Security Bulletin
26 Mar 2024
Biztonsági szemle
Rockwell Automation Arena Simulation
View CSAF 1. EXECUTIVE SUMMARY CVSS v3 7.8 ATTENTION: low attack complexity Vendor: Rockwell Automation Equipment: Arena Simulation Software Vulnerabilities: Out-of-bounds Write, Heap-based Buffer Overflow, Improper Restriction of Operations within...
26 Mar 2024
Biztonsági szemle
Automation-Direct C-MORE EA9 HMI
View CSAF 1. EXECUTIVE SUMMARY CVSS v3 7.5 ATTENTION: Exploitable remotely/low attack complexity Vendor: AutomationDirect Equipment: C-MORE EA9 HMI Vulnerabilities: Path Traversal, Stack-Based Buffer Overflow, Plaintext Storage of a Password 2. RISK...
26 Mar 2024
Biztonsági szemle
Three flaws added to CISA's known exploited vulnerabilities catalog
All of the vulnerabilities should be remediated by federal agencies by Apr. 15, according to CISA.
26 Mar 2024
Biztonsági szemle
EPA collaborating with state, local governments in boosting water cybersecurity
More details regarding state and local governments' vulnerability assessment measures have been sought by Deputy National Security Advisor for Cyber and Emerging Technologies.
26 Mar 2024
Biztonsági szemle
Reported HHS breach leading to theft of $7.5M under investigation
More details regarding the reported breach of the Department of Health and Human Services' Health Resources and Services Administration grant payments platform from March to November 2023 have been demanded.
26 Mar 2024
Biztonsági szemle
Outages at major UK tech trade union linked to cyberattack
Such impacted systems contained certain CWU member information but further investigation into a possible data breach is still needed.
26 Mar 2024
Biztonsági szemle
Ransomware hits Florida city
The City of St. Cloud in Florida have confirmed that the city's services have been disrupted by a ransomware attack.
26 Mar 2024
Biztonsági szemle
Malware, scams promoted by Google AI-powered search algorithms
Malicious websites redirecting to fraudulent giveaways, tech support scams, and spam subscriptions were discovered by search engine optimization expert Lily Ray and pushed by Google's newly launched artificial intelligence-based Search Generative...
26 Mar 2024
Biztonsági szemle
Raspberry Pi exploited by novel GEOBOX tool
Stealthier attacks have been facilitated by threat actors through the utilization of several strategically positioned internet-connected GEOBOX devices.
26 Mar 2024
Biztonsági szemle
New Tycoon 2FA PhaaS kit examined
Microsoft 365 and Gmail accounts have been increasingly targeted with attacks leveraging the new Tycoon 2FA phishing-as-a-service kit.
26 Mar 2024
Biztonsági szemle
Top.gg, others targeted by software supply chain attack
Top.gg GitHub organization, which is commonly leveraged for Discord servers, and other GitHub developers have been compromised in a new software supply chain attack campaign that involved browser cookie exfiltration and malicious PyPi package...
26 Mar 2024
Biztonsági szemle
Novel MuddyWater phishing campaign hits Israel
Attacks commenced with the delivery of malicious emails with PDF attachments linking to file-sharing site-hosted documents, which when opened fetches an MSI installer-containing ZIP archive that prompts Atera Agent installation.
Pagination
- Previous page ‹‹
- Page 925
- Next page ››