Sunday , February 23 2025

TimeLine Layout

May, 2024

  • 31 May

    ALERT
    NGINX Releases Security Updates: HTTP/3 Vulnerabilities Patched

    NGINX

    NGINX team released important updates for their web server software and is advising users to upgrade as soon as possible. The updates fix four important vulnerabilities in the HTTP/3 implementation, especially affecting configurations using the “ngx_http_v3_module.” CVE-2024-32760: A vulnerability in NGINX Plus or NGINX OSS causes HTTP/3 QUIC module to …

    Read More »
  • 31 May

    CISA Releases Seven Industrial Control Systems Advisories

    ics

    On May 30, 2024, CISA published seven advisories about Industrial Control Systems (ICS). These advisories share important information regarding security issues, vulnerabilities, and exploits related to ICS. ICSA-24-151-01 LenelS2 NetBox ICSA-24-151-02 Fuji Electric Monitouch V-SFT ICSA-24-151-03 Inosoft VisiWin ICSA-24-151-04 Westermo EDW-100 ICSA-22-356-03 Mitsubishi Electric MELSEC iQ-R, iQ-L Series and MELIPC …

    Read More »
  • 31 May

    CISA Alerts Federal Agencies to Patch Actively Exploited Linux Kernel Flaw

    CISA added a security flaw in the Linux kernel to the KEV catalog. This flaw is being actively exploited. The CVE-2024-1086 (CVSS score: 7.8) is a high-severity issue. It is related to a use-after-free bug in the netfilter component. This bug allows a local attacker to gain root privileges from …

    Read More »
  • 30 May

    Business Leaders & Celebrities’ Accounts Exposed

    phone

    Jeremiah Fowler, a cybersecurity researcher, found and informed WebsitePlanet about a database without password protection. It held around 121,000 user accounts of entrepreneurs and business leaders from Clarity.fm, a platform for connecting entrepreneurs with experts. The database had 155,531 records, including 121,000 member profiles with personal and professional email addresses, …

    Read More »
  • 30 May

    Hacker Claim to compromise over 15 Asian telecom

    tower

    A large dataset belonging to BSNL, an Indian state-owned telecommunications company, has been put up for sale by cybercriminals on an underground forum. On May 27, 2024, it was discovered that “kiberphant0m” was selling unauthorized access to databases stolen from BSNL, as well as data from other Asian telecom companies …

    Read More »
  • 29 May

    Check Point released emergency fix for VPN vulnerability

    check point

    Check Point has released hotfixes for a VPN vulnerability used in attacks to gain remote access to firewalls and try to breach corporate networks. On Monday, the company warned about an increase in attacks on VPN devices and provided recommendations on how admins can protect their devices. The CVE-2024-24919 vulnerability …

    Read More »
  • 29 May

    First American December data breach impacts 44,000 people

    In December 2023, The First American Financial Corporation, a major title insurance company in the US, experienced a cyberattack. This resulted in the personal information of approximately 44,000 individuals being exposed. The company disclosed this data breach to the US Securities and Exchange Commission (SEC) on May 28, 2024. This …

    Read More »
  • 29 May

    Exploit released for maximum severity RCE In FORTINET SIEM

    fortinet

    Researchers released a proof-of-concept (PoC) exploit for remote code execution flaw CVE-2024-23108 in Fortinet SIEM solution. Horizon3’s Attack Team released a demonstration of a security vulnerability, identified as CVE-2024-23108, in Fortinet’s SIEM solution. This vulnerability allows attackers to run commands as the most powerful user on publicly accessible FortiSIEM devices. …

    Read More »
  • 29 May

    Bangladeshi app “Boithok” got WSIS award 2024

    picture

    State Minister for Posts, Telecommunications and Information Technology Zunaid Ahmed Palak received the award in Geneva, Switzerland, winner of the World Summit on Information Society (WSIS) Award-2024, one of the awards in the information and technology sector in the international arena. This year, he received this award as the winner …

    Read More »
  • 29 May

    CISA Releases One Industrial Control Systems Advisory

    cyber

    CISA published an advisory on May 28, 2024, about Industrial Control Systems (ICS). They share important information about security issues, vulnerabilities, and exploits related to ICS. ICSA-24-149-01 Campbell Scientific CSI Web Server: The Campbell Scientific CSI Web Server supports a command that will return the most recent file that matches …

    Read More »