๐ด Tesla, SpaceX Parts Manufacturer Suffers Data Breach ๐ด
๐ Read
via "Dark Reading: ".
Visser Precision has confirmed a security incident likely caused by the data-stealing DoppelPaymer ransomware.๐ Read
via "Dark Reading: ".
Darkreading
Tesla, SpaceX Parts Manufacturer Suffers Data Breach
Visser Precision has confirmed a security incident likely caused by the data-stealing DoppelPaymer ransomware.
ATENTIONโผ New - CVE-2019-12183
๐ Read
via "National Vulnerability Database".
Incorrect Access Control in Safescan Timemoto TM-616 and TA-8000 series allows remote attackers to read any file via the administrative API.๐ Read
via "National Vulnerability Database".
ATENTIONโผ New - CVE-2017-12580
๐ Read
via "National Vulnerability Database".
An issue was discovered in IDM UltraEdit through 24.10.0.32. To exploit the vulnerability, on unpatched Windows systems, an attacker could include in the same directory as the affected executable a DLL using the name of a Windows DLL. This DLL must be preloaded by the executable (for example, "ntmarta.dll"). When the installer EXE is executed by the user, the DLL located in the EXE's current directory will be loaded instead of the Windows DLL, allowing the attacker to run arbitrary code on the affected system.๐ Read
via "National Vulnerability Database".
ATENTIONโผ New - CVE-2015-1583
๐ Read
via "National Vulnerability Database".
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account via a request to mods/_core/users/admins/create.php or (2) create a user account via a request to mods/_core/users/create_user.php.๐ Read
via "National Vulnerability Database".
โ RSAC: Keeping Smart Cities Safe From Hacks โ
๐ Read
via "Threatpost".
As cities grow more connected, municipal operators must deal with new risks like ransomware, IoT hacks and more.๐ Read
via "Threatpost".
Threat Post
Forrester: Keeping Smart Cities Safe From Hacks
As cities grow more connected, municipal operators must deal with new risks like ransomware, IoT hacks and more.
๐ Companies Increasingly Complacent Around Data Breach Preparedness ๐
๐ Read
via "Subscriber Blog RSS Feed ".
Ponemon Institute's annual data breach readiness survey suggests the increased adoption of security technologies but the continuation of problems, like spear phishing attacks.๐ Read
via "Subscriber Blog RSS Feed ".
Digital Guardian
Companies Increasingly Complacent Around Data Breach Preparedness
Ponemon Institute's annual data breach readiness survey suggests the increased adoption of security technologies but the continuation of problems, like spear phishing attacks.
ATENTIONโผ New - CVE-2019-14892
๐ Read
via "National Vulnerability Database".
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.๐ Read
via "National Vulnerability Database".
ATENTIONโผ New - CVE-2018-14384
๐ Read
via "National Vulnerability Database".
The Website Manager module in SEO Panel 3.13.0 and earlier is affected by a stored Cross-Site Scripting (XSS) vulnerability, allowing remote authenticated attackers to inject arbitrary web script or HTML via the websites.php name parameter.๐ Read
via "National Vulnerability Database".
ATENTIONโผ New - CVE-2018-11675
๐ Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.๐ Read
via "National Vulnerability Database".
๐ Report: Coronavirus is negatively impacting international call quality ๐
๐ Read
via "Security on TechRepublic".
When entire regions are quarantined, home-bound people are overloading local switches, reducing international call quality and interrupting connectivity.๐ Read
via "Security on TechRepublic".
TechRepublic
Coronavirus is negatively impacting international call quality
When entire regions are quarantined, home-bound people are overloading local switches, reducing international call quality and interrupting connectivity.
๐ด Walgreens' Mobile App Exposes Customers' Info ๐ด
๐ Read
via "Dark Reading: ".
An error in the app allowed some secure chat users to see medical information that wasn't theirs.๐ Read
via "Dark Reading: ".
Darkreading
Walgreens' Mobile App Exposes Customers' Info
An error in the app allowed some secure chat users to see medical information that wasn't theirs.
ATENTIONโผ New - CVE-2018-19658
๐ Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.๐ Read
via "National Vulnerability Database".
ATENTIONโผ New - CVE-2018-19599
๐ Read
via "National Vulnerability Database".
Monstra CMS 1.6 allows XSS via an uploaded SVG document to the admin/index.php?id=filesmanager&path=uploads/ URI. NOTE: this is a discontinued product.๐ Read
via "National Vulnerability Database".
ATENTIONโผ New - CVE-2018-19284
๐ Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.๐ Read
via "National Vulnerability Database".
ATENTIONโผ New - CVE-2018-18479
๐ Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.๐ Read
via "National Vulnerability Database".
ATENTIONโผ New - CVE-2018-17572
๐ Read
via "National Vulnerability Database".
InfluxDB 0.9.5 has Reflected XSS in the Write Data module.๐ Read
via "National Vulnerability Database".
ATENTIONโผ New - CVE-2018-16357
๐ Read
via "National Vulnerability Database".
An issue was discovered in PbootCMS. There is a SQL injection via the api.php/Cms/search order parameter.๐ Read
via "National Vulnerability Database".
ATENTIONโผ New - CVE-2018-16356
๐ Read
via "National Vulnerability Database".
An issue was discovered in PbootCMS. There is a SQL injection via the api.php/List/index order parameter.๐ Read
via "National Vulnerability Database".
ATENTIONโผ New - CVE-2018-15820
๐ Read
via "National Vulnerability Database".
EasyIO EasyIO-30P devices before 2.0.5.27 allow XSS via the dev.htm GDN parameter.๐ Read
via "National Vulnerability Database".
ATENTIONโผ New - CVE-2018-15819
๐ Read
via "National Vulnerability Database".
EasyIO EasyIO-30P devices before 2.0.5.27 have Incorrect Access Control, related to webuser.js.๐ Read
via "National Vulnerability Database".