Security Bulletin

8 Aug 2024
Biztonsági szemle
Severe Roundcube, RaspAP vulnerabilities examined
Included in the severe Roundcube vulnerabilities were the cross-site scripting issues, tracked as CVE-2024-42008 and CVE-2024-42009, as well as the information disclosure bug, tracked as CVE-2024-42010, an analysis from Sonar revealed.

8 Aug 2024
Biztonsági szemle
Ronin Network breached via bridge flaw, $12M in withdrawn funds returned
Ronin Network attributed the flaw to a recent bridge update that resulted in the misinterpretation of the fund withdrawal authorization threshold for bridge operators.

8 Aug 2024
Biztonsági szemle
INC Ransom attack disrupts McLaren Health Care
McLaren Bay Region Hospital employees showed an INC Ransom note threatening the exposure of stolen data on the ransomware operation's leak site should the health system fail to pay the demanded ransom.

8 Aug 2024
Biztonsági szemle
Feds: BlackSuit's ransomware demands exceed $500M
While most ransoms sought by BlackSuit ranged from about $1 million to $10 million worth of Bitcoin, the ransomware gang has demanded payments of up to $60 million, according to an updated joint advisory from the FBI and Cybersecurity and...

8 Aug 2024
Biztonsági szemle
Critical AWS Vulnerabilities Allow S3 Attack Bonanza
Researchers at Aqua Security discovered the "Shadow Resource" attack vector and the "Bucket Monopoly" problem, where threat actors can guess the name of S3 buckets based on their public account IDs.
8 Aug 2024
Biztonsági szemle
Dorsett Controls InfoScan
View CSAF 1. EXECUTIVE SUMMARY CVSS v4 6.9 ATTENTION: Exploitable remotely/low attack complexity Vendor: Dorsett Controls Equipment: InfoScan Vulnerabilities: Exposure of Sensitive Information To An Unauthorized Actor, Path Traversal 2. RISK...
8 Aug 2024
Biztonsági szemle
CISA Releases One Industrial Control Systems Advisory
CISA released one Industrial Control Systems (ICS) advisory on August 8, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-221-01 Dorsett Controls InfoScan CISA...
8 Aug 2024
Biztonsági szemle
Best Practices for Cisco Device Configuration
In recent incidents, CISA has seen malicious cyber actors acquire system configuration files by leveraging available protocols or software on devices, such as abusing the legacy Cisco Smart Install feature. CISA recommends organizations disable Smart...

8 Aug 2024
Biztonsági szemle
ISC Stormcast For Thursday, August 8th, 2024 https://isc.sans.edu/podcastdetail/9088, (Thu, Aug 8th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

8 Aug 2024
Biztonsági szemle
Ransomware gangs: How low will they go?
Ransomware operators are increasingly turning to new, and in some cases extremely concerning, tactics to extort payments from victims.

8 Aug 2024
Biztonsági szemle
Amid the glitter of Las Vegas, don’t forget the cybersecurity basics
The latest AI-enabled tools are enticing, but don’t lose focus on what’s really important as the show continues on.

8 Aug 2024
Biztonsági szemle
Black Hat USA: Wi-Fi tracking flaw puts the ‘BS’ in BSSID
Geolocation services for a number of popular mobile hardware vendors can be used to perform widescale Wi-Fi network monitoring.
Pagination
- Previous page ‹‹
- Page 598
- Next page ››