Aggregator
AppsFlyer SDK Exploited in New Supply Chain Crypto Attack
Between March 9 and March 11, 2026, attackers had a 48-hour window inside one of the most widely embedded JavaScript libraries on the internet. The […]
The post AppsFlyer SDK Exploited in New Supply Chain Crypto Attack appeared first on Reflectiz.
The post AppsFlyer SDK Exploited in New Supply Chain Crypto Attack appeared first on Security Boulevard.
CVE-2024-21607 | Juniper Junos OS on MX/EX9200 UI unsupported feature in ui (JSA75748 / Nessus ID 305081)
CVE-2026-34379 | AcademySoftwareFoundation OpenEXR up to 3.2.6/3.3.8/3.4.8 EXR File Parser internal_dwa_decoder.h LossyDctDecoder_execute type conversion (GHSA-w88v-vqhq-5p24 / Nessus ID 305083)
CVE-2026-21767 | HCL BigFix Platform missing authentication (KB0129906 / WID-SEC-2026-0960)
CVE-2026-5318 | LibRaw up to 0.22.0 JPEG DHT Parser losslessjpeg.cpp HuffTable::initval bits[] out-of-bounds write (Issue 794 / EUVD-2026-18116)
CVE-2026-1243 | IBM Content Navigator up to 3.0.15/3.1.0/3.2.0 Web UI cross site scripting (EUVD-2026-18112 / CNNVD-202604-467)
CVE-2026-21765 | HCL BigFix Platform File System permission assignment (KB0129906 / WID-SEC-2026-0960)
Рост атак в 37 раз. Как работает EvilTokens и почему антивирусы его пропускают
CVE-2024-44282 | Apple watchOS User Information out-of-bounds (Nessus ID 211697 / WID-SEC-2024-3291)
CVE-2024-44294 | Apple macOS up to 13.6/14.6 System Files denial of service (Nessus ID 211697 / WID-SEC-2024-3291)
CVE-2024-44296 | Apple visionOS protection mechanism (Nessus ID 210137 / WID-SEC-2024-3291)
CVE-2024-44287 | Apple macOS up to 13.6/14.6 access control (Nessus ID 211697 / WID-SEC-2024-3291)
CVE-2024-44285 | Apple visionOS Kernel Memory use after free (Nessus ID 211696 / WID-SEC-2024-3291)
CVE-2024-44285 | Apple tvOS Kernel Memory use after free (Nessus ID 211696 / WID-SEC-2024-3291)
CVE-2024-44285 | Apple watchOS Kernel Memory use after free (Nessus ID 211696 / WID-SEC-2024-3291)
CVE-2024-44285 | Apple iOS/iPadOS Kernel Memory use after free (Nessus ID 211696 / WID-SEC-2024-3291)
CVE-2024-44284 | Apple macOS up to 13.6/14.6 File out-of-bounds write (Nessus ID 211697 / WID-SEC-2024-3291)
CVE-2024-44289 | Apple macOS up to 13.6/14.6 information disclosure (Nessus ID 211697 / WID-SEC-2024-3291)
The case for fixing CWE weakness patterns instead of patching one bug at a time
In this Help Net Security interview, Alec Summers, MITRE CVE/CWE Project Lead, discusses how CWE is moving from a background reference into active use in vulnerability disclosure. More CVE records now include CWE mappings from CNAs, which tends to produce more precise root-cause data. Automation tools help analysts map weaknesses faster, but can reinforce bad patterns if trained on poor examples. Summers argues that fixing weakness patterns reduces recurring work for security teams, even those … More →
The post The case for fixing CWE weakness patterns instead of patching one bug at a time appeared first on Help Net Security.