A vulnerability has been found in German National Identity Card up to 2024-02-15 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Online-Ausweis-Funktion eID Scheme Handler. The manipulation leads to authentication bypass by spoofing.
This vulnerability is known as CVE-2024-23674. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in Linux Kernel up to 5.15.133/6.1.55/6.5.5. It has been rated as problematic. Affected by this issue is some unknown functionality of the component sun6i. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2023-52511. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in Google Android. This affects an unknown part of the component ACPM. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-22006. The attack can only be done within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as problematic was found in Elspec G5 Digital Fault Recorder up to 1.1.4.15. Affected by this vulnerability is an unknown functionality of the component shadow File. The manipulation leads to incorrect default permissions.
This vulnerability is known as CVE-2024-22085. The attack can only be done within the local network. There is no exploit available.
A vulnerability was found in Linux Kernel up to 5.10.209/5.15.148/6.1.75/6.6.14/6.7.2. It has been classified as critical. Affected is the function __dma_async_device_channel_register of the component dmaengine. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2023-52492. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
Omdia Principal Analyst Hollie Hennessy says that until a promising new set of regulations around the world comes online, connected device security entails a shared responsibility among consumers, enterprises, and manufacturers.
Cisco has fixed a maximum severity vulnerability that allows attackers to run commands with root privileges on vulnerable Ultra-Reliable Wireless Backhaul (URWB) access points that provide connectivity for industrial wireless automation. [...]
A vulnerability, which was classified as critical, was found in Apple iOS up to 9.3.1. Affected is an unknown function of the component Kernel. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2016-1831. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
Security Professionals Must Continually Hone Technical and Communication Skills In cybersecurity, there's no such thing as "done learning." The field's dynamic nature - driven by rapid technological advances and evolving threats - demands that professionals stay adaptable and proactive. It's essential for staying relevant, effective and prepared for what's next.
Burning Issues Include Russian Hacking, China's Hitting Critical Infrastructure Four years since Trump's last term, the cyber picture looks - in many ways - markedly different. How will the incoming administration tackle Russian disinformation and cyber operations against NATO, rampant Chinese cyber espionage, and cybercriminals and ransomware continuing to disrupt businesses?
CyberEspionage 'Salt Typhoon' Operation Infiltrated Telcos' Infrastructure The impact of a major U.S. national security breach attributed to China reportedly continues to expand, as investigators probe the infiltration of telecommunications infrastructure and eavesdropping on national security and policymaking officials' mobile phone communications.
Former President’s Win Could Bring Major Changes to U.S. Cyber Policy, Experts Say Republican Donald Trump's return to the White House in January could bring significant changes to technology and cybersecurity policy in the United States, potentially reshaping federal approaches to AI regulation, industry investment and national security against rising digital threats.