224Articles
10Categories
2024-10-08Date
🚨
CISA Adds Three Known Exploited Vulnerabilities to CatalogCISA has added three new vulnerabilities to its  Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2024-43047 Qualcomm Multiple Chipsets Use-After-Free Vulnerability CVE-2024-43572 Microsoft Windows Management Console Remote Code Executi…
KEV
πŸ›
Qualcomm Urges OEMs to Patch Critical DSP and WLAN Flaws Amid Active Exploits
πŸ›
Open-Source Scanner Released to Detect CUPS Vulnerability
πŸ›
PoC Exploit Releases for CVE-2024-44193: Local Privilege Escalation Vulnerability in iTunes
πŸ›
CVE-2021-1683 Windows Bluetooth Security Feature Bypass Vulnerability
πŸ›
CVE-2021-1684 Windows Bluetooth Security Feature Bypass Vulnerability
πŸ›
CVE-2021-1638 Windows Bluetooth Security Feature Bypass Vulnerability
πŸ›
CVE-2024-38097 Azure Monitor Agent Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43516 Windows Secure Kernel Mode Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38179 Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38261 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-43480 Azure Service Fabric for Linux Remote Code Execution Vulnerability
πŸ›
CVE-2024-43481 Power BI Report Server Spoofing Vulnerability
πŸ›
CVE-2024-38229 .NET and Visual Studio Remote Code Execution Vulnerability
πŸ›
CVE-2024-43502 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43503 Microsoft SharePoint Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43504 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2024-43505 Microsoft Office Visio Remote Code Execution Vulnerability
πŸ›
CVE-2024-43506 BranchCache Denial of Service Vulnerability
πŸ›
CVE-2024-43508 Windows Graphics Component Information Disclosure Vulnerability
πŸ›
CVE-2024-43513 BitLocker Security Feature Bypass Vulnerability
πŸ›
CVE-2024-43515 Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability
πŸ›
CVE-2024-43518 Windows Telephony Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-43519 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-43525 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-43526 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-43527 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43529 Windows Print Spooler Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43532 Remote Registry Service Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43533 Remote Desktop Client Remote Code Execution Vulnerability
πŸ›
CVE-2024-43534 Windows Graphics Component Information Disclosure Vulnerability
πŸ›
CVE-2024-43535 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43537 Windows Mobile Broadband Driver Denial of Service Vulnerability
πŸ›
CVE-2024-43538 Windows Mobile Broadband Driver Denial of Service Vulnerability
πŸ›
CVE-2024-43540 Windows Mobile Broadband Driver Denial of Service Vulnerability
πŸ›
CVE-2024-43541 Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
πŸ›
CVE-2024-43542 Windows Mobile Broadband Driver Denial of Service Vulnerability
πŸ›
CVE-2024-43543 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-43554 Windows Kernel-Mode Driver Information Disclosure Vulnerability
πŸ›
CVE-2024-43573 Windows MSHTML Platform Spoofing Vulnerability
πŸ›
CVE-2024-43576 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2024-43581 Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
πŸ›
CVE-2024-6197 Open Source Curl Remote Code Execution Vulnerability
πŸ›
CVE-2024-43601 Visual Studio Code for Linux Remote Code Execution Vulnerability
πŸ›
CVE-2024-43604 Outlook for Android Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43608 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-43609 Microsoft Office Spoofing Vulnerability
πŸ›
CVE-2024-43607 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-43612 Power BI Report Server Spoofing Vulnerability
πŸ›
CVE-2024-43615 Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
πŸ›
CVE-2024-43616 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2024-43500 Windows Resilient File System (ReFS) Information Disclosure Vulnerability
πŸ›
CVE-2024-20659 Windows Hyper-V Security Feature Bypass Vulnerability
πŸ›
CVE-2024-37976 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
πŸ›
CVE-2024-37982 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
πŸ›
CVE-2024-37979 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2024-37983 Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
πŸ›
CVE-2024-38149 BranchCache Denial of Service Vulnerability
πŸ›
CVE-2024-38029 Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
πŸ›
CVE-2024-38129 Windows Kerberos Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38124 Windows Netlogon Elevation of Privilege Vulnerability
πŸ›
CVE-2024-38265 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-38262 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
πŸ›
CVE-2024-43453 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-38212 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-30092 Windows Hyper-V Remote Code Execution Vulnerability
πŸ›
CVE-2024-43456 Windows Remote Desktop ServicesΒ Tampering Vulnerability
πŸ›
CVE-2024-43483 .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
πŸ›
CVE-2024-43484 .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
πŸ›
CVE-2024-43485 .NET and Visual Studio Denial of Service Vulnerability
πŸ›
CVE-2024-43497 DeepSpeed Remote Code Execution Vulnerability
πŸ›
CVE-2024-43468 Microsoft Configuration Manager Remote Code Execution Vulnerability
πŸ›
CVE-2024-43501 Windows Common Log File System Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43509 Windows Graphics Component Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43511 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43512 Windows Standards-Based Storage Management Service Denial of Service Vulnerability
πŸ›
CVE-2024-43514 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43517 Microsoft ActiveX Data Objects Remote Code Execution Vulnerability
πŸ›
CVE-2024-43520 Windows Kernel Denial of Service Vulnerability
πŸ›
CVE-2024-43521 Windows Hyper-V Denial of Service Vulnerability
πŸ›
CVE-2024-43522 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43523 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-43524 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-43528 Windows Secure Kernel Mode Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43536 Windows Mobile Broadband Driver Remote Code Execution Vulnerability
πŸ›
CVE-2024-43544 Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability
πŸ›
CVE-2024-43545 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability
πŸ›
CVE-2024-43546 Windows Cryptographic Information Disclosure Vulnerability
πŸ›
CVE-2024-43547 Windows Kerberos Information Disclosure Vulnerability
πŸ›
CVE-2024-43549 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-43550 Windows Secure Channel Spoofing Vulnerability
πŸ›
CVE-2024-43551 Windows Storage Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43552 Windows Shell Remote Code Execution Vulnerability
πŸ›
CVE-2024-43553 NT OS Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43555 Windows Mobile Broadband Driver Denial of Service Vulnerability
πŸ›
CVE-2024-43556 Windows Graphics Component Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43557 Windows Mobile Broadband Driver Denial of Service Vulnerability
πŸ›
CVE-2024-43558 Windows Mobile Broadband Driver Denial of Service Vulnerability
πŸ›
CVE-2024-43559 Windows Mobile Broadband Driver Denial of Service Vulnerability
πŸ›
CVE-2024-43560 Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43561 Windows Mobile Broadband Driver Denial of Service Vulnerability
πŸ›
CVE-2024-43562 Windows Network Address Translation (NAT) Denial of Service Vulnerability
πŸ›
CVE-2024-43563 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43564 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-43565 Windows Network Address Translation (NAT) Denial of Service Vulnerability
πŸ›
CVE-2024-43567 Windows Hyper-V Denial of Service Vulnerability
πŸ›
CVE-2024-43570 Windows Kernel Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43571 Sudo for Windows Spoofing Vulnerability
πŸ›
CVE-2024-43572 Microsoft Management Console Remote Code Execution Vulnerability
πŸ›
CVE-2024-43574 Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability
πŸ›
CVE-2024-43575 Windows Hyper-V Denial of Service Vulnerability
πŸ›
CVE-2024-43582 Remote Desktop Protocol Server Remote Code Execution Vulnerability
πŸ›
CVE-2024-43584 Windows Scripting Engine Security Feature Bypass Vulnerability
πŸ›
CVE-2024-43585 Code Integrity Guard Security Feature Bypass Vulnerability
πŸ›
CVE-2024-43589 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-43590 Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43591 Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43592 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-43593 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-43599 Remote Desktop Client Remote Code Execution Vulnerability
πŸ›
CVE-2024-43603 Visual Studio Collector Service Denial of Service Vulnerability
πŸ›
CVE-2024-43583 Winlogon Elevation of Privilege Vulnerability
πŸ›
CVE-2024-43614 Microsoft Defender for Endpoint for Linux Spoofing Vulnerability
πŸ›
CVE-2024-43611 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2024-43488 Visual Studio Code extension for Arduino Remote Code Execution Vulnerability
πŸ›
New scanner finds Linux, UNIX servers exposed to CUPS RCE attacks
⚠️
How the increasing demand for cyber insurance is changing the role of the CISO
⚠️
Hackers Gained Unauthorized Network Access to Casio Networks
⚠️
Open-Source Scanner Released to Detect CUPS Vulnerability
⚠️
SAP Patches Critical BusinessObjects Vulnerability with October Security Updates
⚠️
Tokyo DriftSec: Who is going First? Who is going Smooth? - Lisa Landau - CSP #195
⚠️
Avoid Scams After Disaster Strikes
⚠️
Attackers Abuse URL Rewriting to Evade Security Filters
⚠️
Critical Automative 0-Day Flaws Let Attackers Gain Full Control Over Cars
⚠️
LemonDuck Malware Exploiting SMB Vulnerabilities To Attack Windwos Servers
⚠️
Exploiting Microsoft Teams on macOS during a Purple Team engagement
⚠️
Ivanti warns of three more CSA zero-days exploited in attacks
KEV
⚠️
Zero-Day Alert: Three Critical Ivanti CSA Vulnerabilities Actively Exploited
KEV
⚠️
Largest US Water Utility Hit by Cybersecurity Incident
⚠️
CISA and FBI Release Fact Sheet on Protecting Against Iranian Targeting of Accounts Associated with National Political Organizations
⚠️
RCE from Iconv + PHP, Fuzzing a Codec, Fuzzing LLMs, Revisiting Recall - ASW #302
⚠️
The Future of Zed Attack Proxy - Simon Bennetts, Ori Bendet - ASW #302
⚠️
Run Your Security Program Like an Election Campaign - Kush Sharma - BSW #367
⚠️
Microsoft October 2024 Patch Tuesday fixes 5 zero-days, 118 flaws
KEV
⚠️
Microsoft Releases October 2024 Security Updates
⚠️
6 Risk-Assessment-Frameworks im Vergleich
⚠️
Adobe Releases Security Updates for Multiple Products
⚠️
β€œEinzigartig und zerstΓΆrerisch”
⚠️
NHS: Most Patient Services Online Following Synnovis Attack
⚠️
Großangelegte Cyberattacke auf AWS
⚠️
Weg vom Hype, hin zur RealitΓ€t!
⚠️
OT geht auch den CISO an!
⚠️
UN Says Asian Cybercrime Cartels Are Rising Global Threat
⚠️
Muah.AI - 1,910,261 breached accounts
⚠️
Critical Patches Issued for Microsoft Products, October 8, 2024
πŸ“‹
Windows 10 KB5044273 update released with 9 fixes, security updates
πŸ“‹
Microsoft fixes Remote Desktop issues caused by Windows Server update
πŸ“‹
Microsoft Patch Tuesday - October 2024, (Tue, Oct 8th)
πŸ“‹
Patch Tuesday, October 2024 Edition
πŸ“’
Scalability Challenges in Privacy-Preserving Federated Learning
πŸ“’
[Control systems] Schneider Electric security advisory (AV24-570)
πŸ“’
[Control systems] Siemens security advisory (AV24-568)
πŸ“’
CISA and FBI Warn of Iranian-Backed Cyber Activity to Undermine U.S. Democratic Institutions
πŸ“’
SAP security advisory – October 2024 monthly rollup (AV24-569)
πŸ“’
Qualcomm security advisory (AV24-571)
πŸ“’
Ivanti security advisory (AV24-572)
πŸ“’
Adobe security advisory (AV24–573)
πŸ“’
Microsoft security advisory – October 2024 monthly rollup (AV24–574)
πŸ“’
CISA Issues Guidance to Counter Iran’s Election Interference
πŸ“’
Cloudflare Acquires Kivera to Fuel Preventive Cloud Security
πŸ”₯
Pro-Ukrainian Hackers Strike Russian State TV on Putin's Birthday
πŸ”₯
American Water Works Cyber Attack Impacts IT Systems
πŸ”₯
Comcast Cyber Attack Impacts 237,000+ Users Personal Data
πŸ”₯
fetchmail logs showing a Tor exit node is compromised
πŸ”₯
Study: 92% of Healthcare Firms Hit by Cyberattacks This Year
πŸ”₯
GoldenJackal Target Embassies and Air-Gapped Systems Using Malware Toolsets
πŸ”₯
China Possibly Hacking US β€œLawful Access” Backdoor
πŸ”₯
Cyberattack Group 'Awaken Likho' Targets Russian Government with Advanced Tools
πŸ”₯
LEGO's website hacked to push cryptocurrency scam
πŸ”₯
MoneyGram confirms hackers stole customer data in cyberattack
πŸ”₯
ADT discloses second breach in 2 months, hacked via stolen credentials
πŸ”₯
Palo Alto Networks and Tata Comms partner for AI-powered managed security
πŸ”₯
American Water Shuts Down Customer Portal Amid Cybersecurty Incident
πŸ”₯
Healthcare Orgs Warned Of Trinity Ransomware Attacks
πŸ”₯
Casio reports IT systems failure after weekend network breach
πŸ”₯
Healthcare Organizations Warned of Trinity Ransomware Attacks
πŸ”₯
European govt air-gapped systems breached using custom malware
πŸ”₯
MoneyGram Money Transfer Firm Reports Customer Data Breach
πŸ”₯
European govt air-gapped systems breached using custom malware
πŸ”₯
EU Strengthens Sanctions Against Russian Hackers
πŸ•΅οΈ
ISC Stormcast For Tuesday, October 8th, 2024 https://isc.sans.edu/podcastdetail/9170, (Tue, Oct 8th)
πŸ•΅οΈ
Google Blocked Malicious Sideloading Apps for Indian Users
πŸ•΅οΈ
Malicious Chrome Add-ons Evade Google's Updated Security
πŸ•΅οΈ
Hackers Gained Unauthorized Network Access to Casio Networks
πŸ•΅οΈ
Microsoft: Word deletes some documents instead of saving them
πŸ•΅οΈ
Is AI saving jobs… or taking them?
πŸ•΅οΈ
Palo Alto Networks Joins EU AI Pact for a Secure Digital Future
πŸ•΅οΈ
CyberheistNews Vol 14 #41 [Wake-Up Call] Senator Falls Victim to Deepfake Scam. Are Your Users Next?
πŸ•΅οΈ
[Cybersecurity Awareness Month] Keeping Your Mobile Devices Secure from the β€˜Inside’ Out
πŸ•΅οΈ
Cybersecurity best practices are the worst, AI indegestion, real time doxxing - ESW #378
πŸ•΅οΈ
Likho Hackers Using MeshCentral For Remotely Managing Victim Systems
πŸ•΅οΈ
Badge and CyberArk Announce Partnership to Redefine Privacy in PAM and Secrets Management
πŸ•΅οΈ
Give CISOs a Seat at the Table as CISO Salaries Surge - BSW #367
πŸ•΅οΈ
Aryaka brings CASB into unified SASE fold
πŸ•΅οΈ
AI, American Water, Broadband, Claroty, Okta, Meta, Phishing, Robocop, Josh Marpet... - SWN #420
πŸ•΅οΈ
MI5 Chief Warns of Cyberthreats to the UK
πŸ•΅οΈ
Uniklinik Frankfurt nach 10 Monaten wieder online erreichbar
πŸ•΅οΈ
File hosting services misused for identity phishing
🌐
Ukrainian Malware Operator Pleads Guilty In US Court
🌐
Gamers Tricked Into Downloading Lua-Based Malware via Fake Cheating Script Engines
πŸŽ™οΈ
The AI Fix #19: AI spy specs, robot dogs with ladders, and is it AI or the climate?
πŸ“‘
Microsoft Edge begins testing Copilot Vision
πŸ“‘
Sophos Firewall: New XGS Series Desktop Firewalls and SFOS v21
πŸ“‘
Trust and trustworthiness in the internet of things | Kaspersky official blog
πŸ“‘
New Case Study: The Evil Twin Checkout Page
πŸ“‘
The Value of AI-Powered Identity
πŸ“‘
Okta Classic Customers Told To Check Logs For Sign-On Bypass
πŸ“‘
You Might Have The Skills That Cyber-Security Wants
πŸ“‘
Kasperksy says it’s closing down its UK office and laying off dozens
πŸ“‘
Windows 11 KB5044284 and KB5044285 cumulative updates released
πŸ“‘
Harnessing AI for Enhanced Security
πŸ“‘
New Mamba 2FA bypass service targets Microsoft 365 accounts
πŸ“‘
Microsoft: Windows 11 22H2 Home and Pro reached end of servicing
πŸ“‘
Cyber insurance, human risk, and the potential for cyber-ratings