Aggregator
CVE-2024-33039 | Qualcomm Snapdragon Auto/Snapdragon Wearables up to WSA8835 PAL Service API untrusted pointer dereference
CVE-2024-33040 | Qualcomm Snapdragon Auto up to XR2 5G Platform Release Command use after free
CVE-2024-33037 | Qualcomm Snapdragon Auto up to XR2 5G Platform NPU Firmware buffer over-read
CVE-2024-33036 | Qualcomm Snapdragon Auto up to XR2 5G Platform Sensor Packet Parser out-of-range pointer offset
利用SSRF访问内部数据
AWS offers incident response service
Amazon Web Services (AWS) has launched a new service to help organizations prepare for and recover from ransomware attacks, account takeovers, data breaches, and other security events: AWS Security Incident Response (SIR). Creating a case (Source: AWS) AWS Security Incident Response explained “Security events are becoming more pervasive and complex for customers,” says Betty Zheng, Senior Developer Advocate at AWS. Incident response is becoming harder due to the increased complexity and the lack of in-house … More →
The post AWS offers incident response service appeared first on Help Net Security.
CVE-2024-20137 | MediaTek MT6890/MT7622/MT7915/MT7916/MT7981/MT7986 WLAN Driver uncaught exception (MSV-1727 / WCNCR00384543)
CVE-2024-20138 | MediaTek MT8390 WLAN Driver out-of-bounds (MSV-1604 / ALPS08998291)
CVE-2024-20136 | MediaTek MT8893 Da out-of-bounds (MSV-1821 / ALPS09121847)
CVE-2024-20135 | MediaTek MT9687 Soundtrigger out-of-bounds write (MSV-1841 / ALPS09142526)
CVE-2024-20139 | MediaTek MT8678 Android 13.0 up to SDK release 3.3 Bluetooth Firmware assertion (MSV-1600 / ALPS09001270)
CVE-2024-10490 | B&R Industrial Automation mapp Cockpit up to 5.x authentication bypass
CVE-2004-0940 | Apache HTTP Server up to 1.3.32-r1 mod_include get_tag memory corruption (EDB-587 / Nessus ID 15797)
2nd December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 2nd December, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Supply chain software provider Blue Yonder was hit by a ransomware attack, disrupting services for clients like Starbucks and UK grocery chains Morrisons and Sainsbury’s. The incident affected operations such as employee […]
The post 2nd December – Threat Intelligence Report appeared first on Check Point Research.