Aggregator
FBI, Pentagon warn of Iran hacking groups targeting operational technology
3 days 15 hours ago
The advisory said Iranian actors are targeting local municipal governments, water and wastewater systems and the energy sector.
Attackers exploit critical Flowise flaw CVE-2025-59528 for remote code execution
3 days 15 hours ago
Attackers are exploiting a critical Flowise flaw, tracked as CVE-2025-59528 (CVSS score of 10), that lets them run malicious code and access systems due to poor validation of user-supplied JavaScript. Attackers are actively exploiting a critical vulnerability in Flowise, tracked as CVE-2025-59528, that allows remote code execution and file system access. The flaw stems from improper validation […]
Pierluigi Paganini
Storm-1175 Deploys Medusa Ransomware at 'High Velocity'
3 days 15 hours ago
Microsoft says the financially motivated cybercrime group has exploited n-day and zero-day vulnerabilities in campaigns predicated on speed.
Rob Wright
Hackers Exploit Kubernetes Misconfigurations to Move From Containers to Cloud Accounts
3 days 15 hours ago
Kubernetes has become one of the most widely used platforms for managing containerized applications in enterprise environments. But as its adoption has grown, so has the attention it draws from malicious actors. Threat actors are now exploiting misconfigurations within Kubernetes clusters to break out of containers and move directly into the cloud accounts that host […]
The post Hackers Exploit Kubernetes Misconfigurations to Move From Containers to Cloud Accounts appeared first on Cyber Security News.
Tushar Subhra Dutta
Hitachi security advisory (AV26-321)
3 days 15 hours ago
Canadian Centre for Cyber Security
CVE-2024-44241 | Apple iOS/iPadOS up to 18.0 DCP Firmware memory corruption (WID-SEC-2024-3291)
3 days 15 hours ago
A vulnerability categorized as critical has been discovered in Apple iOS and iPadOS up to 18.0. This affects an unknown part of the component DCP Firmware Handler. Such manipulation leads to memory corruption.
This vulnerability is referenced as CVE-2024-44241. The attack needs to be initiated within the local network. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2024-44242 | Apple iOS/iPadOS up to 18.0 DCP Firmware memory corruption (WID-SEC-2024-3291)
3 days 15 hours ago
A vulnerability marked as critical has been reported in Apple iOS and iPadOS up to 18.0. Impacted is an unknown function of the component DCP Firmware Handler. The manipulation leads to memory corruption.
This vulnerability is listed as CVE-2024-44242. The attack must be carried out from within the local network. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2024-44212 | Apple iOS/iPadOS Cookie state issue (WID-SEC-2024-3291)
3 days 15 hours ago
A vulnerability marked as problematic has been reported in Apple iOS and iPadOS. This impacts an unknown function of the component Cookie Handler. Performing a manipulation results in state issue.
This vulnerability was named CVE-2024-44212. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2024-44246 | Apple macOS Private Relay information disclosure (WID-SEC-2024-3692)
3 days 15 hours ago
A vulnerability described as problematic has been identified in Apple macOS. Affected is an unknown function of the component Private Relay Handler. Executing a manipulation can lead to information disclosure.
The identification of this vulnerability is CVE-2024-44246. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2024-44246 | Apple iOS/iPadOS Private Relay information disclosure (WID-SEC-2024-3692)
3 days 15 hours ago
A vulnerability classified as problematic has been found in Apple iOS and iPadOS. Affected by this vulnerability is an unknown functionality of the component Private Relay Handler. The manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2024-44246. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-44224 | Apple macOS up to 13.6/14.6/15.1 permission (WID-SEC-2024-3692)
3 days 15 hours ago
A vulnerability was found in Apple macOS up to 13.6/14.6/15.1. It has been rated as critical. This vulnerability affects unknown code. The manipulation leads to permission issues.
This vulnerability is documented as CVE-2024-44224. The attack needs to be performed locally. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2024-44245 | Apple visionOS Kernel Memory memory corruption (WID-SEC-2024-3692)
3 days 15 hours ago
A vulnerability identified as critical has been detected in Apple visionOS. Impacted is an unknown function of the component Kernel Memory Handler. This manipulation causes memory corruption.
This vulnerability appears as CVE-2024-44245. The attack requires local access. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2024-44245 | Apple macOS Kernel Memory memory corruption (WID-SEC-2024-3692)
3 days 15 hours ago
A vulnerability labeled as critical has been found in Apple macOS. The affected element is an unknown function of the component Kernel Memory Handler. Such manipulation leads to memory corruption.
This vulnerability is traded as CVE-2024-44245. An attack has to be approached locally. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2024-44245 | Apple iOS/iPadOS Kernel Memory memory corruption (WID-SEC-2024-3692)
3 days 15 hours ago
A vulnerability marked as critical has been reported in Apple iOS and iPadOS. The impacted element is an unknown function of the component Kernel Memory Handler. Performing a manipulation results in memory corruption.
This vulnerability is known as CVE-2024-44245. Attacking locally is a requirement. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2024-44225 | Apple tvOS Local Privilege Escalation (WID-SEC-2024-3692)
3 days 15 hours ago
A vulnerability categorized as critical has been discovered in Apple tvOS. The impacted element is an unknown function. Such manipulation leads to Local Privilege Escalation.
This vulnerability is documented as CVE-2024-44225. The attack needs to be performed locally. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2024-44225 | Apple macOS Local Privilege Escalation (WID-SEC-2024-3692)
3 days 15 hours ago
A vulnerability identified as critical has been detected in Apple macOS. This affects an unknown function. Performing a manipulation results in Local Privilege Escalation.
This vulnerability is reported as CVE-2024-44225. The attack requires a local approach. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2024-44225 | Apple watchOS Local Privilege Escalation (WID-SEC-2024-3692)
3 days 15 hours ago
A vulnerability labeled as critical has been found in Apple watchOS. This impacts an unknown function. Executing a manipulation can lead to Local Privilege Escalation.
This vulnerability appears as CVE-2024-44225. The attack requires local access. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2024-44225 | Apple iOS/iPadOS Local Privilege Escalation (WID-SEC-2024-3692)
3 days 15 hours ago
A vulnerability marked as critical has been reported in Apple iOS and iPadOS. Affected is an unknown function. The manipulation leads to Local Privilege Escalation.
This vulnerability is traded as CVE-2024-44225. An attack has to be approached locally. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2024-44243 | Apple macOS up to 15.1 access control (Nessus ID 214661 / WID-SEC-2024-3692)
3 days 15 hours ago
A vulnerability, which was classified as critical, has been found in Apple macOS up to 15.1. This impacts an unknown function. This manipulation causes improper access controls.
This vulnerability is handled as CVE-2024-44243. It is possible to launch the attack on the local host. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com