Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 3 / 4
75 résultats taggé securityweek  ✕
Windows Update Flaws Allow Undetectable Downgrade Attacks https://www.securityweek.com/safebreach-sounds-alarm-on-windows-update-flaws-allowing-undetectable-downgrade-attacks/
08/08/2024 10:07:49
QRCode
archive.org

Researcher showcases hack against Microsoft Windows Update architecture, turning fixed vulnerabilities into zero-days.

securityweek EN 2024 Microsoft Windows Update Downgrade
Acronis Product Vulnerability Exploited in the Wild https://www.securityweek.com/acronis-product-vulnerability-exploited-in-the-wild/
03/08/2024 21:10:03
QRCode
archive.org

Cybersecurity and data protection technology company Acronis last week warned that threat actors are exploiting a critical-severity vulnerability patched nine months ago.

Tracked as CVE-2023-45249 (CVSS score of 9.8), the security defect impacts Acronis Cyber Infrastructure (ACI) and allows threat actors to execute arbitrary code remotely due to the use of default passwords.

securityweek EN 2024 acronis CVE-2023-45249 ACI Exploited
Apple Rolls Out Security Updates for iOS, macOS https://www.securityweek.com/apple-rolls-out-security-updates-for-ios-macos
03/08/2024 21:08:56
QRCode
archive.org

Apple on Monday announced a hefty round of security updates that address dozens of vulnerabilities impacting both newer and older iOS and macOS devices.

iOS 17.6 and iPadOS 17.6 were released for the latest generation iPhone and iPad devices with fixes for 35 security defects that could lead to authentication and policy bypasses, unexpected application termination or system shutdown, information disclosure, denial-of-service (DoS), and memory leaks.

securityweek EN 2024 macos ios ipados Security Updates for iOS iOS17.6
Recent Zyxel NAS Vulnerability Exploited by Botnet https://www.securityweek.com/recent-zyxel-nas-vulnerability-exploited-by-botnet/
25/06/2024 15:25:56
QRCode
archive.org

A recently disclosed critical-severity vulnerability in discontinued Zyxel NAS devices is already exploited in botnet attacks, the Shadowserver Foundation warns.

Tracked as CVE-2024-29973, the issue is described as a code injection flaw that can be exploited remotely without authentication. It was introduced last year, when Zyxel patched CVE-2023-27992, a similar code injection bug.

“While patching this vulnerability, they added a new endpoint which uses the same approach as the old ones, and while doing so, implemented the same mistakes as its predecessors,” explains Outpost24 security researcher Timothy Hjort, who discovered and reported the security defect.

securityweek EN 2024 Mirai-like CVE-2024-29973 Zyxel
Apple Patches Vision Pro Vulnerability Used in Possibly ‘First Ever Spatial Computing Hack’ https://www.securityweek.com/apple-patches-vision-pro-vulnerability-used-in-first-ever-spatial-computing-hack/
13/06/2024 16:32:27
QRCode
archive.org

Apple on Monday updated visionOS, the operating system powering its Vision Pro virtual reality headset, to version 1.2, which addresses several vulnerabilities, including what may be the first security flaw that is specific to this product.

visionOS 1.2 patches nearly two dozen vulnerabilities. However, a vast majority of them are in components that visionOS shares with other Apple products, such as iOS, macOS and tvOS.

securityweek EN 2024 CVE-2024-27812 CVE-2024-27812 visionOS Apple Spatial Computing Hack
NIST Getting Outside Help for National Vulnerability Database https://www.securityweek.com/nist-getting-outside-help-for-national-vulnerability-database/
01/06/2024 14:04:01
QRCode
archive.org

NIST announced on Wednesday that it will be receiving outside help to get the National Vulnerability Database (NVD) back on track within the next few months.

The organization informed the cybersecurity community in February that it should expect delays in the analysis of Common Vulnerabilities and Exposures (CVE) identifiers in the NVD, saying that it was working to establish a consortium to improve the program.

securityweek EN 2024 NIST CVE National Vulnerability Database NVD
The UK Says a Huge Payroll Data Breach by a ‘Malign Actor’ Has Exposed Details of Military Personnel https://www.securityweek.com/the-uk-says-a-huge-payroll-data-breach-by-a-malign-actor-has-exposed-details-of-military-personnel/
12/05/2024 13:06:58
QRCode
archive.org

The UK Ministry of Defense said a breach at a third-party payroll system exposed as many as 272,000 armed forces personnel and veterans.

securityweek EN 2024 UK Defense Payroll military data-breach veterans
Siemens Industrial Product Impacted by Exploited Palo Alto Firewall Vulnerability https://www.securityweek.com/siemens-industrial-product-impacted-by-exploited-palo-alto-firewall-vulnerability/
23/04/2024 13:06:28
QRCode
archive.org

The recently disclosed Palo Alto Networks firewall vulnerability tracked as CVE-2024-3400, which has been exploited in attacks for at least one month, has been found to impact one of Siemens’ industrial products.

In an advisory published late last week, Siemens revealed that its Ruggedcom APE1808 devices configured with a Palo Alto Networks virtual next-generation firewall (NGFW) could be affected by CVE-2024-3400.

securityweek EN 2024 CVE-2024-3400 Palo Alto Networks firewall Siemens IoT
Thousands of Ivanti VPN Appliances Impacted by Recent Vulnerability https://www.securityweek.com/thousands-of-ivanti-vpn-appliances-impacted-by-recent-vulnerability/
14/04/2024 15:35:21
QRCode
archive.org

The Shadowserver Foundation identifies thousands of Ivanti VPN instances likely impacted by a recent remote code execution flaw.

securityweek EN 2024 Shadowserver Ivanti VPN CVE-2024-21894 vulnerable
Security Flaw in WP-Members Plugin Leads to Script Injection https://www.securityweek.com/security-flaw-in-wp-members-plugin-leads-to-script-injection/
04/04/2024 19:04:25
QRCode
archive.org

Attackers could exploit a high-severity cross-site Scripting (XSS) vulnerability in the WP-Members Membership WordPress plugin to inject arbitrary scripts into web pages, according to an advisory from security firm Defiant.

securityweek EN 2024 plugin WP Wordpress WP-Members Injection vulnerability
Details and Lessons Learned From the Ransomware Attack on the British Library https://www.securityweek.com/details-and-lessons-learned-from-the-ransomware-attack-on-the-british-library/
30/03/2024 17:24:12
QRCode
archive.org

The British Library has shared details on the destructive ransomware attack it experienced in October 2023. Although the attack on the national library of the UK occurred five months ago, the Library’s infrastructure won’t be rebuilt until mid-April 2024, and then the full restoration of systems and data can begin.

securityweek EN 2024 lesson-learned British-Library UK
Google Paid Out $10 Million via Bug Bounty Programs in 2023 https://www.securityweek.com/google-paid-out-10-million-via-bug-bounty-programs-in-2023
17/03/2024 16:58:48
QRCode
archive.org

Google on Tuesday announced that it paid out a total of $10 million through its bug bounty programs in 2023, bringing the total amount awarded by the tech giant for vulnerabilities found in its products since 2010 to $59 million.

The total paid out in 2023 is less than the $12 million handed out in 2022, but it’s still a significant amount. The money was earned last year by 632 researchers from 68 countries. The highest single reward was $113,337.

securityweek EN 2024 Google bugbounty 2023 paid
Kubernetes Vulnerability Allows Remote Code Execution on Windows Endpoints https://www.securityweek.com/kubernetes-vulnerability-allows-remote-code-execution-on-windows-endpoints/
14/03/2024 11:45:58
QRCode
archive.org

The exploitation of a high-severity Kubernetes vulnerability can lead to arbitrary code execution with System privileges on all Windows endpoints in a cluster, Akamai warns.

The issue, tracked as CVE-2023-5528 and impacting default Kubernetes installations, exists in the way the open source container orchestration system processes YAML files, which it uses for virtually every function.

In some regards, the vulnerability is like CVE-2023-3676, a lack of sanitization in the subPath parameter in YAML files leading to code injection when creating pods with volumes.

securityweek EN 2024 Kubernetes cmd Windows CVE-2023-5528
LoanDepot Ransomware Attack Exposed 16.9 Million Individuals - SecurityWeek https://www.securityweek.com/loandepot-ransomware-attack-exposed-16-9-million-individuals/
03/03/2024 20:17:39
QRCode
archive.org

Lending firm LoanDepot said the personal information of 16.9 million individuals was stolen in a ransomware attack in early January 2024.

securityweek EN 2024 LoanDepot ransomware attack data-breach
QNAP Patches High-Severity Flaws in QTS, Video Station, QuMagie, Netatalk Products https://www.securityweek.com/qnap-patches-high-severity-flaws-in-qts-video-station-qumagie-netatalk-products/
15/01/2024 07:21:09
QRCode
archive.org

QNAP has released patches for a dozen vulnerabilities in its products, including several high-severity flaws.

securityweek EN 2023 QNAP vulnerabilities High-Severity
Inmate, Staff Information Stolen in Rhode Island Prison Data Breach https://www.securityweek.com/inmate-staff-information-stolen-in-rhode-island-prison-data-breach/
23/12/2023 12:28:32
QRCode
archive.org

he Donald W. Wyatt Detention Facility says the data of 2,000 inmates, staff, and vendors was stolen in a cyberattack.

securityweek EN 2023 Data-Breach Detention Facility US Inmate Staff Rhode-Island Prison
Sophos has patched EOL Firewall versions against a critical flaw exploited in the wild, after identifying a new exploit. https://www.securityweek.com/sophos-patches-eol-firewalls-against-exploited-vulnerability/?is=e4f6b16c6de31130985364bb824bcb39ef6b2c4e902e4e553f0ec11bdbefc118
18/12/2023 11:24:18
QRCode
archive.org

UK-based cybersecurity firm Sophos this week announced patches for an exploited vulnerability in Firewall versions that have reached End-of-Life (EOL).

The critical-severity flaw, tracked as CVE-2022-3236, was found to impact versions 19.0 MR1 (19.0.1) and older of the product. It was originally patched in September 2022, but only in supported versions of Sophos Firewall.

Sophos describes the security defect as a code injection issue in the Firewall’s User Portal and Webadmin components, allowing attackers to achieve remote code execution (RCE).

securityweek EN 2023 Sophos CVE-2022-3236 critical-severity EOL Firewall patch
SysAid Zero-Day Vulnerability Exploited by Ransomware Group https://www.securityweek.com/sysaid-zero-day-vulnerability-exploited-by-ransomware-group/
09/11/2023 10:56:04
QRCode
archive.org
thumbnail

CVE-2023-47246, a zero-day vulnerability in SysAid IT service management software has been exploited by Cl0p ransomware affiliates.

securityweek EN 2023 SysAid CVE-2023-47246 0-day
New Supermicro BMC Vulnerabilities Could Expose Many Servers to Remote Attacks https://www.securityweek.com/new-supermicro-bmc-vulnerabilities-could-expose-many-servers-to-remote-attacks/
05/10/2023 12:47:44
QRCode
archive.org
thumbnail

Supermicro has released BMC IPMI firmware updates to address multiple vulnerabilities impacting select motherboard models.

securityweek EN 2023 BMC Supermicro CVE-2023-40284 CVE-2023-40290
New GPU Side-Channel Attack Allows Malicious Websites to Steal Data https://www.securityweek.com/new-gpu-side-channel-attack-allows-malicious-websites-to-steal-data/
27/09/2023 19:25:15
QRCode
archive.org
thumbnail

GPUs from AMD, Apple, Arm, Intel, Nvidia and Qualcomm are vulnerable to a new type of side-channel attack named GPU.zip.

securityweek EN 2023 GPU.zip Side-Channel Attack
page 3 / 4
4649 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio