Saturday , October 19 2024

infosecbulletin

CISA Adds Two Known Exploited Vulnerabilities to Catalog

cisa

CISA added 2 new vulnerabilities to its catalog of known exploited vulnerabilities, because they have proof that these vulnerabilities are being actively exploited. CVE-2024-4610 ARM Mali GPU Kernel Driver Use-After-Free Vulnerability:  Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a …

Read More »

Hackers breached 20,000 FortiGate systems worldwide: MIVD

laptop

The Dutch military security service MIVD recently revealed that a cyber espionage campaign, which was initially mentioned in February, managed to gain access to around 20,000 Fortigate-secured systems between 2022 and 2023. It is now believed that this campaign “appears to be much more extensive than previously known”. The Nationaal Cyber Security …

Read More »

Riskiest Connected Devices in 2024: Forescout Report

iot

By 2028, there will be over 25 billion Internet of Things (IoT) devices. Attackers are increasingly targeting various devices, operating systems, and firmware to gain access. Forescout Technologies, a cybersecurity leader, has released a report called “The Riskiest Connected Devices in 2024.” The report is based on data from 19 million …

Read More »

Singapore-Based Absolute Telecom Allegedly Hit by Cyberattack

GhostR hacker claimed to hack Absolute Telecom PTE Ltd, a Singapore-based telecom company and stole 34 gigabytes of data including corporate information, accounting records, sales data, customer details, credit card information, and call records. In a post the bad actor claimed they infiltrated and compromised the company’s server networks on …

Read More »

SSRF Vulnerability Patched in Bitdefender GravityZone Console On-Premise

Bitdefender

Bitdefender fixed a serious vulnerability (CVE-2024-4177, CVSS 8.1) in its GravityZone Console On-Premise product. This flaw, found by security researcher Nicolas Verdier (n1nj4sec), could enable attackers to carry out server-side request forgery (SSRF) attacks, possibly resulting in unauthorized access and data breaches. GravityZone Console is a security management platform by …

Read More »