Cybercriminal Gang 'Money Message' Claims Credit, Publishes Stolen Records A Massachusetts hospital is notifying 316,000 people that their information was compromised in a cyberattack discovered nearly a year ago during Christmas 2023. Cybercriminal group Money Message claimed that it stole 600 gigabytes data, posting patient and employee records on the darkweb.
Flaw in Embedded Device Operating System Allowed Hackers to Bypass Integrity Check A critical flaw in the updating service of a popular Linux operating system for embedded devices could enable hackers to compromise firmware with malicious images. OpenWrt developers patched the vulnerability, tracked as CVE-2024-54143, with a CVSS score of 9.3.
deviceTRUST, Strong Network Acquisitions Improve Zero Trust, Developer Protections Citrix enhances its security for hybrid work by acquiring deviceTRUST and Strong Network. Purchasing these European startups boosts protection for VDI, DaaS and cloud development, empowering organizations to enforce zero trust principles and reduce risks across their hybrid environments.
Report: Financial Orgs Shift to Multi-Cloud to Address Cyber Threats and Regulation Financial institutions are increasingly adopting multi-cloud strategies to mitigate rising cyber risks and comply with complex regulations, according to a new report. The move enhances flexibility and disaster recovery, though challenges remain, from implementation costs to a growing skills gap.
A vulnerability classified as problematic has been found in Linux Kernel up to 5.15.133/6.1.55/6.5.5 on CPU. Affected is the function arm_smmu_mm_arch_invalidate_secondary_tlbs of the component arm-smmu-v3. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2023-52484. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 4.19.190/5.4.118/5.10.36/5.11.20/5.12.3. It has been classified as critical. Affected is the function regmap_debugfs_exit of the component regmap. The manipulation of the argument debugfs_name leads to memory leak.
This vulnerability is traded as CVE-2021-47058. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in Linux Kernel up to 5.4.118/5.10.36/5.11.20/5.12.3. This affects the function rtw_get_tx_power_params of the file /home/finger/wireless-drivers-next/drivers/net/wireless/realtek/rtw88/phy.c of the component rtw88. The manipulation leads to improper validation of array index.
This vulnerability is uniquely identified as CVE-2021-47065. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 5.12.3. This issue affects the function for_each_available_child_of_node of the component qcom. The manipulation leads to infinite loop.
The identification of this vulnerability is CVE-2021-47054. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 5.10.36/5.11.20/5.12.3 on Tegra30 and classified as critical. This vulnerability affects unknown code of the component tegra. The manipulation leads to denial of service.
This vulnerability was named CVE-2021-47067. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 5.12.3 and classified as critical. Affected by this issue is the function llcp_sock_connect of the component nfc. The manipulation leads to use after free.
This vulnerability is handled as CVE-2021-47068. The attack can only be initiated within the local network. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in SourceCodester Petrol Pump Management Software 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/app/product.php. The manipulation of the argument photo leads to unrestricted upload.
This vulnerability is known as CVE-2024-2058. The attack can be launched remotely. Furthermore, there is an exploit available.
A vulnerability has been found in Dogtag PKI and classified as critical. This vulnerability affects unknown code of the component XML Document Parser. The manipulation leads to xml external entity reference.
This vulnerability was named CVE-2022-2414. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in Microsoft SharePoint. It has been classified as problematic. Affected is an unknown function. The manipulation leads to xml external entity reference.
This vulnerability is traded as CVE-2024-49064. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.