Monday , December 2 2024
Women

CISA Warns of 3 Critical Vulnerabilities in Industrial Control Systems

On November 7, 2024, CISA released advisories about 3 critical security issues, vulnerabilities, and exploits related to Industrial Control Systems (ICS).

ICSA-24-312-01 Beckhoff Automation TwinCAT Package Manager:

Workshop on “DDoS use cases & solutions for government & BFSI” held at BCS

A workshop on "DDoS use cases & solutions for government & BFSI" held at Bangladesh computer society premises on Saturday...
Read More
Workshop on “DDoS use cases & solutions for government & BFSI” held at BCS

Uganda confirms hack of central bank accounts, Refutes $17 Million Claim

Uganda’s finance ministry confirmed media reports that hackers breached the central bank’s systems and stole money, but refuted the claims...
Read More
Uganda confirms hack of central bank accounts, Refutes $17 Million Claim

CVE-2024-11667
Hackers actively exploiting Zyxel firewall to deploy Ransomware

CERT Germany and Zyxel have alerted about a serious vulnerability in Zyxel firewalls, identified as CVE-2024-11667. This flaw is being...
Read More
CVE-2024-11667  Hackers actively exploiting Zyxel firewall to deploy Ransomware

Daily Security Update Dated: 29.11.2024

Every day a lot of cyberattack happen around the world including ransomware, Malware attack, data breaches, website defacement and so...
Read More
Daily Security Update  Dated: 29.11.2024

CIRT-in flags Critical Flaw in Oracle Agile PLM Framework

CERT-In has flagged a security vulnerability in Oracle’s Agile Product Lifecycle Management (PLM) software, identified as CVE-2024-21287 and cataloged as...
Read More
CIRT-in flags Critical Flaw in Oracle Agile PLM Framework

Microsoft patches four vulnerabilities in its services

On November 26th, Microsoft patched four vulnerabilities detected in Dynamics 365 Sales, the Partner.Microsoft.Com portal, Microsoft Copilot Studio and Azure...
Read More
Microsoft patches four vulnerabilities in its services

Data broker exposes 600K+ passwordless sensitive files online

SL Data Services/Propertyrec, an information research provider exposes a non-password-protected database containing more than 600K records according to the security...
Read More
Data broker exposes 600K+ passwordless sensitive files online

Cloudflare logs faces major failure, losing 55% of user data

Cloudflare suffered an incident roughly 3.5 hours On November 14, 2024 impacting the majority of customers using Cloudflare Logs. Cloudflare...
Read More
Cloudflare logs faces major failure, losing 55% of user data

VMware Patched critical flaw in Aria Operations

VMware revealed several critical vulnerabilities in its Aria Operations product, with the most severe allowing attackers to gain root user...
Read More
VMware Patched critical flaw in Aria Operations

HDFC Life hit by data breach, begins investigation

On Monday, Indian HDFC life insurance said, They got some instances of data leaks. "We have received communication from an...
Read More
HDFC Life hit by data breach, begins investigation

CISA has identified a serious vulnerability in Beckhoff Automation’s TwinCAT Package Manager, a key software in manufacturing. The flaw, called CVE-2024-8934, relates to improper handling of special elements, making it susceptible to OS command injection attacks.

This vulnerability allows a local attacker with admin access to execute arbitrary commands, risking the system’s integrity and security.

Beckhoff Automation has released a security update, advising users to upgrade to version 1.0.613.0 to address a vulnerability. CISA also recommends that users check values entered by admins and limit network exposure to control systems to reduce exploitation risks.

ICSA-24-312-02 Delta Electronics DIAScreen:

CISA’s advisories highlighted several stack-based buffer overflow vulnerabilities in Delta Electronics’ DIAScreen equipment, which is mainly used in smart machine engineering and integrated into the DIAStudio Smart Machine Suite.

CVE-2024-47131, CVE-2024-39605, and CVE-2024-39354 are vulnerabilities that allow remote code execution in DIAScreen versions before v1.5.0. Attackers can exploit these to run arbitrary code remotely.

Delta Electronics has released v1.5.0 of DIAScreen and recommends that users update quickly to reduce risks.

ICSA-24-312-03 Bosch Rexroth IndraDrive:

A serious vulnerability in Bosch Rexroth’s IndraDrive equipment, vital for manufacturing, has been revealed by CISA. Known as CVE-2024-48989, it allows attackers to exploit uncontrolled resource consumption, leading to denial-of-service (DoS) attacks. By sending specific UDP messages to devices using the affected PROFINET stack, attackers can render the devices unresponsive, which may disrupt industrial operations.

The vulnerability has a CVSS v3.1 score of 7.5 and a CVSS v4 score of 8.7, indicating a high risk. Bosch Rexroth has not released a specific update, so organizations should take immediate action to reduce risks, such as isolating control systems from internet-facing networks.

CISA urges users to check the latest ICS advisories for important information and solutions.

Check Also

Microsoft

Microsoft patches four vulnerabilities in its services

On November 26th, Microsoft patched four vulnerabilities detected in Dynamics 365 Sales, the Partner.Microsoft.Com portal, …

Leave a Reply

Your email address will not be published. Required fields are marked *