Aggregator
CVE-2020-12242 | Valve Source Engine /tmp/hl2_relaunch privileges management (EDB-48387)
Submit #405528: 10Web cms <=1.0 Improper Restriction of Names for Files and Other Resources [Accepted]
CVE-2002-1147 | HP Procurve Switch 4000M up to C.09.15 HTTP Administration Interface denial of service (EDB-21828 / XFDB-10172)
CVE-2014-6699 | Weather Channel 5.2.0 X.509 Certificate cryptographic issues (VU#582497)
Record $65m Settlement for Hacked Patient Photos
CVE-2007-2609 | gnuedu web/index.php LIBSDIR code injection (EDB-3876 / XFDB-34174)
The Dark Nexus Between Harm Groups and ‘The Com’
CVE-2007-2609 | gnuedu web/help.php LIBSDIR code injection (EDB-3876 / XFDB-34174)
CVE-2014-6698 | igg Galaxy Online 2 1.2.3 X.509 Certificate cryptographic issues (VU#582497)
纯干货 | 开学反诈第一课!大学生警惕成为电诈“工具人”
一图读懂 | 如何更好的保护你的个人信息
国际 | 部分国家对网络犯罪的规制
2024网安周 | 让网络安全“防火墙”愈筑愈牢、“保护网”越织越密
CCS 2024 | 金钻芯科技发布《高效安全管理体系白皮书》
CCS 2024 | 科蓝软件——底线思维扫除隐患,国产数据库捍卫金融数据安全
CCS 2024 | 《关键信息基础设施网络及信息系统作业可信与安全白皮书》重磅发布,共筑安全可信的网络空间
Choosing the Best Solution for Your SecOps Automation Needs
与 AI 对话有助于减少阴谋论信仰
Ivanti Releases Security Update for Cloud Services Appliance
Ivanti has released a security update addressing an OS command injection vulnerability (CVE-2024-8190) affecting Ivanti Cloud Services Appliance (CSA) 4.6 (all versions before patch 519). A cyber threat actor could exploit this vulnerability to take control of an affected system.
At this time, Ivanti has confirmed limited exploitation and urges its customers using the affected versions to upgrade to CSA version 5.0. Ivanti no longer supports CSA 4.6 (end-of-life).
CISA recommends users and administrators review CISA and FBI's joint guidance on eliminating OS command injections and the Ivanti security advisory and apply the recommended updates.
Note: CISA has added CVE-2024-8190 to its Known Exploited Vulnerabilities Catalog, which, per Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the specified due date to protect FCEB networks against active threats.