Category: Uncategorized
-
Adobe ColdFusion Vulnerability Exploited in Attacks on US Government Agency Eduard Kovacs
US government agency was targeted in attacks that involved exploitation of an Adobe ColdFusion vulnerability tracked as CVE-2023-26360. The post Adobe ColdFusion Vulnerability Exploited in Attacks on US Government Agency appeared first on SecurityWeek. Read More
-
CISA Urges Federal Agencies to Patch Exploited Qualcomm Vulnerabilities Ionut Arghire
CISA has added to its Known Exploited Vulnerabilities Catalog four Qualcomm bugs, including three exploited as zero-days. The post CISA Urges Federal Agencies to Patch Exploited Qualcomm Vulnerabilities appeared first on SecurityWeek. Read More
-

New Report: Unveiling the Threat of Malicious Browser Extensions [email protected] (The Hacker News)
Compromising the browser is a high-return target for adversaries. Browser extensions, which are small software modules that are added to the browser and can enhance browsing experiences, have become a popular browser attack vector. This is because they are widely adopted among users and can easily turn malicious through developer actions or attacks on legitimate…
-

Sierra:21 – Flaws in Sierra Wireless Routers Expose Critical Sectors to Cyber Attacks [email protected] (The Hacker News)
A collection of 21 security flaws have been discovered in Sierra Wireless AirLink cellular routers and open-source software components like TinyXML and OpenNDS. Collectively tracked as Sierra:21, the issues expose over 86,000 devices across critical sectors like energy, healthcare, waste management, retail, emergency services, and vehicle tracking to cyber threats, accordingRead More
-
5 Critical Steps to Prepare for AI-Powered Malware in Your Connected Asset Ecosystem Rik Ferguson
AI-powered attacks will become progressively more common, and a well-rounded security approach involves more than simply managing incidents effectively. The post 5 Critical Steps to Prepare for AI-Powered Malware in Your Connected Asset Ecosystem appeared first on SecurityWeek. Read More
-
Virtual Event Today: Cyber AI & Automation Summit SecurityWeek News
Virtual conference on December 6th will explore cybersecurity use-cases for artificial intelligence (AI) technology and the race to protect LLM algorithms from adversarial use. The post Virtual Event Today: Cyber AI & Automation Summit appeared first on SecurityWeek. Read More
-

Scaling Security Operations with Automation [email protected] (The Hacker News)
In an increasingly complex and fast-paced digital landscape, organizations strive to protect themselves from various security threats. However, limited resources often hinder security teams when combatting these threats, making it difficult to keep up with the growing number of security incidents and alerts. Implementing automation throughout security operations helps security teams alleviateRead More
-

Hackers Exploited ColdFusion Vulnerability to Breach Federal Agency Servers [email protected] (The Hacker News)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation of a high-severity Adobe ColdFusion vulnerability by unidentified threat actors to gain initial access to government servers. “The vulnerability in ColdFusion (CVE-2023-26360) presents as an improper access control issue and exploitation of this CVE can result in arbitrary code execution,”Read More
-
21 Vulnerabilities in Sierra Wireless Routers Could Expose Critical Infrastructure to Attacks Eduard Kovacs
Forescout has found 21 vulnerabilities in Sierra Wireless OT/IoT routers that could expose critical infrastructure organizations to remote attacks. The post 21 Vulnerabilities in Sierra Wireless Routers Could Expose Critical Infrastructure to Attacks appeared first on SecurityWeek. Read More
-

Atlassian Releases Critical Software Fixes to Prevent Remote Code Execution [email protected] (The Hacker News)
Atlassian has released software fixes to address four critical flaws in its software that, if successfully exploited, could result in remote code execution. The list of vulnerabilities is below – CVE-2022-1471 (CVSS score: 9.8) – Deserialization vulnerability in SnakeYAML library that can lead to remote code execution in multiple products CVE-2023-22522 (CVSS scoreRead More
