Aggregator
Подрядчик подвел: «Ростелеком» расследует утечку данных
Vulnerability Archeology: Stealing Passwords with IBM i Access Client Solutions
CVE-2025-0614 | Qualifio Wheel of fortune path traversal
CVE-2024-37284 | Elastic Defend up to 8.13.2 on Windows exceptional condition
CVE-2024-43709 | Elasticsearch up to 7.17.20/8.13.2 allocation of resources
CVE-2024-52973 | Elastic Kibana up to 7.17.22/8.14.1 /api/log_entries/summary allocation of resources
Ransomware attackers are “vishing” organizations via Microsoft Teams
The “email bombing + posing as tech support via Microsoft Teams” combination is proving fruitful for two threat actors looking to deliver ransomware to organizations, and they seem to be ramping up their efforts. “Sophos MDR has observed more than 15 incidents involving these tactics in the past three months, with half of them in the past two weeks,” the company’s incident responders have warned today. The threat actors are social-engineering their way in To … More →
The post Ransomware attackers are “vishing” organizations via Microsoft Teams appeared first on Help Net Security.
AI Mistakes Are Very Different from Human Mistakes
Report riepilogativo sulle tendenze delle campagne malevole analizzate dal CERT-AGID nel 2024
CISA Releases Three Industrial Control Systems Advisories
CISA released three Industrial Control Systems (ICS) advisories on January 21, 2025. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
- ICSA-25-021-01 Traffic Alert and Collision Avoidance System (TCAS) II
- ICSA-25-021-02 Siemens SIMATIC S7-1200 CPUs
- ICSA-25-021-03 ZF Roll Stability Support Plus (RSSPlus)
CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.