Tuesday , December 24 2024

infosecbulletin

Multiple TP-Link Omada Vulnerabilities found

TP link

Several vulnerabilities have been found in the TP-Link Omada system, which is a popular software-defined networking solution for small to medium-sized businesses. The vulnerabilities could let attackers run code from a distance, causing serious security issues. The affected devices are wireless access points, routers, switches, VPN devices, and hardware controllers …

Read More »

Evolve Bank Confirms Data Breach, Customer Info Exposed

Evolve Bank & Trust

Evolve Bank & Trust experienced a cybersecurity incident. The bank confirmed that cybercriminals obtained and shared customers’ personal information on the dark web. This data breach affected both retail bank customers and customers of Evolve’s financial technology partners. Evolve Bank was hacked by a cybercriminal group that stole and shared …

Read More »

BSNL Data Breach: Data worth 278GB leaked: Report claim

BSNL

According to digital risk management firm Athenian Technology, BSNL, India’s state-owned telecom provider, suffered a significant data breach. A cybercriminal named “kiberphant0m” performed the attack, resulting in the exposure of a large amount of sensitive data. This puts millions of users at risk. Zee news reported, Kanishk Gaur, CEO of …

Read More »

CISA issued two advisories for industrial control systems

ics

CISA released two advisories about Industrial Control Systems (ICS) on June 25, 2024. The advisories contain important information about security issues, vulnerabilities, and exploits related to ICS. ICSA-24-177-01 ABB Ability System 800xA: Successful exploitation of these vulnerabilities could cause services to crash and restart. ICSA-24-177-02 PTC Creo Elements/Direct License Server: …

Read More »

Indonesia’s National data center compromised, $8M ransom demand

Data center

Cyber attack compromised Indonesia’s national data center, causing trouble with immigration checks at airports. Attacker demanded an $8 million ransom, Reuters reported. The attack caused problems for government services, especially at airports, with long lines at immigration desks. The communications ministry said that automated passport machines are now working. Minister …

Read More »

ESET Issues Security Patch for Privilege Escalation Flaw

eset

ESET Issued security patch for privilege escalation flaw in its Windows security products. This flaw, called CVE-2024-2003 (CVSS 7.3), was found by the Zero Day Initiative (ZDI). It could have let attackers gain access to important files and folders without permission. The vulnerability exploited ESET’s file operations while restoring quarantined …

Read More »