Aggregator
Ireland's DPC Takes Twitter to Court Over AI User Data Concerns
1 year 10 months ago
The Irish data protection watchdog accuses X Corp’s European subsidiary of breaching GDPR with Grok AI training
UK IT provider faces $7.7 million fine for 2022 ransomware breach
1 year 10 months ago
The UK's Information Commissioner's Office (ICO) has announced a provisional decision to impose a fine of £6.09M ($7.74 million) on Advanced Computer Software Group Ltd (Advanced) for its failure to protect the personal information of tens of thousands when it was hit by ransomware in 2022. [...]
Bill Toulas
Chameleon Banking Trojan Makes a Comeback Cloaked as CRM App
1 year 10 months ago
The evolving malware is targeting hospitality and other B2C workers in Canada and Europe with capabilities that can evade Android 13 security restrictions.
Elizabeth Montalbano, Contributing Writer
CVE-2024-20451 | Cisco SPA300/SPA500 up to 7.6.2SR7 Web-based Management Interface buffer overflow (cisco-sa-spa-http-vulns-RJZmX2Xz)
1 year 10 months ago
A vulnerability was found in Cisco SPA300 and SPA500. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Web-based Management Interface. The manipulation leads to buffer overflow.
This vulnerability is known as CVE-2024-20451. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20454 | Cisco SPA300/SPA500 up to 7.6.2SR7 Web-based Management Interface buffer overflow (cisco-sa-spa-http-vulns-RJZmX2Xz)
1 year 10 months ago
A vulnerability was found in Cisco SPA300 and SPA500. It has been classified as very critical. Affected is an unknown function of the component Web-based Management Interface. The manipulation leads to buffer overflow.
This vulnerability is traded as CVE-2024-20454. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-7143 | Red Hat Ansible Automation Platform Role-Based Access Control add_roles_for_object_creator insecure inherited permissions
1 year 10 months ago
A vulnerability was found in Red Hat Ansible Automation Platform, Satellite and Update Infrastructure for Cloud Providers and classified as problematic. This issue affects the function add_roles_for_object_creator of the component Role-Based Access Control. The manipulation leads to insecure inherited permissions.
The identification of this vulnerability is CVE-2024-7143. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-20479 | Cisco Identity Services Engine up to 3.3.0 Web-based Management Interface cross site scripting (cisco-sa-ise-xss-V2bm9JCY)
1 year 10 months ago
A vulnerability has been found in Cisco Identity Services Engine and classified as problematic. This vulnerability affects unknown code of the component Web-based Management Interface. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-20479. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20450 | Cisco Small Business IP Phones up to 7.6.2SR7 Web-based Management Interface buffer overflow (cisco-sa-spa-http-vulns-RJZmX2Xz)
1 year 10 months ago
A vulnerability, which was classified as very critical, was found in Cisco Small Business IP Phones. This affects an unknown part of the component Web-based Management Interface. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2024-20450. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-7061 | Okta Verify 5.0.0/5.0.1 on Windows path traversal
1 year 10 months ago
A vulnerability, which was classified as critical, has been found in Okta Verify 5.0.0/5.0.1 on Windows. Affected by this issue is some unknown functionality. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2024-7061. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-20443 | Cisco ASA/Identity Services Engine Web-based Management Interface cross site scripting (cisco-sa-ise-xss-V2bm9JCY)
1 year 10 months ago
A vulnerability classified as problematic was found in Cisco ASA and Identity Services Engine. Affected by this vulnerability is an unknown functionality of the component Web-based Management Interface. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-20443. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42250 | Linux Kernel up to 6.9.9 cachefiles_req null pointer dereference
1 year 10 months ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.9.9. Affected is the function cachefiles_req. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2024-42250. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-42249 | Linux Kernel up to 6.9.9 spi_async information disclosure (8b9af6d67517/c86a918b1bdb)
1 year 10 months ago
A vulnerability was found in Linux Kernel up to 6.9.9. It has been rated as problematic. This issue affects the function spi_async. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2024-42249. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-41250 | Kashipara Responsive School Management System 3.2.0 Student Details /smsa/view_students.php access control
1 year 10 months ago
A vulnerability was found in Kashipara Responsive School Management System 3.2.0. It has been declared as critical. This vulnerability affects unknown code of the file /smsa/view_students.php of the component Student Details Handler. The manipulation leads to improper access controls.
This vulnerability was named CVE-2024-41250. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-41245 | Kashipara Responsive School Management System 3.2.0 Teacher Details /smsa/view_teachers.php access control
1 year 10 months ago
A vulnerability was found in Kashipara Responsive School Management System 3.2.0. It has been classified as critical. This affects an unknown part of the file /smsa/view_teachers.php of the component Teacher Details Handler. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2024-41245. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-41244 | Kashipara Responsive School Management System 3.2.0 Class Details /smsa/view_class.php access control
1 year 10 months ago
A vulnerability was found in Kashipara Responsive School Management System 3.2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /smsa/view_class.php of the component Class Details Handler. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2024-41244. The attack may be launched remotely. There is no exploit available.
vuldb.com
Randall Munroe’s XKCD ‘Matter’
1 year 10 months ago
via the comic & dry wit of Randall Munroe, creator of XKCD
The post Randall Munroe’s XKCD ‘Matter’ appeared first on Security Boulevard.
Marc Handelman
macOS Sequoia brings better Gatekeeper, stalkerware protections
1 year 10 months ago
Apple's macOS Sequoia, now in beta testing, will make it harder to bypass Gatekeeper warnings and add system alerts for potential stalkerware threats. [...]
Sergiu Gatlan
Тень Пекина над Манилой: что скрывается за фейковым видео с президентом Филиппин
1 year 10 months ago
Скандальный ролик появился за несколько часов до важного выступления политика.
CVE-2024-41308 | Enjay IT Solutions CRM OS 1.0 Ping sandbox
1 year 10 months ago
A vulnerability has been found in Enjay IT Solutions CRM OS 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Ping. The manipulation leads to sandbox issue.
This vulnerability is known as CVE-2024-41308. Access to the local network is required for this attack. There is no exploit available.
vuldb.com