Aggregator
CVE-2023-4617 | Govee Home App up to 5.8 on Android HTTP POST Request device/sku/type authorization
CVE-2020-12820 | Fortinet FortiOS up to 5.6.12/6.0.10 SSL VPN stack-based overflow (FG-IR-20-083)
Crypto-Hackers Steal $2.2bn as North Koreans Dominate
The year in ransomware: Security lessons to help you stay one step ahead
CISA orders federal agencies to secure their Microsoft cloud environments
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a binding operational directive (BOD 25-01) requiring federal civilian agencies to secure their (Microsoft) cloud environments. About the CISA BOD 25-01 directive The Implementing Secure Practices for Cloud Services directive sets out three deadlines for the agencies: By February 21, 2025, they have to identify all cloud tenants within the scope of the directive and report to CISA. By April 25th, 2025, they must deploy … More →
The post CISA orders federal agencies to secure their Microsoft cloud environments appeared first on Help Net Security.
CISA Mandates Federal Agencies Secure Their Cloud Environments
APT73
SASE Market Hits $2.4 Billion, Top Vendors Tighten Market Share Grip
The key to growing a cybersecurity career are soft skills
Gorilla Tag: режим «бога» в VR-мире или билет в киберхаос
深入浅出API测试|搜集分析与漏洞挖掘实战
CVE-2024-35928 | Linux Kernel up to 6.1.85/6.6.26/6.8.5 AMD GPU amdgpu_device_init memory leak (Nessus ID 210815)
CVE-2024-36885 | Linux Kernel up to 6.6.30/6.8.9 nvkm_firmware_ctor state issue (1a88c18da464/e05af0093028/52a6947bf576)
CVE-2024-41024 | Linux Kernel up to 6.6.40/6.9.9 FastRPC root_pd Privilege Escalation (5e305b5986dc/c69fd8afaceb/bab2f5e8fd5d)
CVE-2024-43903 | Linux Kernel up to 6.1.104/6.6.45/6.10.4 AMD Display amdgpu_dm_plane_handle_cursor_update null pointer dereference
CVE-2024-12626 | AutomatorWP Plugin up to 5.0.9 on WordPress a-0-o-search_field_value cross site scripting
CVE-2024-45818 | Xen VGA deadlock (Nessus ID 210883)
CVE-2024-45819 | Xen libxl information disclosure (Nessus ID 210883)
Beware Of Malicious SharePoint Notifications That Delivers Xloader Malware
Through the use of XLoader and impersonating SharePoint notifications, researchers were able to identify a sophisticated malware delivery campaign. A link that was disguised as a legitimate SharePoint notification was included in the emails that were sent out at the beginning of the attack. The engine flagged the message as malicious based on several factors: […]
The post Beware Of Malicious SharePoint Notifications That Delivers Xloader Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.