Aggregator
CVE-2024-34336 | ORDAT FOSS-Online up to 2.24.00 Forgot Password information disclosure
CVE-2024-36066 | Keyfactor EJBCA up to 8.3.0 CMP CLI Client message integrity
CVE-2024-25270 | Mirapolis LMS 4.6.x ID/STEP resource injection
CVE-2024-8641 | GitLab Community Edition/Enterprise Edition up to 17.1.6/17.2.4/17.3.1 Session Token CI_JOB_TOKEN privilege context switching error (Issue 471954)
CVE-2024-8311 | GitLab Enterprise Edition up to 17.2.4/17.3.1 Pipeline Execution improper protection of alternate path (Issue 479315)
CVE-2024-6678 | GitLab Community Edition/Enterprise Edition up to 17.1.6/17.2.4/17.3.1 Pipeline authentication spoofing (Issue 471923)
CVE-2024-4472 | GitLab Community Edition/Enterprise Edition up to 17.1.6/17.2.4/17.3.1 graphql Log log file (Issue 460289)
CVE-2024-45182 | Wibu-Systems WibuKey up to 6.69 Packet WibuKey64.sys denial of service
CVE-2024-45181 | Wibu-Systems WibuKey up to 6.69 WibuKey64.sys memory corruption
CVE-2024-45383 | Microsoft High Definition Audio Bus Driver 10.0.19041.3636 IRP HDAudBus_DMA resource control (TALOS-2024-2008)
Разведка 21 века: как КНДР незаметно ведет кибервойну против всего мира
Navigating the Shared Responsibility Model: Lessons Learned from the Snowflake Cybersecurity Incident
Jerry Dawkins, PhD In the world of cybersecurity, the recent incident involving Snowflake has sparked a significant discussion around the shared responsibility between vendors and customers. The attacks, which targeted over 100 Snowflake customers, have highlighted vulnerabilities that arise not from the platform itself, but from how customers manage their security environments. A Bold Stance: […]
The post Navigating the Shared Responsibility Model: Lessons Learned from the Snowflake Cybersecurity Incident appeared first on CISO Global.
The post Navigating the Shared Responsibility Model: Lessons Learned from the Snowflake Cybersecurity Incident appeared first on Security Boulevard.
CVE-2014-6678 | wordbox Algeria Radio 2.5 X.509 Certificate cryptographic issues (VU#582497)
When Startup Founders Should Start Thinking About Cybersecurity
Meow
Meow
CVE-2014-6677 | Ticket Round Up 3.0.1 X.509 Certificate cryptographic issues (VU#143641)
USENIX Security ’23 – Downgrading DNSSEC: How to Exploit Crypto Agility for Hijacking Signed Zones
Authors/Presenters:Elias Heftrig, Haya Shulman, Michael Waidner
Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the organizations YouTube channel.
The post USENIX Security ’23 – Downgrading DNSSEC: How to Exploit Crypto Agility for Hijacking Signed Zones appeared first on Security Boulevard.