Aggregator
South Korea fined Meta $15.67M for illegally collecting and sharing Facebook users
1 year 8 months ago
South Korea fined Meta $15.67M for illegally collecting and sharing Facebook users’ sensitive data, including political views and sexual orientation, with advertisers. South Korea’s data privacy watchdog, Personal Information Protection Commission (PIPC), fined Meta 21.62 billion won ($15.67 million) for illegally collecting sensitive personal information from Facebook users, including data about their political views and […]
Pierluigi Paganini
CVE-2024-10028 | Everest Backup Plugin up to 2.2.13 on WordPress procstat Log information disclosure
1 year 8 months ago
A vulnerability, which was classified as problematic, has been found in Everest Backup Plugin up to 2.2.13 on WordPress. Affected by this issue is some unknown functionality of the component procstat Log. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-10028. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-10647 | WS Form Lite Plugin up to 1.9.244 on WordPress URL cross site scripting
1 year 8 months ago
A vulnerability, which was classified as problematic, was found in WS Form Lite Plugin up to 1.9.244 on WordPress. This affects an unknown part of the component URL Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-10647. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-34676 | Samsung Mobile Devices subtitle File Parser libsubextractor.so heap-based overflow
1 year 8 months ago
A vulnerability, which was classified as critical, has been found in Samsung Mobile Devices. This issue affects some unknown processing of the file libsubextractor.so of the component subtitle File Parser. The manipulation leads to heap-based buffer overflow.
The identification of this vulnerability is CVE-2024-34676. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-34673 | Samsung Mobile Devices Modem IpcProtocol denial of service
1 year 8 months ago
A vulnerability was found in Samsung Mobile Devices. It has been declared as problematic. This vulnerability affects the function IpcProtocol of the component Modem. The manipulation leads to denial of service.
This vulnerability was named CVE-2024-34673. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-34674 | Samsung Mobile Devices Contacts access control
1 year 8 months ago
A vulnerability classified as problematic was found in Samsung Mobile Devices. Affected by this vulnerability is an unknown functionality of the component Contacts. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2024-34674. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-34675 | Samsung Mobile Devices Dex Mode access control
1 year 8 months ago
A vulnerability, which was classified as problematic, has been found in Samsung Mobile Devices. Affected by this issue is some unknown functionality of the component Dex Mode. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2024-34675. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-34677 | Samsung Mobile Devices System UI information disclosure
1 year 8 months ago
A vulnerability, which was classified as problematic, was found in Samsung Mobile Devices. This affects an unknown part of the component System UI. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-34677. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-34678 | Samsung Mobile Devices libsapeextractor.so out-of-bounds write
1 year 8 months ago
A vulnerability has been found in Samsung Mobile Devices and classified as critical. This vulnerability affects unknown code in the library libsapeextractor.so. The manipulation leads to out-of-bounds write.
This vulnerability was named CVE-2024-34678. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-34679 | Samsung Mobile Devices Crane default permission
1 year 8 months ago
A vulnerability was found in Samsung Mobile Devices and classified as problematic. This issue affects some unknown processing of the component Crane. The manipulation leads to incorrect default permissions.
The identification of this vulnerability is CVE-2024-34679. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-34680 | Samsung Mobile Devices WlanTest implicit intent
1 year 8 months ago
A vulnerability was found in Samsung Mobile Devices. It has been classified as problematic. Affected is an unknown function of the component WlanTest. The manipulation leads to use of implicit intent for sensitive communication.
This vulnerability is traded as CVE-2024-34680. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
С 32% до 50%: каждый второй киберинцидент нарушает бизнес-процессы в 2024 году
1 year 8 months ago
В 39% случаев эксперты обнаружили следы активности 17 известных APT-группировок.
От Сингапура до США: Китай тестирует силы перед глобальной кибератакой
1 year 8 months ago
Сингапурский телеком стал тестовой площадкой для подготовки взлома критической инфраструктуры.
警告:LastPass 提醒用户注意在 Chrome Web Store 上使用虚假支持评论的网络钓鱼诈骗
1 year 8 months ago
安全客
CVE-2016-1828 | Apple Mac OS X up to 10.11.4 Kernel memory corruption (HT206567 / EDB-44239)
1 year 8 months ago
A vulnerability was found in Apple Mac OS X up to 10.11.4 and classified as critical. This issue affects some unknown processing of the component Kernel. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2016-1828. Local access is required to approach this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Darknet User Claims Access to Major Telecom Companies in Multiple Countries
1 year 8 months ago
cohenido
Bengal cat lovers in Australia get psspsspss’d in Google-driven Gootloader campaign
1 year 8 months ago
The Internet is full of cats—and in this case, malware-delivering fake cat websites used for very targeted search engine optimization.
gallagherseanm
9 Steps to Get CTEM on Your 2025 Budgetary Radar
1 year 8 months ago
Budget season is upon us, and everyone in your organization is vying for their slice of the pie. Every year, every department has a pet project that they present as absolutely essential to profitability, business continuity, and quite possibly the future of humanity itself. And no doubt that some of these actually may be mission critical. But as cybersecurity professionals, we understand that
The Hacker News
勒索组织要求法国施耐德公司用法棍支付赎金
1 year 8 months ago
法国施耐德电气公司证实正在调查一起网络安全事件,而勒索组织 Hellcat 宣称它窃取了逾 40 GB 的压缩数据,要求该公司以法棍支付 12.5 万美元赎金,否则其敏感的客户和运营信息将被泄露。施耐德拒绝置评与法棍或加密货币支付赎金的相关报道,只声明其产品和服务未受影响。Hellcat 组织称它是通过施耐德的 Atlassian Jira 系统访问了其基础设施。这是施耐德电气在不到两年时间内第三次遭到入侵。