CISA has issued an urgent alert about critical vulnerabilities being exploited in Synacor’s Zimbra Collaboration and Ivanti’s Endpoint Manager (EPM). Organizations using these products are urged to mitigate potential risks immediately.
CVE-2024-45519: Synacor Zimbra Collaboration Command Execution Vulnerability:
By infosecbulletin
/ Saturday , November 2 2024
GitHub has launched an AI tool called 'Spark' that allows users to create apps using natural language, eliminating the need...
Read More
By infosecbulletin
/ Friday , November 1 2024
"A threat actor has reportedly claimed to gain root-level access to Titas Gas’s firewall server and is actively offering this...
Read More
By infosecbulletin
/ Friday , November 1 2024
Zimperium researchers have found a new version of FakeCall malware for Android that threatens financial security. This malware redirects users'...
Read More
By infosecbulletin
/ Friday , November 1 2024
Hikvision, a top provider of network cameras, has issued firmware updates to fix a security vulnerability that could reveal users'...
Read More
By infosecbulletin
/ Friday , November 1 2024
Global threat actors have significantly increased attacks on government sectors, with malware-driven attempts rising by triple digits in the first...
Read More
By infosecbulletin
/ Thursday , October 31 2024
Meetup of Bangladesh Kubernetes User Group was held at Banani Club 9294, Dhaka on Thursday, 31 October 2024. A lively...
Read More
By infosecbulletin
/ Thursday , October 31 2024
Bangladesh Bank issues alert on cyber threat. In its alert the central bank said, according to Bangladesh cyber security intelligence...
Read More
By infosecbulletin
/ Thursday , October 31 2024
Interbank, a major financial institution in Peru, has confirmed a data breach after a hacker leaked stolen data online. Formerly...
Read More
By infosecbulletin
/ Wednesday , October 30 2024
The US Cybersecurity and Infrastructure Security Agency (CISA) has released its first international strategic plan to enhance global cooperation in...
Read More
By infosecbulletin
/ Tuesday , October 29 2024
The Indian Cyber Crime Coordination Centre (I4C) has warned about illegal payment gateways set up by transnational cyber criminals using...
Read More
A new vulnerability, CVE-2024-45519, has been found in the Synacor Zimbra Collaboration platform. It affects the postjournal service and could let unauthenticated users run commands remotely.
It’s unclear if this vulnerability has been used in ransomware attacks, but the risk of misuse is high. Organizations using Zimbra Collaboration should follow the mitigation recommendations from Synacor.
If mitigations are not available, it’s strongly advised to stop using the product. CISA has set a deadline for remediation by October 24, 2024, highlighting the urgency.
CVE-2024-29824: Ivanti Endpoint Manager SQL Injection Vulnerability:
The Ivanti Endpoint Manager (EPM) is at risk because of a SQL injection vulnerability called CVE-2024-29824.
This vulnerability lets unauthenticated attackers on the same network execute arbitrary code on the Core server. Like the Zimbra issue, there’s no evidence of it being exploited in ransomware attacks yet, but the risk is still significant.
Ivanti has provided guidance to address this vulnerability, and organizations should follow it quickly. The deadline to implement these measures is October 23, 2024.
CISA’s alert emphasizes the serious nature of these vulnerabilities and their potential global impact on organizations.
Synacor and Ivanti emphasize the need for quick action to safeguard sensitive data and ensure operational integrity.