Friday , November 22 2024

infosecbulletin

NGINX Ingress Controller
Vulnerabilities Uncovered in NGINX Ingress Controller for Kubernetes

Three unpatched security flaws in the NGINX Ingress controller for Kubernetes have been revealed. These flaws have a high severity level and could be used by a malicious actor to steal secret credentials from the cluster. The vulnerabilities are as follows: CVE-2022-4886 (CVSS score: 8.8) – Ingress-nginx path sanitization can …

Read More »

Submarine Cable Upgradation
Internet to face disruption around 20 hours on Oct 31, Nov 2

Internet services will face partial disruption in the country for around 20 hours on October 31 and November 2. This is because the country’s first submarine cable will be partially disconnected for an upgrade. The circuits through the South East Asia-Middle East-Western Europe 4 (SEA-ME-WE 4) submarine cable installed Cox’s …

Read More »

BDSAF hold day-long cyber symposium at Dhaka today

Bangladesh System Administrators Forum (BDSAF) organized a day-long IT security conference titled “Cyber Security Symposium 2023”. Symposium was held on October 28, at “Brac In” auditorium on various important issues of information technology security and cyber awareness. Md. Shamsul Arefin, secretary of information and technology division, was the chief guest …

Read More »

F5 warning customer: BIG-IP Vulnerability Allows Remote Code Execution

F5 warned customers about a serious security flaw in BIG-IP that may lead to unauthorized remote code execution. An issue has been identified in the configuration utility component. It is assigned the CVE identifier CVE-2023-46747 and has a CVSS score of 9.8 out of 10. F5 has stated that an …

Read More »

CISCO Zero-Day Vulnerabilities exploitation in Bangladesh

The Cyber Threat Intelligence team of BGD e-GOV CIRT has issued a warning about ongoing attacks using two zero-day vulnerabilities in Cisco’s IOS XE Software web UI feature. Successful exploitation attempts have been observed against organizations in Bangladesh. This advisory is intended for IT teams responsible for configuring and managing …

Read More »

VMware released update for PoC exploits Vulnerabilities

Multiple vulnerabilities in VMware Aria Operations for Logs were privately reported to VMware. VMware Aria Operations for Logs contains an authentication bypass vulnerability VMware has evaluated the severity of this issue to be in the Important Severity Range with a maximum CVSSv3 base score of 8.1. An unauthenticated, malicious actor …

Read More »

NCC GROUP REPORT
September faced a record ransomware attack in 2023

Ransomware activity soared in September after a temporary decrease in August, which was still higher than usual for summer. In September, ransomware groups conducted 514 attacks, surpassing the 459 attacks recorded in March 2023 according to NCC group cyber threat intelligence report. The March attacks were mainly caused by the …

Read More »