Saturday , October 19 2024

infosecbulletin

Indonesia’s National data center compromised, $8M ransom demand

Data center

Cyber attack compromised Indonesia’s national data center, causing trouble with immigration checks at airports. Attacker demanded an $8 million ransom, Reuters reported. The attack caused problems for government services, especially at airports, with long lines at immigration desks. The communications ministry said that automated passport machines are now working. Minister …

Read More »

ESET Issues Security Patch for Privilege Escalation Flaw

eset

ESET Issued security patch for privilege escalation flaw in its Windows security products. This flaw, called CVE-2024-2003 (CVSS 7.3), was found by the Zero Day Initiative (ZDI). It could have let attackers gain access to important files and folders without permission. The vulnerability exploited ESET’s file operations while restoring quarantined …

Read More »

Azad selected expert reviewer for CISA Review Manual 28th Edition

cisa

Certified Information Systems Auditor (CISA) is a globally recognized professional certification for information systems audit, control, and security. It’s offered by ISACA (Information Systems Audit and Control Association). CISA holders demonstrate expertise in assessing an organization’s IT controls and processes to identify and manage risks. The CISA Review Manual, 28th …

Read More »

CISA released Guidance for Modern Approaches to Network Access Security

network

CISA and the FBI released guidance, Modern Approaches to Network Access Security, with support from other organizations including New Zealand’s GCSB, CERT-NZ, and the Canadian CCCS. Business owners of all sizes are encouraged to adopt stronger security solutions like Zero Trust, Secure Service Edge (SSE), and Secure Access Service Edge …

Read More »

CISA Releases One Industrial Control Systems Advisory

ics

On June 18, 2024, CISA released an advisory about Industrial Control Systems (ICS). These advisories give important information about security issues, vulnerabilities, and exploits related to ICS. ICSA-24-170-01 RAD Data Communications SecFlow-2: Successful exploitation of this vulnerability could allow an attacker to obtain files from the operating system by crafting …

Read More »

VMware Patche vCenter Server, Cloud Foundation and vSphere ESXi

VMware

VMware has fixed critical security flaws in Cloud Foundation, vCenter Server, and vSphere ESXi. These flaws could be used for privilege escalation and remote code execution. Vulnerabilities include: CVE-2024-37079 & CVE-2024-37080 (CVSS scores: 9.8): Multiple heap-overflow vulnerabilities in the implementation of the DCE/RPC protocol that could allow an unauthorized individual …

Read More »