An Iranian state hacking group is using custom malware to compromise IoT and OT infrastructure in Israel and the United States. An attack wave from Islamic Revolutionary Guard Corps-affiliated "CyberAv3ngers" swept up fuel management systems made by U.S.-based firm Gilbarco Veeder-Root.
IT Outage, Downtime Procedures Affecting Services at California Healthcare Provider Cybercriminals claim they stole 17 million patient records from a southern California regional healthcare provider that is still struggling with IT and phone systems outages that have been disrupting patient care since the organization was hit by a ransomware attack on Dec. 1.
Also: How Leading Cybersecurity Firms Are Gearing Up for 2025 In the latest weekly update, ISMG editors discussed the shooting death of the UnitedHealthcare CEO and its wider implications for AI-driven decision-making, market strategies for the top cybersecurity companies in 2025, and how these strategies reflect industry trends.
Around 30,000 German IoT Devices Infected From Backdoored Android Applications The German federal information security agency disrupted a botnet that infected thousands of backdoored digital picture frames and media players made with knockoff Android operating systems shipped from China. The agency identified at least 30,000 infected devices.
A vulnerability was found in GNU Binutils 2.34/2.35/2.36/2.37/2.38. It has been rated as problematic. Affected by this issue is the function stab_demangle_v3_arg of the file stabs.c. The manipulation leads to memory leak.
This vulnerability is handled as CVE-2022-47007. Access to the local network is required for this attack. There is no exploit available.
A vulnerability classified as problematic was found in Linux Kernel up to 5.10.227/5.15.168/6.1.113/6.6.57/6.11.4. This vulnerability affects the function pc_clock_settime of the component posix-clock. The manipulation leads to improper check for unusual conditions.
This vulnerability was named CVE-2024-50195. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in wolfSSL up to 5.6.4 and classified as problematic. This vulnerability affects unknown code of the component TLS Record Handler. The manipulation leads to information disclosure.
This vulnerability was named CVE-2023-6937. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in wolfSSL up to 5.6.4. Affected by this vulnerability is an unknown functionality of the component RSA. The manipulation leads to information exposure through discrepancy.
This vulnerability is known as CVE-2023-6935. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in Linux Kernel up to 5.15.169/6.1.114/6.6.58/6.11.5. It has been classified as critical. This affects the function smb2_set_next_command of the file mount.cifs. The manipulation leads to permission issues.
This vulnerability is uniquely identified as CVE-2024-50151. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in Linux Kernel up to 5.15.167/6.1.112/6.6.56/6.11.3. This vulnerability affects the function kthread_bind of the file kernel/kthread.c. The manipulation leads to state issue.
This vulnerability was named CVE-2024-50019. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.11.2. It has been declared as critical. Affected by this vulnerability is the function ext4_split_extent_at. The manipulation leads to use after free.
This vulnerability is known as CVE-2024-49884. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 5.15.167/6.1.112/6.6.53/6.10.12/6.11.1. Affected by this issue is the function nid_of_current of the component sgx. The manipulation leads to deadlock.
This vulnerability is handled as CVE-2024-49856. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.11.4. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component entry_32. The manipulation leads to buffer overflow.
This vulnerability is known as CVE-2024-50193. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.1.114/6.6.58/6.11.5. It has been rated as problematic. Affected by this issue is some unknown functionality of the file drivers/firmware/efi/runtime-wrappers.c of the component PRM Handler. The manipulation leads to allocation of resources.
This vulnerability is handled as CVE-2024-50141. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 6.11.1. This vulnerability affects the function e_value_offs of the component ext4. The manipulation leads to use after free.
This vulnerability was named CVE-2024-47701. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.