Aggregator
Possible Russian Hackers Targeted UK Ministry of Defense
3 months 4 weeks ago
Spear-Phishing Campaign Used RomCom Malware Variant
A phishing campaign wielding malware previously associated with Russian-speaking hackers targeted the U.K. Ministry of Defense in late 2024. It is unclear if the campaign is tied to a data leak of 600 armed personnel, civil servants, and defense contractors reported late last year.
A phishing campaign wielding malware previously associated with Russian-speaking hackers targeted the U.K. Ministry of Defense in late 2024. It is unclear if the campaign is tied to a data leak of 600 armed personnel, civil servants, and defense contractors reported late last year.
RSAC Conference 2025 Aims to Accelerate Cyber Innovation
3 months 4 weeks ago
Event to Feature Innovation Sandbox 20-Year Anniversary, DARPA, Hacking Sessions
RSAC Conference brings together thousands of cybersecurity professionals with one goal: finding innovative ways to defend enterprises. This year for the event's annual Innovation Sandbox, the stakes couldn't be bigger. This year, leading-edge projects will receive $5 million in investment funding.
RSAC Conference brings together thousands of cybersecurity professionals with one goal: finding innovative ways to defend enterprises. This year for the event's annual Innovation Sandbox, the stakes couldn't be bigger. This year, leading-edge projects will receive $5 million in investment funding.
Ransomware Attack Disrupts Global Dialysis Provider DiVita
3 months 4 weeks ago
Company Files Report With SEC About Incident Discovered Over the Weekend
Denver-based DaVita Inc., which runs more than 3,100 dialysis and other kidney care facilities in the U.S. and in 13 other countries, reported to the U.S. Securities and Exchange Commission that a ransomware attack over the weekend is disrupting some of its operations.
Denver-based DaVita Inc., which runs more than 3,100 dialysis and other kidney care facilities in the U.S. and in 13 other countries, reported to the U.S. Securities and Exchange Commission that a ransomware attack over the weekend is disrupting some of its operations.
Fraud in Your Inbox: Email Is Still the Weakest Link
3 months 4 weeks ago
At-Bay Cyber Insurance Claims Report Finds 83% of Financial Fraud Starts With Email
Financial fraud remains the leading driver of cyberinsurance claims, with 83% of cases traced back to email-based attacks. Common tactics used to deceive employees include wiring funds to fraudulent accounts, generative AI-crafted emails, executive and vendor impersonation and BEC scams.
Financial fraud remains the leading driver of cyberinsurance claims, with 83% of cases traced back to email-based attacks. Common tactics used to deceive employees include wiring funds to fraudulent accounts, generative AI-crafted emails, executive and vendor impersonation and BEC scams.
Test SBX
3 months 4 weeks ago
The post Test SBX appeared first on Security Boulevard.
Greg Yarnold
CVE-2022-42898 | Samba up to 4.15.11/4.16.6/4.17.2 on 32-bit Kerberos Library/AD DC integer overflow (Nessus ID 207970)
3 months 4 weeks ago
A vulnerability was found in Samba up to 4.15.11/4.16.6/4.17.2 on 32-bit. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Kerberos Library/AD DC. The manipulation leads to integer overflow.
This vulnerability is known as CVE-2022-42898. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-45896 | Planet eStream improper authentication
3 months 4 weeks ago
A vulnerability, which was classified as critical, has been found in Planet eStream. This issue affects some unknown processing. The manipulation leads to improper authentication.
The identification of this vulnerability is CVE-2022-45896. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-45893 | Planet eStream user session
3 months 4 weeks ago
A vulnerability, which was classified as critical, was found in Planet eStream. Affected is an unknown function. The manipulation leads to manage user sessions.
This vulnerability is traded as CVE-2022-45893. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-45889 | Planet eStream sql injection
3 months 4 weeks ago
A vulnerability was found in Planet eStream and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2022-45889. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2022-45892 | Planet eStream cross site scripting
3 months 4 weeks ago
A vulnerability was found in Planet eStream. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2022-45892. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2022-45890 | Planet eStream cross site scripting
3 months 4 weeks ago
A vulnerability was found in Planet eStream. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2022-45890. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2022-45894 | Planet eStream URL Parameter path traversal
3 months 4 weeks ago
A vulnerability was found in Planet eStream. It has been rated as critical. This issue affects some unknown processing of the component URL Parameter Handler. The manipulation leads to path traversal: '..\filedir'.
The identification of this vulnerability is CVE-2022-45894. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2022-45895 | Planet eStream information disclosure
3 months 4 weeks ago
A vulnerability classified as problematic has been found in Planet eStream. Affected is an unknown function. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2022-45895. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2022-47949 | Nintendo NetworkBuffer UDP Packet buffer overflow
3 months 4 weeks ago
A vulnerability was found in Nintendo NetworkBuffer. It has been declared as critical. This vulnerability affects unknown code of the component UDP Packet Handler. The manipulation leads to buffer overflow.
This vulnerability was named CVE-2022-47949. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-42898 | Oracle Communications Cloud Native Core Security Edge Protection Proxy Installation/Configuration integer overflow (Nessus ID 207970)
3 months 4 weeks ago
A vulnerability was found in Oracle Communications Cloud Native Core Security Edge Protection Proxy 23.1.0/22.4.1. It has been rated as critical. This issue affects some unknown processing of the component Installation/Configuration. The manipulation leads to integer overflow.
The identification of this vulnerability is CVE-2022-42898. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2022-42898 | Oracle Healthcare Translational Research 4.1.0/4.1.1 DataStudio integer overflow (Nessus ID 207970)
3 months 4 weeks ago
A vulnerability has been found in Oracle Healthcare Translational Research 4.1.0/4.1.1 and classified as critical. This vulnerability affects unknown code of the component DataStudio. The manipulation leads to integer overflow.
This vulnerability was named CVE-2022-42898. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2022-42898 | Oracle Communications Cloud Native Core Binding Support Function Install/Upgrade integer overflow (Nessus ID 207970)
3 months 4 weeks ago
A vulnerability classified as critical was found in Oracle Communications Cloud Native Core Binding Support Function 22.4.0/23.1.0. This vulnerability affects unknown code of the component Install/Upgrade. The manipulation leads to integer overflow.
This vulnerability was named CVE-2022-42898. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2022-42898 | Oracle Communications Cloud Native Core Network Repository Function Linux integer overflow (Nessus ID 207970)
3 months 4 weeks ago
A vulnerability, which was classified as critical, has been found in Oracle Communications Cloud Native Core Network Repository Function 22.4.2/22.4.3. This issue affects some unknown processing of the component Linux. The manipulation leads to integer overflow.
The identification of this vulnerability is CVE-2022-42898. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2022-45197 | Slixmpp up to 1.8.2 XMLStream certificate validation (Nessus ID 211124)
3 months 4 weeks ago
A vulnerability was found in Slixmpp up to 1.8.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component XMLStream. The manipulation leads to certificate with host mismatch.
This vulnerability is handled as CVE-2022-45197. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com