π΄ 2 Years After Colonial Pipeline, US Critical Infrastructure Still Not Ready for Ransomware π΄
π Read
via "Dark Reading".
Sweeping changes implemented since the May 2021 cyberattack are helping -- but more work remains to be done, security experts say.π Read
via "Dark Reading".
Dark Reading
2 Years After Colonial Pipeline, US Critical Infrastructure Still Not Ready for Ransomware
Sweeping changes implemented since the May 2021 cyberattack are helping β but more work remains to be done, security experts say.
π1
βΌ CVE-2023-30242 βΌ
π Read
via "National Vulnerability Database".
NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php.π Read
via "National Vulnerability Database".
π΄ New White House AI Initiatives Include AI Software-Vetting Event at DEF CON π΄
π Read
via "Dark Reading".
The Biden administration outlined its plans to ensure responsible AI development β cyber-risk is a core element.π Read
via "Dark Reading".
Dark Reading
New White House AI Initiatives Include AI Software-Vetting Event at DEF CON
The Biden administration outlined its plans to ensure responsible AI development β cyber-risk is a core element.
βΌ CVE-2022-43919 βΌ
π Read
via "National Vulnerability Database".
IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow an authenticated attacker with authorization to craft messages to cause a denial of service. IBM X-Force ID: 241354.π Read
via "National Vulnerability Database".
βΌ CVE-2023-29935 βΌ
π Read
via "National Vulnerability Database".
llvm-project commit a0138390 was discovered to contain an assertion failure at !replacements.count(op) && "operation was already replaced.π Read
via "National Vulnerability Database".
βΌ CVE-2023-29932 βΌ
π Read
via "National Vulnerability Database".
llvm-project commit fdbc55a5 was discovered to contain a segmentation fault via the component mlir::IROperand<mlir::OpOperand.π Read
via "National Vulnerability Database".
βΌ CVE-2023-22874 βΌ
π Read
via "National Vulnerability Database".
IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when processing configuration files. IBM X-Force ID: 244216.π Read
via "National Vulnerability Database".
βΌ CVE-2023-29934 βΌ
π Read
via "National Vulnerability Database".
llvm-project commit 6c01b5c was discovered to contain a segmentation fault via the component mlir::Type::getDialect().π Read
via "National Vulnerability Database".
βΌ CVE-2023-30053 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection.π Read
via "National Vulnerability Database".
βΌ CVE-2023-29939 βΌ
π Read
via "National Vulnerability Database".
llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::spirv::TargetEnv::TargetEnv(mlir::spirv::TargetEnvAttr).π Read
via "National Vulnerability Database".
βΌ CVE-2023-29941 βΌ
π Read
via "National Vulnerability Database".
llvm-project commit a0138390 was discovered to contain a segmentation fault via the component matchAndRewriteSortOp<mlir::sparse_tensor::SortOp>(mlir::sparse_tensor::SortOp.π Read
via "National Vulnerability Database".
βΌ CVE-2023-29933 βΌ
π Read
via "National Vulnerability Database".
llvm-project commit bd456297 was discovered to contain a segmentation fault via the component mlir::Block::getArgument.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30243 βΌ
π Read
via "National Vulnerability Database".
Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allows access to sensitive information.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30434 βΌ
π Read
via "National Vulnerability Database".
IBM Storage Scale (IBM Spectrum Scale 5.1.0.0 through 5.1.2.9, 5.1.3.0 through 5.1.6.1 and IBM Elastic Storage Systems 6.1.0.0 through 6.1.2.5, 6.1.3.0 through 6.1.6.0) could allow a local user to cause a kernel panic. IBM X-Force ID: 252187.π Read
via "National Vulnerability Database".
βΌ CVE-2023-29942 βΌ
π Read
via "National Vulnerability Database".
llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::Type::isa<mlir::LLVM::LLVMVoidType.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30013 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2023-30054 βΌ
π Read
via "National Vulnerability Database".
TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell through a specially constructed payload.π Read
via "National Vulnerability Database".
βΌ CVE-2022-38707 βΌ
π Read
via "National Vulnerability Database".
IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 234179.π Read
via "National Vulnerability Database".
β S3 Ep133: Apple takes βtight-lippedβ to a whole new level β
π Read
via "Naked Security".
Entertaining, educational, and all in plain English π§ππ Read
via "Naked Security".
Naked Security
S3 Ep133: Apple takes βtight-lippedβ to a whole new level
Entertaining, educational, and all in plain English π§π
β World Password Day: 2 + 2 = 4 β
π Read
via "Naked Security".
We've kept it short and simple, with no sermons, no judgmentalism, no tubthumping... and no BUY NOW buttons. Have a nice day!π Read
via "Naked Security".
Naked Security
World Password Day: 2 + 2 = 4
Weβve kept it short and simple, with no sermons, no judgmentalism, no tubthumpingβ¦ and no BUY NOW buttons. Have a nice day!
β PHP Packagist supply chain poisoned by hacker βlooking for a jobβ β
π Read
via "Naked Security".
I pwned you! Gizza job! You know it makes sense!π Read
via "Naked Security".
Sophos News
Naked Security β Sophos News