192Articles
10Categories
2024-09-10Date
🚨
U.S. CISA adds SonicWall SonicOS, ImageMagick and Linux Kernel bugs to its Known Exploited Vulnerabilities catalogsubmitted by kid to cybersecurity 2 points | 0 comments https://securityaffairs.com/168251/security/u-s-cisa-adds-sonicwall-sonicos-imagemagick-and-linux-kernel-bugs-to-its-known-exploited-vulnerabilities-catalog.html
KEV
🚨
CISA Adds Four Known Exploited Vulnerabilities to CatalogCISA has added four new vulnerabilities to its  Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2024-38226 Microsoft Publisher Security Feature Bypass Vulnerability CVE-2024-43491 Microsoft Windows Update Remote Code Execution Vulnerab…
KEV
πŸ›
MindsDB Fixes Critical CVE-2024-24759: DNS Rebinding Attack Bypasses Security Protections
πŸ›
PoC Exploit Releases for Windows Elevation of Privilege Vulnerability (CVE-2024-26230)
πŸ›
CISA Issues Warning About Three Actively Exploited Vulnerabilities in the Wild
KEV
πŸ›
New Chrome Zero-Day
πŸ›
Citrix Releases Security Updates for Citrix Workspace App for Windows
πŸ›
CVE-2020-17042 Windows Print Spooler Remote Code Execution Vulnerability
πŸ›
Ivanti Releases Security Updates for Endpoint Manager, Cloud Service Application, and Workspace Control
πŸ›
CVE-2024-37338 Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
πŸ›
CVE-2024-37966 Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
πŸ›
CVE-2024-37335 Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
πŸ›
CVE-2024-37340 Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
πŸ›
CVE-2024-37339 Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
πŸ›
CVE-2024-37337 Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
πŸ›
CVE-2024-37342 Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
πŸ›
CVE-2024-26186 Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
πŸ›
CVE-2024-26191 Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability
πŸ›
CVE-2024-38018 Microsoft SharePoint Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-38216 Azure Stack Hub Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38220 Azure Stack Hub Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38188 Azure Network Watcher VM Agent Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38230 Windows Standards-Based Storage Management Service Denial of Service Vulnerability
πŸ›
CVE-2024-38236 DHCP Server Service Denial of Service Vulnerability
πŸ›
CVE-2024-38240 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38241 Kernel Streaming Service Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38242 Kernel Streaming Service Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38249 Windows Graphics Component Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38250 Windows Graphics Component Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38252 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38253 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38254 Windows Authentication Information Disclosure Vulnerability
πŸ›
CVE-2024-38256 Windows Kernel-Mode Driver Information Disclosure Vulnerability
πŸ›
CVE-2024-43463 Microsoft Office Visio Remote Code Execution Vulnerability
πŸ›
CVE-2024-43464 Microsoft SharePoint Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-43467 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
πŸ›
CVE-2024-43474 Microsoft SQL Server Information Disclosure Vulnerability
πŸ›
CVE-2024-43482 Microsoft Outlook for iOS Information Disclosure Vulnerability
πŸ›
CVE-2024-43492 Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43465 Microsoft Excel Elevation of Privilege Vulnerability
πŸ›
CVE-2024-37965 Microsoft SQL Server Elevation of Privilege Vulnerability
πŸ›
CVE-2024-37341 Microsoft SQL Server Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38014 Windows Installer Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38046 PowerShell Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38217 Windows Mark of the Web Security Feature Bypass Vulnerability
πŸ›
CVE-2024-38225 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38226 Microsoft Publisher Security Feature Bypass Vulnerability
πŸ›
CVE-2024-38227 Microsoft SharePoint Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-38228 Microsoft SharePoint Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-38231 Windows Remote Desktop Licensing Service Denial of Service Vulnerability
πŸ›
CVE-2024-38232 Windows Networking Denial of Service Vulnerability
πŸ›
CVE-2024-38233 Windows Networking Denial of Service Vulnerability
πŸ›
CVE-2024-38234 Windows Networking Denial of Service Vulnerability
πŸ›
CVE-2024-38235 Windows Hyper-V Denial of Service Vulnerability
πŸ›
CVE-2024-38237 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38238 Kernel Streaming Service Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38239 Windows Kerberos Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38243 Kernel Streaming Service Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38244 Kernel Streaming Service Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38245 Kernel Streaming Service Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38246 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38247 Windows Graphics Component Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38248 Windows Storage Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38257 Microsoft AllJoyn API Information Disclosure Vulnerability
πŸ›
CVE-2024-38258 Windows Remote Desktop Licensing Service Information Disclosure Vulnerability
πŸ›
CVE-2024-38259 Microsoft Management Console Remote Code Execution Vulnerability
πŸ›
CVE-2024-38260 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
πŸ›
CVE-2024-38263 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
πŸ›
CVE-2024-21416 Windows TCP/IP Remote Code Execution Vulnerability
πŸ›
CVE-2024-38045 Windows TCP/IP Remote Code Execution Vulnerability
πŸ›
CVE-2024-38119 Windows Network Address Translation (NAT) Remote Code Execution Vulnerability
πŸ›
CVE-2024-43454 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
πŸ›
CVE-2024-43455 Windows Remote Desktop Licensing Service Spoofing Vulnerability
πŸ›
CVE-2024-43457 Windows Setup and Deployment Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43458 Windows Networking Information Disclosure Vulnerability
πŸ›
CVE-2024-43461 Windows MSHTML Platform Spoofing Vulnerability
πŸ›
CVE-2024-43466 Microsoft SharePoint Server Denial of Service Vulnerability
πŸ›
CVE-2024-43469 Azure CycleCloud Remote Code Execution Vulnerability
πŸ›
CVE-2024-43470 Azure Network Watcher VM Agent Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43475 Microsoft Windows Admin Center Information Disclosure Vulnerability
πŸ›
CVE-2024-43476 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
πŸ›
CVE-2024-43479 Microsoft Power Automate Desktop Remote Code Execution Vulnerability
πŸ›
CVE-2024-30073 Windows Security Zone Mapping Security Feature Bypass Vulnerability
πŸ›
CVE-2024-43487 Windows Mark of the Web Security Feature Bypass Vulnerability
πŸ›
CVE-2024-43491 Microsoft Windows Update Remote Code Execution Vulnerability
πŸ›
CVE-2024-43495 Windows libarchive Remote Code Execution Vulnerability
πŸ›
CVE-2024-38194 Azure Web Apps Elevation of Privilege Vulnerability
πŸ›
CVE-2024-37980 Microsoft SQL Server Elevation of Privilege Vulnerability
πŸ›
Cisco Releases Security Updates for Cisco Smart Licensing Utility
⚠️
Want to get ahead? Four activities that can enable a more proactive security regime
⚠️
CAMO Unveiled: How Cybercriminals Exploit Legitimate Software for Stealthy Attacks
⚠️
High School in London Forced to Sends Students Home Following Ransomware Attack
⚠️
WhatsApp’s β€œView Once” Feature Flaw Exploited in the Wild
KEV
⚠️
China-based cyber espionage campaign in SE Asia is expanding, says Sophos
⚠️
Third-party risk management can learn a lot from the musk ox
⚠️
New PIXHELL Attack Exploits Screen Noise to Exfiltrates Data from Air-Gapped Computers
⚠️
US targets advanced AI and cloud firms with new reporting proposal
⚠️
Chinese APT Group Abuses Visual Studio Code to Target Government in Asia
⚠️
ChatGPT 4 can exploit 87% of one-day vulnerabilities: Is it really that impressive?
⚠️
Chinese Hackers Using Open Source Tools To Launch Cyber Attacks
⚠️
CISA Releases Four Industrial Control Systems Advisories
⚠️
Microsoft to start force-upgrading Windows 22H2 systems next month
⚠️
CISA Breaks Silence On Controversial Airport Security Bypass Vulnerability
⚠️
Avis reports data breach affecting 300,000 customers
⚠️
Microsoft September 2024 Patch Tuesday fixes 4 zero-days, 79 flaws
KEV
⚠️
Microsoft fixes Windows Smart App Control zero-day exploited since 2018
⚠️
Microsoft September 2024 Patch Tuesday, (Tue, Sep 10th)
⚠️
Microsoft Releases September 2024 Security Updates
⚠️
Critical Patches Issued for Microsoft Products, September 10, 2024
⚠️
Ivanti fixes maximum severity RCE bug in Endpoint Management software
⚠️
ANZ CIOs see cybersecurity as top priority for 2025
⚠️
Commerce Unveils 'Scale' Tool to Tackle Supply Chain Risks
⚠️
US quantum computing lead over China threatened by weakness in commercialization
⚠️
Microsoft Says Windows Update Zero-DayΒ Being Exploited to Undo Security Fixes
⚠️
UK ICO and NCA to Collaborate on Cyber Incident Preparedness
⚠️
Bug Left Some Windows PCs Dangerously Unpatched
KEV
⚠️
RAM Signals Expose Air-Gapped Networks to Attacks
πŸ“‹
Adobe Patches Critical, Code Execution Flaws in Multiple Products
πŸ“‹
Windows 10 KB5043064 update released with 6 fixes, security updates
πŸ“‹
CrowdStrike Has Yet to See Any Customer Lawsuits Over Outage
πŸ“‹
Microsoft fixes Windows Server performance issues from August updates
πŸ“’
Researchers Details Attacks On Air-Gaps Computers To Steal Data
πŸ“’
Kimsuky-linked Hackers Use Similar Tactics to Attack Russia and South Korea
πŸ“’
SAP security advisory – September 2024 monthly rollup (AV24-506)
πŸ“’
CISA Flags ICS Bugs in Baxter, Mitsubishi Products
πŸ“’
[Control systems] Siemens security advisory (AV24–507)
πŸ“’
[Control systems] Schneider Electric security advisory (AV24-508)
πŸ“’
Ivanti security advisory (AV24-509)
πŸ“’
Microsoft security advisory – September 2024 monthly rollup (AV24-510)
πŸ“’
Adobe security advisory (AV24–511)
πŸ“’
Polish Government Disrupts Russian and Belarusian Hacks
πŸ”₯
Poland’s Cybersecurity Experts Foil Russian and Belarussian Attacks
πŸ”₯
Slim CD Data Breach Impacts 1.7 Million Individuals
πŸ”₯
Mustang Panda Deploys Advanced Malware to Spy on Asia-Pacific Governments
πŸ”₯
NoName ransomware gang deploying RansomHub malware in recent attacks
πŸ”₯
'TIDrone' Cyberattackers Target Taiwan's Drone Manufacturers
πŸ”₯
Shining a Light on Shadow Apps: The Invisible Gateway to SaaS Data Breaches
πŸ”₯
Wisconsin Insurer Discloses Data Breach Impacting 950,000 Individuals
πŸ”₯
Experts Identify 3 Chinese-Linked Clusters Behind Cyberattacks in Southeast Asia
πŸ”₯
Using Time in Your Favor During a Ransomware Attack
πŸ”₯
Poland thwarted cyberattacks that were carried out by Russia and Belarus
πŸ”₯
Poland Dismantles Cyber Sabotage Group Linked to Russia, Belarus
πŸ”₯
CISO & Legal: Partnerships Needed - Joe Sullivan - CSP #191
πŸ”₯
Small Business, Big Threats: INE Security Launches Initiative to Train SMBs to Close a Critical Skills Gap
πŸ”₯
Electronic Payment Firm Slim CD Notifies 1.7M Customers Of Data Breach
πŸ”₯
CosmicBeetle Deploys Custom ScRansom Ransomware, Partnering with RansomHub
πŸ”₯
RansomHub ransomware abuses Kaspersky TDSSKiller to disable EDR software
πŸ”₯
London’s transit agency drops claim it has β€˜no evidence’ of customer data theft after hack
πŸ”₯
News alert: INE Security launches initiative to help SMBs foster a proactive cybersecurity culture
πŸ”₯
CosmicBeetle steps up: Probation period at RansomHub
πŸ•΅οΈ
ISC Stormcast For Tuesday, September 10th, 2024 https://isc.sans.edu/podcastdetail/9132, (Tue, Sep 10th)
πŸ•΅οΈ
Threat Actors Allegedly Claiming Leak of Capgemini Data
πŸ•΅οΈ
North Korean Threat Actors Deploy COVERTCATCH Malware via LinkedIn Job Scams
πŸ•΅οΈ
Lazarus Group Targets Blockchain Pros with Fake Video Conferencing, Job Scam
πŸ•΅οΈ
Beware Of Malicious Chrome Extension That Delivers Weaponized ZIP Archive
πŸ•΅οΈ
Crimson Palace returns: New Tools, Tactics, and Targets
πŸ•΅οΈ
Darkhive Raises $21 Million for Drones, Secure Code Delivery System
πŸ•΅οΈ
The AI Convention: Lofty Goals, Legal Loopholes, and National Security Caveats
πŸ•΅οΈ
China-Linked Hackers Target Drone Makers
πŸ•΅οΈ
Upcoming Webinar On How To Avoid Hiring Nation-State Fake Employees
πŸ•΅οΈ
CyberheistNews Vol 14 #37 Scammers Use Fake Funeral LiveStream Social Media Posts to Extort Victims
πŸ•΅οΈ
Seventh Sense Unveils Revolutionary Privacy-Preserving Face-Based Public Key Infrastructure and eID Solution
πŸ•΅οΈ
Study Finds Excessive Use of Remote Access Tools in OT Environments
πŸ•΅οΈ
P0 Security Banks $15M for Security Cloud Access
πŸ•΅οΈ
SAP Releases 16 New Security Notes on September 2024 Patch Day
πŸ•΅οΈ
Epic AI Fails And What We Can Learn From Them
πŸ•΅οΈ
Paying Down Tech Debt, Rust in Firmware, EUCLEAK, Deploying SSO - ASW #298
πŸ•΅οΈ
AI Trucks, Solid Concrete, Sonicwall, Progress, Rust, Apple, and more... - SWN #412
πŸ•΅οΈ
Quad7 Botnet Operators Expand Targets, Aim for Stealth
πŸ•΅οΈ
News alert: Seventh Sense unveils a revolutionary privacy solution β€” face-based PKI and β€˜eID’
🌐
Spyware Vendors' Nebulous Ecosystem Helps Them Evade Sanctions
🌐
Cybercriminals Target Latin American Banks with Mekotio, BBTok, and Grandoreiro Trojans
🌐
Predator Spyware Roars Back with New Infrastructure, Evasive Tactics
πŸŽ™οΈ
The AI Fix #15: AI robot butlers and gigawatt banana highways
πŸ“‘
Musician Charged With $10M Streaming Royalties Fraud Using AI and Bots
πŸ“‘
Homeland Security Hopes to Scuttle Maritime Cyber-Threats
πŸ“‘
Moody's Ratings: Cyber Insurance Competition Up, Prices Down
πŸ“‘
Key Cyber Insurance Stakeholders Urge Government To Help Close $900B in Uncovered Risk
πŸ“‘
Underground Demand for Malicious LLMs is Robust
πŸ“‘
Navigating Endpoint Privilege Management: Insights for CISOs and Admins
πŸ“‘
Flipper Zero releases Firmware 1.0 after three years of development
πŸ“‘
Wix.com to block Russian users starting September 12
πŸ“‘
Crypto Scams Rake In $5.6B A Year For Lowlifes, FBI Says
πŸ“‘
Microsoft Hosting Cybersecurity Summit After Global IT Outage
πŸ“‘
WhatApp's View Once Could Be View Whenever Due To A Flaw
πŸ“‘
Russia's Top Secret Military Unit Reportedly Plots Undersea Cable Sabotage
πŸ“‘
Wix to block Russian users starting September 12
πŸ“‘
How to Harness the Power of GenAI and LLM Responsibly
πŸ“‘
Windows 11 KB5043076 cumulative update released with 19 changes
πŸ“‘
Sophos Firewall v21: Third-party threat feeds
πŸ“‘
New PIXHELL acoustic attack leaks secrets from LCD screen noise
πŸ“‘
Defending the Cloud: Essential Strategies for Cyber Resilience