Aggregator
Cybersecurity Compass: An Integrated Cyber Defense Strategy
5 months 4 weeks ago
Explore how the Cybersecurity Compass can guide various security professionals' and stakeholders' decision-making before, during, and after a breach.
Juan Pablo Castro
Attacks on Bytecode Interpreters Conceal Malicious Injection Activity
5 months 4 weeks ago
By injecting malicious bytecode into interpreters for VBScript, Python, and Lua, researchers found they can circumvent malicious code detection.
Robert Lemos, Contributing Writer
More Legal Records Stolen in 2023 Than Previous 5 Years Combined
5 months 4 weeks ago
Law firms make the perfect target for extortion, so it's no wonder that ransomware attackers target them and demand multimillion dollar ransoms.
Nate Nelson, Contributing Writer
'Sitting Ducks' Attacks Create Hijacking Threat for Domain Name Owners
5 months 4 weeks ago
Researchers say the attacks are easy to perform, difficult to contact, nearly unrecognizable, and "entirely preventable."
Dark Reading Staff
Twilio kills off Authy for desktop, forcibly logs out all users
5 months 4 weeks ago
Twilio has finally killed off its Authy for Desktop application, forcibly logging users out of the desktop application. [...]
Lawrence Abrams
Protect your mini-me—How to prevent child identity theft
5 months 4 weeks ago
Most parents work hard thinking about their little one’s future ahead—imagining it bright and full of possibilities, while doing all they can to protect it. But there may be identity thieves snooping around, looking to target your child and mess with that future before they even know what a credit score is.
The post Protect your mini-me—How to prevent child identity theft appeared first on Security Boulevard.
Avast Blog
CVE-2024-7029 | AVTECH AVM1203 up to FullImg-1023-1007-1011-1009 command injection (icsa-24-214-07)
5 months 4 weeks ago
A vulnerability classified as very critical was found in AVTECH AVM1203 up to FullImg-1023-1007-1011-1009. This vulnerability affects unknown code. The manipulation leads to command injection.
This vulnerability was named CVE-2024-7029. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-4353 | Concrete CMS up to 9.3.2 Generate Dashboard Board Name cross site scripting
5 months 4 weeks ago
A vulnerability classified as problematic has been found in Concrete CMS up to 9.3.2. This affects an unknown part of the component Generate Dashboard Board. The manipulation of the argument Name leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-4353. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-41259 | Navidrome 0.52.3 Gravatar Service weak hash
5 months 4 weeks ago
A vulnerability was found in Navidrome 0.52.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Gravatar Service. The manipulation leads to use of weak hash.
This vulnerability is handled as CVE-2024-41259. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-7211 | 1E Platform 8.4.1.229/23.7.1.80/23.11.1.15/24.7 redirect
5 months 4 weeks ago
A vulnerability was found in 1E Platform 8.4.1.229/23.7.1.80/23.11.1.15/24.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to open redirect.
This vulnerability is known as CVE-2024-7211. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-41260 | netbird 0.28.4 Initialization encrypt predictable state
5 months 4 weeks ago
A vulnerability was found in netbird 0.28.4. It has been classified as problematic. Affected is the function encrypt of the component Initialization Handler. The manipulation leads to predictable from observable state.
This vulnerability is traded as CVE-2024-41260. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-39633 | IdeaBox PowerPack for Beaver Builder Plugin up to 2.33.0 on WordPress privileges management
5 months 4 weeks ago
A vulnerability was found in IdeaBox PowerPack for Beaver Builder Plugin up to 2.33.0 on WordPress and classified as critical. This issue affects some unknown processing. The manipulation leads to improper privilege management.
The identification of this vulnerability is CVE-2024-39633. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-6040 | parisneo lollms-webui up to 9.8 lollms_binding_infos client_id cross-site request forgery
5 months 4 weeks ago
A vulnerability has been found in parisneo lollms-webui up to 9.8 and classified as problematic. This vulnerability affects the function lollms_binding_infos. The manipulation of the argument client_id leads to cross-site request forgery.
This vulnerability was named CVE-2024-6040. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-41264 | Casdoor 1.636.0 ssh.InsecureIgnoreHostKey information disclosure
5 months 4 weeks ago
A vulnerability, which was classified as problematic, was found in Casdoor 1.636.0. This affects the function ssh.InsecureIgnoreHostKey. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-41264. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-41265 | Cortex 0.42.1 TLS Certificate Verification makeOperatorRequest information disclosure
5 months 4 weeks ago
A vulnerability, which was classified as problematic, has been found in Cortex 0.42.1. Affected by this issue is the function makeOperatorRequest of the component TLS Certificate Verification. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-41265. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-41962 | Yonle bostr up to 3.0.9 authorized_keys improper authorization (GHSA-5cf7-cxrf-mq73)
5 months 4 weeks ago
A vulnerability classified as critical was found in Yonle bostr up to 3.0.9. Affected by this vulnerability is an unknown functionality. The manipulation of the argument authorized_keys leads to improper authorization.
This vulnerability is known as CVE-2024-41962. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23600 | Ping Identity OPENIDM up to 7.5.0 Query Search Result information disclosure
5 months 4 weeks ago
A vulnerability classified as problematic has been found in Ping Identity OPENIDM up to 7.5.0. Affected is an unknown function of the component Query Search Result Handler. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2024-23600. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6242 | Rockwell Automation ControlLogix 5580 1756-L8z Trusted Slot unprotected alternate channel
5 months 4 weeks ago
A vulnerability was found in Rockwell Automation ControlLogix 5580 1756-L8z, GuardLogix 5580 1756-L8zS, 1756-EN4TR, 1756-EN2T, 1756-EN2F, 1756-EN2TR, 1756-EN3TR and 1756-EN2TP. It has been rated as critical. This issue affects some unknown processing of the component Trusted Slot. The manipulation leads to unprotected alternate channel.
The identification of this vulnerability is CVE-2024-6242. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-41961 | sapcc elektra Live Search code injection (GHSA-6j2h-486h-487q)
5 months 4 weeks ago
A vulnerability was found in sapcc elektra. It has been declared as critical. This vulnerability affects unknown code of the component Live Search. The manipulation leads to code injection.
This vulnerability was named CVE-2024-41961. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com