploited, could allow attackers to access sensitive data, disrupt operations, or compromise system integrity. The fixes are part of the latest interim fixes (iFixes) for versions 21.0.3 and 24.0.0. The vulnerabilities affect several components within […]
The post Multiple IBM Cloud Pak Vulnerabilities Let Attackers Execute Remote Code appeared first on Cyber Security News.
Future-Proofing Cybersecurity: The Competitive Advantage of Packet-Level Visibility
Preventing account takeover on centralized cryptocurrency exchanges in 2025
By Kelly Kaoudis and Evan Sultanik This blog post highlights key points from our new white paper Preventing Account Takeovers on Centralized Cryptocurrency Exchanges, which documents ATO-related attack vectors and defenses tailored to CEXes. Imagine trying to log in to your centralized cryptocurrency exchange (CEX) account and your password and username just… don’t work. You […]
The post Preventing account takeover on centralized cryptocurrency exchanges in 2025 appeared first on Security Boulevard.
Mobile Indian Cyber Heist: FatBoyPanel And His Massive Data Breach
Our zLabs research team has discovered a mobile malware campaign consisting of almost 900 malware samples primarily targeting users of Indian banks.
The post Mobile Indian Cyber Heist: FatBoyPanel And His Massive Data Breach appeared first on Zimperium.
The post Mobile Indian Cyber Heist: FatBoyPanel And His Massive Data Breach appeared first on Security Boulevard.