Aggregator
CVE-2021-29440 | Grav up to 1.7.10 Twig Processing code injection (EDB-49961)
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
- CVE-2018-14933 NUUO NVRmini Devices OS Command Injection Vulnerability
- CVE-2022-23227 NUUO NVRmini 2 Devices Missing Authentication Vulnerability
- CVE-2019-11001 Reolink Multiple IP Cameras OS Command Injection Vulnerability
- CVE-2021-40407 Reolink RLC-410W IP Camera OS Command Injection Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
CISA Releases Best Practice Guidance for Mobile Communications
Today, CISA released Mobile Communications Best Practice Guidance. The guidance was crafted in response to identified cyber espionage activity by People’s Republic of China (PRC) government-affiliated threat actors targeting commercial telecommunications infrastructure, specifically addressing “highly targeted” individuals who are in senior government or senior political positions and likely to possess information of interest to these threat actors.
Highly targeted individuals should assume that all communications between mobile devices—including government and personal devices—and internet services are at risk of interception or manipulation.
CISA strongly urges highly targeted individuals to immediately review and apply the best practices provided in the guidance to protect mobile communications, including consistent use of end-to-end encryption.
Not Your Old ActiveState: Introducing our End-to-End OS Platform
Not Your Old ActiveState: Introducing our End-to-End OS Platform
European companies hit with effective DocuSign-themed phishing emails
A threat actor looking to take over the Microsoft Azure cloud infrastructure of European companies has successfully compromised accounts of multiple victims in different firms, according to Palo Alto Networks’ Unit 42 researchers. The phishing campaign The attack started earlier this year, with phishing emails that were received by roughly 20,000 users in European (including German and UK) companies in the automotive, chemical and industrial compound manufacturing sectors. The campaign peaked in June 2024. The … More →
The post European companies hit with effective DocuSign-themed phishing emails appeared first on Help Net Security.
CNCERT发现处置两起美对我大型科技企业机构网络攻击事件
CVE-2005-1589 | Linux Kernel up to 2.6.11.9 raw_ioctl memory corruption (EDB-998 / Nessus ID 20450)
CVE-1999-0879 | University of Washington wu-ftpd Message File macro memory corruption (EDB-19560 / Nessus ID 10318)
CVE-2001-0304 | Caucho Technology Resin 1.2.2 URL path traversal (EDB-20635 / Nessus ID 10656)
От мирового лидера к изоляции: РВИ требует пересмотра законопроекта о видеоиграх
CVE-2002-0653 | mod_ssl 2.8.9 Hook ssl_compat_directive off-by-one (EDB-21575 / Nessus ID 13951)
黑莓公司以1折价贱卖网络安全业务Cylance 当时买入价14亿美元现在仅1.6亿美元
New I2PRAT Malware Using encrypted peer-to-peer communication to Evade Detections
Cybersecurity experts are sounding the alarm over a new strain of malware dubbed “I2PRAT,” which leverages encrypted peer-to-peer (P2P) communication via the Invisible Internet Project (I2P) network to avoid detection. The malware, first reported on November 19 by the researcher Gi7w0rm, demonstrates a highly sophisticated infection chain and innovative evasion techniques, raising concerns among the […]
The post New I2PRAT Malware Using encrypted peer-to-peer communication to Evade Detections appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.