Aggregator
Weekly Report: Ivanti Endpoint Manager Mobileに複数の脆弱性
9 months ago
Ivanti製Ivanti Endpoint Manager Mobileには、認証バイパスの脆弱性(CVE-2025-4427)と任意のコード実行の脆弱性(CVE-2025-4428)があります。Ivantiは、当該脆弱性を悪用した攻撃を確認しているとのことです。この問題は、当該製品にパッチを適用することで解決します。詳細は、開発者が提供する情報を参照してください。
Account Takeover Scams Are Bypassing Fraud Defenses
9 months ago
FIs Must Invest in AI-Fueled Behavioral Biometrics to Go Beyond Static Credentials
Scammers are increasingly turning to account takeover fraud, as financial institutions ramp up their defenses. Instead of luring victims into making authorized transactions, cybercriminals are bypassing them altogether, hijacking their digital identities and draining accounts from within.
Scammers are increasingly turning to account takeover fraud, as financial institutions ramp up their defenses. Instead of luring victims into making authorized transactions, cybercriminals are bypassing them altogether, hijacking their digital identities and draining accounts from within.
US Senate Democrats Push Noem on Cybersecurity Spending Cuts
9 months ago
Homeland Security Secretary Says Trump Budget Strengthens Cybersecurity
Senate Democrats Tuesday pushed Homeland Security Secretary Kristi Noem on the Trump administration's cuts to the cybersecurity component of the U.S. federal department she leads. Noem told senators the U.S. Cybersecurity and Infrastructure Agency will "continue to fulfill" its statutory obligations.
Senate Democrats Tuesday pushed Homeland Security Secretary Kristi Noem on the Trump administration's cuts to the cybersecurity component of the U.S. federal department she leads. Noem told senators the U.S. Cybersecurity and Infrastructure Agency will "continue to fulfill" its statutory obligations.
M&S Reportedly Hacked Using Third-Party Credentials
9 months ago
Scattered Spider Stole Tata Consulting Services Employee Login Details for Hack
British retailer Marks & Spencer was reportedly compromised by cybercrime group Scattered Spider using stolen employee credentials from a third-party IT company. Citing an unidentified source, Reuters reported hackers used the M&S login credentials of two Tata Consulting Services employees.
British retailer Marks & Spencer was reportedly compromised by cybercrime group Scattered Spider using stolen employee credentials from a third-party IT company. Citing an unidentified source, Reuters reported hackers used the M&S login credentials of two Tata Consulting Services employees.
Judge Lets Delta Lawsuit Over CrowdStrike Outage Proceed
9 months ago
Georgia Court Allows Claims of Fraud, Trespass Over Falcon Software Update
Delta can proceed with its lawsuit against CrowdStrike over a July 2024 update that allegedly bypassed Microsoft safeguards and crashed thousands of systems. The judge found that Delta sufficiently alleged fraud, computer trespass and gross negligence, allowing key claims to move forward.
Delta can proceed with its lawsuit against CrowdStrike over a July 2024 update that allegedly bypassed Microsoft safeguards and crashed thousands of systems. The judge found that Delta sufficiently alleged fraud, computer trespass and gross negligence, allowing key claims to move forward.
[remote] Remote Keyboard Desktop 1.0.1 - Remote Code Execution (RCE)
9 months ago
Remote Keyboard Desktop 1.0.1 - Remote Code Execution (RCE)
我国科技企业遭境外黑客攻击,透视APT攻击反制策略
9 months ago
境外黑客组织针对我国关键领域的网络攻击频率激增!
CVE-2025-21863 | Linux Kernel up to 6.6.79/6.12.16/6.13.4/6.14-rc3 io_uring privilege escalation (Nessus ID 236983)
9 months ago
A vulnerability was found in Linux Kernel up to 6.6.79/6.12.16/6.13.4/6.14-rc3. It has been classified as problematic. Affected is an unknown function of the component io_uring. The manipulation leads to privilege escalation.
This vulnerability is traded as CVE-2025-21863. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-58088 | Linux Kernel up to 6.6.79/6.12.16/6.13.4/6.14-rc3 bpf_local_storage_map_free deadlock (Nessus ID 236983)
9 months ago
A vulnerability was found in Linux Kernel up to 6.6.79/6.12.16/6.13.4/6.14-rc3 and classified as critical. This issue affects the function bpf_local_storage_map_free. The manipulation leads to deadlock.
The identification of this vulnerability is CVE-2024-58088. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21851 | Linux Kernel up to 6.12.16/6.13.4/6.14-rc3 arena_map_free memory corruption (Nessus ID 236983)
9 months ago
A vulnerability was found in Linux Kernel up to 6.12.16/6.13.4/6.14-rc3. It has been rated as critical. Affected by this issue is the function arena_map_free. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2025-21851. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21836 | Linux Kernel up to 6.6.78/6.12.15/6.13.3/6.14-rc2 io_uring io_buffer_list allocation of resources (Nessus ID 236983)
9 months ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.6.78/6.12.15/6.13.3/6.14-rc2. Affected by this vulnerability is the function io_buffer_list of the component io_uring. The manipulation leads to allocation of resources.
This vulnerability is known as CVE-2025-21836. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21854 | Linux Kernel up to 6.6.79/6.12.16/6.13.4/6.14-rc3 psock_update_sk_prot null pointer dereference (Nessus ID 236983)
9 months ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.6.79/6.12.16/6.13.4/6.14-rc3. This affects the function vsock_proto::psock_update_sk_prot. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2025-21854. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
PowerSchool hacker pleads guilty to student data extortion scheme
9 months ago
A 19-year-old college student from Worcester, Massachusetts, has agreed to plead guilty to a massive cyberattack on PowerSchool that extorted millions of dollars in exchange for not leaking the personal data of millions of students and teachers. [...]
Lawrence Abrams
CVE-2019-1024 | Microsoft Edge/ChakraCore Chakra Scripting Engine memory corruption (ID 91543)
9 months ago
A vulnerability, which was classified as critical, was found in Microsoft Edge and ChakraCore. Affected is an unknown function of the component Chakra Scripting Engine. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2019-1024. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2019-1023 | Microsoft Edge/ChakraCore Scripting Engine information disclosure (ID 91543)
9 months ago
A vulnerability was found in Microsoft Edge and ChakraCore. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Scripting Engine. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2019-1023. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2019-1025 | Microsoft Windows up to Server 2019 memory corruption (ID 91544)
9 months ago
A vulnerability classified as critical has been found in Microsoft Windows. This affects an unknown part. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2019-1025. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2019-1026 | Microsoft Windows up to Server 2019 Audio Service access control (ID 91544)
9 months ago
A vulnerability classified as critical was found in Microsoft Windows up to Server 2019. This vulnerability affects unknown code of the component Audio Service. The manipulation leads to improper access controls.
This vulnerability was named CVE-2019-1026. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2019-1027 | Microsoft Windows up to Server 2019 Audio Service access control (ID 91544)
9 months ago
A vulnerability, which was classified as critical, has been found in Microsoft Windows up to Server 2019. This issue affects some unknown processing of the component Audio Service. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2019-1027. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2019-1028 | Microsoft Windows up to Server 2019 Audio Service access control (ID 91544)
9 months ago
A vulnerability, which was classified as critical, was found in Microsoft Windows. Affected is an unknown function of the component Audio Service. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2019-1028. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com