During the Summer of 2024, several internet service providers (ISPs) & managed service providers (MSPs) were the target of a zero-day vulnerability being used by Volt Typhoon.
The China-linked threat actor known as Earth Estries has been observed using a previously undocumented backdoor called GHOSTSPIDER as part of its attacks targeting Southeast Asian telecommunications companies.
Trend Micro, which described the hacking group as an aggressive advanced persistent threat (APT), said the intrusions also involved the use of another cross-platform backdoor dubbed
Banshee Stealer, a MacOS Malware-as-a-Service, shut down after its source code leaked online. The code is now available on GitHub. In August 2024, Russian hackers promoted BANSHEE Stealer, a macOS malware targeting x86_64 and ARM64, capable of stealing browser data, crypto wallets, and more. BANSHEE Stealer supports basic evasion techniques, relies on the sysctl API […]
A vulnerability, which was classified as very critical, has been found in ProjectSend up to r1719. Affected by this issue is some unknown functionality of the file options.php of the component HTTP Request Handler. The manipulation leads to improper authentication.
This vulnerability is handled as CVE-2024-11680. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Oracle Enterprise Manager Ops Center 12.4.0.0. Affected by this issue is some unknown functionality of the component Satellite Framework. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2020-1971. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Oracle API Gateway 11.1.2.4.0. Affected by this issue is some unknown functionality of the component Oracle API Gateway. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2020-1971. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Oracle Business Intelligence Enterprise Edition 5.5.0.0.0/12.2.1.3.0/12.2.1.4.0. This affects an unknown part of the component BI Platform Security. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2020-1971. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Oracle JD Edwards EnterpriseOne Tools up to 9.2.5.2. It has been declared as critical. This vulnerability affects unknown code of the component OneWorld Tools Security. The manipulation leads to denial of service.
This vulnerability was named CVE-2020-1971. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Oracle JD Edwards World Security A9.4. It has been rated as critical. This issue affects some unknown processing of the component World Software Security. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2020-1971. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Oracle Communications Session Border Controller Cz8.2/Cz8.3/Cz8.4. This vulnerability affects unknown code of the component Routing. The manipulation leads to denial of service.
This vulnerability was named CVE-2020-1971. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in OpenSSL up to 1.0.2w/1.1.1h. It has been rated as problematic. Affected by this issue is the function GENERAL_NAME_cmp of the component x509 Certificate Handler. The manipulation leads to null pointer dereference.
This vulnerability is handled as CVE-2020-1971. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Oracle Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers. It has been classified as critical. Affected is an unknown function of the component XCP Firmware. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2021-23840. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Oracle MySQL Workbench up to 8.0.22. It has been rated as critical. Affected by this issue is some unknown functionality of the component MySQL Workbench. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2020-1971. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.