Security Bulletin

11 Jul 2024
Biztonsági szemle
Centralized Cyber-Incident Reporting Can Improve Effectiveness
Companies need robust cyber-response plans and a straightforward path to transparency.

11 Jul 2024
Biztonsági szemle
Mandatory MFA option unveiled by Snowflake
While the new policy could be adopted based on Snowflake customers' preferences, OAuth and other key-pair authentication systems are still recommended for service users.

11 Jul 2024
Biztonsági szemle
Microsoft chided for spam-looking APT29 hack notifications
Organizations affected by the breach have been urged by security researcher and former Microsoft employee Kevin Beaumont to be vigilant of the emails, which were not sent in adherence to the Microsoft 365 breach process.

11 Jul 2024
Biztonsági szemle
Unauthorized content alteration bug found in NSA platform
Attackers could exploit the flaw, which stemmed from inadequate CSRF protections primarily in SkillTree endpoints for state-changing operations, to spread misinformation and prompt training disruptions.

11 Jul 2024
Biztonsági szemle
Severe vulnerabilities addressed by GitLab, others
GitLab has issued a fix for the critical flaw in GitLab Community Edition and Enterprise Edition software, tracked as CVE-2024-6385, which could be leveraged for arbitrary pipeline job execution.

11 Jul 2024
Biztonsági szemle
Nearly 39M legal records leaked by misconfigured database
Further investigation of the leaked 38 TB dataset revealed links to another storage repository with 89,475 records belonging to backend technology provider Legal Connect, which shares the same parent firm as Rapid Legal.

11 Jul 2024
Biztonsági szemle
ViperSoftX infostealer evolves with improved obfuscation
Fraudulent JPG files have also been leveraged by ViperSoftX to deploy AutoIT scripts and the AutoIT executable, along with PowerShell scripts.

11 Jul 2024
Biztonsági szemle
Microsoft, Nokia employee data exposed
Data from 2,047 Microsoft employees has been exposed, including full names, job titles, direct and corporate phone numbers, email addresses, LinkedIn profile links, city, state, and country addresses, and company phone numbers.

11 Jul 2024
Biztonsági szemle
Kimsuky sets sights on Japanese organizations
Attacks by Kimsuky commenced with the distribution of Japanese security and diplomatic organization-spoofing phishing emails with a malicious ZIP file.

11 Jul 2024
Biztonsági szemle
Attacks leveraging Veeam backup software flaw launched by novel ransomware gang
Newly emergent EstateRansomware ransomware group has deployed intrusions leveraging the already addressed high-severity Veeam Backup & Replication software flaw, tracked as CVE-2023-27532.
11 Jul 2024
Biztonsági szemle
HMS Industrial Networks Anybus-CompactCom 30
View CSAF 1. EXECUTIVE SUMMARY CVSS v4 6.3 ATTENTION: Exploitable remotely/low attack complexity Vendor: HMS Industrial Networks Equipment: Anybus-CompactCom 30 Vulnerability: Cross-site Scripting 2. RISK EVALUATION Successful exploitation of this...
11 Jul 2024
Biztonsági szemle
Siemens Teamcenter Visualization and JT2Go
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT...
Pagination
- Previous page ‹‹
- Page 658
- Next page ››