Aggregator
Palo Alto Networks, Zscaler and PagerDuty Hit in Salesforce Linked Data Breaches
CVE-2024-42067 | Linux Kernel up to 6.6.36/6.6.37/6.9.7 bpf set_memory_rox return value (Nessus ID 210060 / WID-SEC-2024-1722)
CVE-2024-42065 | Linux Kernel up to 6.9.7 xe xe_ttm_stolen_mgr_init null pointer dereference (cc796a77985d/a6eff8f9c7e8 / Nessus ID 210060)
CVE-2024-42064 | Linux Kernel up to 6.9.7 AMD Display denial of service (27df59c60714/af114efe8d24 / Nessus ID 210060)
CVE-2024-42066 | Linux Kernel up to 6.9.7 xe integer overflow (79d54ddf0e29/4f4fcafde343 / Nessus ID 210060)
CVE-2024-42063 | Linux Kernel up to 6.1.96/6.6.36/6.9.7 kernel/bpf/devmap.c kmsan_unpoison_memory initialization (Nessus ID 210060 / WID-SEC-2024-1722)
CVE-2024-41098 | Linux Kernel up to 6.6.36/6.9.7 libata-core ata_port_alloc null pointer dereference (119c97ace2a9/8a8ff7e3b736/5d92c7c566dc / Nessus ID 208099)
Zscaler, Palo Alto Networks, SpyCloud among the affected by Salesloft Drift breach
In the wake of last week’s revelation of a breach at Salesloft by a group tracked by Google as UNC6395, several companies – including Zscaler, Palo Alto Networks, PagerDuty, Tanium, and SpyCloud – have confirmed their Salesforce instances were accessed. The companies noted that attackers had only limited access to Salesforce databases, not to other systems or resources. They warned, however, that the stolen customer data could be used for convincing phishing and social engineering … More →
The post Zscaler, Palo Alto Networks, SpyCloud among the affected by Salesloft Drift breach appeared first on Help Net Security.
唯有热爱,可抵岁月漫长
Azure AD Credentials Exposed in Public App Settings File
AI Governance and Risk in Securing Software Supply Chains
Artificial intelligence (AI) is rapidly transforming software development, accelerating innovation, streamlining processes, and opening the door to entirely new capabilities.
The post AI Governance and Risk in Securing Software Supply Chains appeared first on Security Boulevard.