Aggregator
Breach Roundup: Mexico in Hacker Spotlight
11 months 1 week ago
Also: Critical WHOIS Vulnerability Exposes Internet Security Flaw in .mobi Domains
This week, cyberthreats rising in Mexico; FBI warned of BEC scams; U.K. police arrested hacking suspect; Avis, Slim CD, Medicare and Fortinet disclosed breaches; Highline public schools reopened after cyberattack; a critical flaw was found in WHOIS; and Konni upped attacks on Russia, South Korea.
This week, cyberthreats rising in Mexico; FBI warned of BEC scams; U.K. police arrested hacking suspect; Avis, Slim CD, Medicare and Fortinet disclosed breaches; Highline public schools reopened after cyberattack; a critical flaw was found in WHOIS; and Konni upped attacks on Russia, South Korea.
UK Labels Data Centers as Critical National Infrastructure
11 months 1 week ago
British Government Says Data Centers Are 'Essential for Functioning of Society'
The U.K. government on Thursday designated data centers as part of its critical national infrastructure in a move intended to prevent the loss of sensitive user data during disruptive cyberattacks. A newly announced data center security team will monitor and anticipate potential cyberthreats.
The U.K. government on Thursday designated data centers as part of its critical national infrastructure in a move intended to prevent the loss of sensitive user data during disruptive cyberattacks. A newly announced data center security team will monitor and anticipate potential cyberthreats.
GPS Modernization Stalls as Pentagon Faces Chip Shortages
11 months 1 week ago
New Report Warns of Continued Delays and Deficiencies in Federal GPS Modernization
The Space Force is suffering from years of delays, setbacks and shortcomings in its Global Positioning System modernization program, according to a Government Accountability Office report, which found major deficiencies and testing issues that could hinder the United States competitiveness in space.
The Space Force is suffering from years of delays, setbacks and shortcomings in its Global Positioning System modernization program, according to a Government Accountability Office report, which found major deficiencies and testing issues that could hinder the United States competitiveness in space.
Kernel Mode Under the Microscope at Windows Security Summit
11 months 1 week ago
Company Focused on Safe Deployment Practices, Reducing Kernel Mode Dependencies
Cutting kernel mode dependencies and adopting safe deployment practices will make endpoint systems more resilient and secure for Windows customers. Tuesday's meeting came two months after a faulty CrowdStrike update disrupted 8.5 million Windows machines and caused $5.4 billion in direct losses.
Cutting kernel mode dependencies and adopting safe deployment practices will make endpoint systems more resilient and secure for Windows customers. Tuesday's meeting came two months after a faulty CrowdStrike update disrupted 8.5 million Windows machines and caused $5.4 billion in direct losses.
CVE-2024-29015 | Intel VTune Profiler software 2023.0/2024.0 uncontrolled search path (intel-sa-01122)
11 months 1 week ago
A vulnerability, which was classified as critical, has been found in Intel VTune Profiler software 2023.0/2024.0. This issue affects some unknown processing. The manipulation leads to uncontrolled search path.
The identification of this vulnerability is CVE-2024-29015. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-39283 | Intel TDX Module Software prior 1.5.01.00.592 incomplete filtering of special elements (intel-sa-01010)
11 months 1 week ago
A vulnerability was found in Intel TDX Module Software and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to incomplete filtering of special elements.
This vulnerability is handled as CVE-2024-39283. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-34163 | Intel NUC input validation (intel-sa-01022)
11 months 1 week ago
A vulnerability was found in Intel NUC and classified as critical. This issue affects some unknown processing. The manipulation leads to improper input validation.
The identification of this vulnerability is CVE-2024-34163. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2023-4027 | Radio Player Plugin up to 2.0.73 on WordPress Setting authorization
11 months 1 week ago
A vulnerability, which was classified as problematic, was found in Radio Player Plugin up to 2.0.73 on WordPress. This affects an unknown part of the component Setting Handler. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2023-4027. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-43826 | Linux Kernel up to 6.10.2 nfs_folio_length denial of service (387e6e9d1102/fada32ed6dbc)
11 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.10.2. It has been declared as critical. This vulnerability affects the function nfs_folio_length. The manipulation leads to denial of service.
This vulnerability was named CVE-2024-43826. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-52907 | Linux Kernel up to 6.1.6 mm/kasan/shadow.c pn533_usb_send_frame use after free
11 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.1.6. It has been declared as critical. This vulnerability affects the function pn533_usb_send_frame of the file mm/kasan/shadow.c. The manipulation leads to use after free.
This vulnerability was named CVE-2023-52907. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43138 | MagePeople Team Event Manager for WooCommerce Plugin up to 4.2.1 on WordPress path traversal
11 months 1 week ago
A vulnerability, which was classified as critical, was found in MagePeople Team Event Manager for WooCommerce Plugin up to 4.2.1 on WordPress. This affects an unknown part. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2024-43138. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-36446 | Mitel MiVoice MX-ONE up to 7.6 SP1 access control
11 months 1 week ago
A vulnerability, which was classified as critical, has been found in Mitel MiVoice MX-ONE up to 7.6 SP1. Affected by this issue is some unknown functionality. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2024-36446. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-23497 | Intel Ethernet Network Controllers and Adapters 4.4 on Linux Kernel Mode Driver out-of-bounds write (intel-sa-00918)
11 months 1 week ago
A vulnerability was found in Intel Ethernet Network Controllers and Adapters 4.4 on Linux and classified as critical. This issue affects some unknown processing of the component Kernel Mode Driver Handler. The manipulation leads to out-of-bounds write.
The identification of this vulnerability is CVE-2024-23497. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-28947 | Intel Server Board S2600ST Family prior 02.01.0017 Kernel Mode Driver input validation (intel-sa-01121)
11 months 1 week ago
A vulnerability classified as critical has been found in Intel Server Board S2600ST Family. This affects an unknown part of the component Kernel Mode Driver Handler. The manipulation leads to improper input validation.
This vulnerability is uniquely identified as CVE-2024-28947. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-24977 | Intel License Manager for FLEXlm Product Software prior 11.19.5.0 uncontrolled search path (intel-sa-01126)
11 months 1 week ago
A vulnerability, which was classified as critical, was found in Intel License Manager for FLEXlm Product Software. This affects an unknown part. The manipulation leads to uncontrolled search path.
This vulnerability is uniquely identified as CVE-2024-24977. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-25561 | Intel HID Event Filter Software Installer prior 2.2.2.1 insecure inherited permissions (intel-sa-01089)
11 months 1 week ago
A vulnerability was found in Intel HID Event Filter Software Installer and classified as critical. This issue affects some unknown processing. The manipulation leads to insecure inherited permissions.
The identification of this vulnerability is CVE-2024-25561. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23908 | Intel FPGA Software prior 11.19.5.0 Flexlm License Daemon insecure inherited permissions (intel-sa-01107)
11 months 1 week ago
A vulnerability was found in Intel FPGA Software. It has been classified as critical. Affected is an unknown function of the component Flexlm License Daemon. The manipulation leads to insecure inherited permissions.
This vulnerability is traded as CVE-2024-23908. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23489 | Intel VROC Software 8.0.8.1001 uncontrolled search path (intel-sa-01128)
11 months 1 week ago
A vulnerability classified as critical has been found in Intel VROC Software 8.0.8.1001. Affected is an unknown function. The manipulation leads to uncontrolled search path.
This vulnerability is traded as CVE-2024-23489. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-28887 | Intel IPP Software prior 2021.11 uncontrolled search path (intel-sa-01129)
11 months 1 week ago
A vulnerability, which was classified as critical, was found in Intel IPP Software. This affects an unknown part. The manipulation leads to uncontrolled search path.
This vulnerability is uniquely identified as CVE-2024-28887. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com