Security Bulletin
22 Aug 2024
Biztonsági szemle
Widespread WordPress site compromise likely with critical LiteSpeed Cache bug
Exploitation of the flaw, which was addressed last week, through a brute-force attack iterating and passing all known possible security hash values in the litespeed_hash cookie could facilitate immediate site access through any user ID provided that...
22 Aug 2024
Biztonsági szemle
Cryptomining aimed by new PostgreSQL database-targeting malware
Intrusions commence with brute-force attempts to guess the PostgreSQL database's credentials, which when achieved would be followed by the establishment of a superuser role that would ensure database access even after modifications to the original...
22 Aug 2024
Biztonsági szemle
Novel MoonPeak RAT leveraged by North Korean hackers
UAT-5394 — which has been suspected to be Kimsuky, its subgroup, or a separate operation leveraging Kimsuky's toolkit — established updated test virtual machines, payload-hosting sites, and command-and-control servers to support the creation of new...
22 Aug 2024
Biztonsági szemle
Rockwell Automation 5015 - AENFTXT
View CSAF 1. EXECUTIVE SUMMARY CVSS v4 8.7 ATTENTION: Exploitable remotely/low attack complexity Vendor: Rockwell Automation Equipment: 5015 - AENFTXT Vulnerability: Improper Input Validation 2. RISK EVALUATION Successful exploitation of this...
22 Aug 2024
Biztonsági szemle
CISA Releases Five Industrial Control Systems Advisories
CISA released five Industrial Control Systems (ICS) advisories on August 22, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-235-01 Rockwell Automation Emulate3D...
22 Aug 2024
Biztonsági szemle
MOBOTIX P3 and Mx6 Cameras
View CSAF 1. EXECUTIVE SUMMARY CVSS v4 8.7 ATTENTION: Exploitable remotely/low attack complexity Vendor: MOBOTIX Equipment: P3 Cameras, Mx6 Cameras Vulnerability: Improper Neutralization of Expression/Command Delimiters 2. RISK EVALUATION Successful...
22 Aug 2024
Biztonsági szemle
Rockwell Automation Emulate3D
View CSAF 1. EXECUTIVE SUMMARY CVSS v4 5.4 ATTENTION: Exploitable locally Vendor: Rockwell Automation Equipment: Emulate3D Vulnerability: Externally Controlled Reference to a Resource in Another Sphere 2. RISK EVALUATION Successful exploitation of...
22 Aug 2024
Biztonsági szemle
Avtec Outpost 0810
View CSAF 1. EXECUTIVE SUMMARY CVSS v4 8.7 ATTENTION: Exploitable remotely/low attack complexity Vendor: Avtec Equipment: Outpost 0810, Outpost Uploader Utility Vulnerability: Storage of File with Sensitive Data Under Web Root, Use of Hard-coded...
22 Aug 2024
Biztonsági szemle
When it comes to hiring remote IT workers: Caveat emptor
There’s so much pressure to hire good IT workers that it’s no wonder some of the best companies get caught by fraudsters.
22 Aug 2024
Biztonsági szemle
ISC Stormcast For Thursday, August 22nd, 2024 https://isc.sans.edu/podcastdetail/9108, (Thu, Aug 22nd)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
22 Aug 2024
Biztonsági szemle
Chinese Threat Actors Use MSI Files to Bypass Windows, VT Detection
Analysts have been picking up increased cases of malware delivery via Windows Installer files in Southeast Asia.
22 Aug 2024
Biztonsági szemle
The Silver Bullet of MFA Was Never Enough
There is no such thing as a silver bullet in cybersecurity. No, not even multifactor authentication.
Pagination
- Previous page ‹‹
- Page 650
- Next page ››