Security Bulletin
8 Apr 2024
Biztonsági szemle
E-commerce site data compromised via critical Magento flaw
Attacks leveraging an already fixed critical Magento vulnerability, tracked as CVE-2024-20720, have been launched against e-commerce websites to facilitate the distribution of a Stripe payment skimmer for financial data exfiltration, according to The...
8 Apr 2024
Biztonsági szemle
Numerous Ivanti VPN gateways impacted by RCE vulnerability
BleepingComputer reports that attacks leveraging a recently patched high-severity heap overflow vulnerability, tracked as CVE-2024-21894, could impact nearly 16,500 internet-exposed Ivanti Connect Secure and Poly Secure VPN gateways.
8 Apr 2024
Biztonsági szemle
Over 92,000 D-Link NAS devices face compromise risk
More than 92,000 outdated internet-exposed D-Link Network Attached Storage devices could be breached in attacks exploiting a newly discovered arbitrary command injection and hardcoded backdoor vulnerability, tracked as CVE-2024-3273, which could...
8 Apr 2024
Biztonsági szemle
What security pros can learn about AI from the Russia-Ukraine war
Here are four insights into how security pros can judge new AI products when vendors say they were “battle-tested in Ukraine.”
8 Apr 2024
Biztonsági szemle
Toward greater transparency: Adopting the CWE standard for Microsoft CVEs
At the Microsoft Security Response Center (MSRC), our mission is to protect our customers, communities, and Microsoft from current and emerging threats to security and privacy. One way we achieve this is by determining the root cause of security...
5 Apr 2024
Biztonsági szemle
Bing ad posing as NordVPN aims to spread SecTopRAT malware
The remote access trojan creates a second hidden desktop to control the victim’s browser.
5 Apr 2024
Biztonsági szemle
'Hugging Face' AI models, customer data at risk to cross-tenant attacks
New joint research by Wiz and AI-as-a-service provider Hugging Face find that a malicious pickle-serialized model could contain a remote execution payload.
5 Apr 2024
Biztonsági szemle
SEXi, Powerhost, Acuity, Layerslider, JSOutProx, Byakugan, Josh Marpet, and More - SWN #375
5 Apr 2024
Biztonsági szemle
Omni Hotels blames cyberattack for widespread tech outages
The North American accommodation group is still investigating the impact of the Easter weekend disruptions.
5 Apr 2024
Biztonsági szemle
Cloud security: Challenges and best practices
Security practitioners share what they've learned in the push for better cloud security.
5 Apr 2024
Biztonsági szemle
AI expected to bolster corporate cybersecurity
Artificial intelligence is believed by 63% of IT and security professionals to be beneficial to their organizations' security posture, ZDNET reports.
5 Apr 2024
Biztonsági szemle
Potentially significant risk of novel DoS attack technique examined
Threat actors could leverage the novel HTTP/2 Continuation Flood denial-of-service attack technique to facilitate DDoS attacks more severe than record-breaking intrusions enabled by the Rapid Reset approach last year, according to SecurityWeek.
Pagination
- Previous page ‹‹
- Page 677
- Next page ››