News - Vulnerabilities
-
Progress Q3 2024 Earnings Exceed Estimates with ShareFile Acquisition Plans -
VU#455367: Insecure Platform Key (PK) used in UEFI system firmware signature
Overview A vulnerability in the user of hard-coded Platform Keys (PK) within the UEFI framework, known as PKfail, has been discovered. This flaw allows attackers to bypass critical UEFI -
VU#244112: Multiple SMTP services are susceptible to spoofing attacks due to insufficient enforcement
Overview Multiple hosted, outbound SMTP servers are vulnerable to email impersonation. This allows authenticated users and certain trusted networks to send emails containing spoofed sender information. Two vulnerabilities were -
VU#456537: RADIUS protocol susceptible to forgery attacks.
Overview A vulnerability in the RADIUS protocol allows an attacker allows an attacker to forge an authentication response in cases where a Message-Authenticator attribute is not required or enforced. -
Snowflake denies claim linking it to Ticketmaster, Santander hacks
“We have not identified evidence suggesting this activity was caused by a vulnerability, misconfiguration or breach of Snowflake’s platform,” Snowflake said
-
How Illumio microsegmentation and Netskope ZTNA integration 'gets zero trust covered'
The partnership may further broaden to the security services edge and secure access service edge space in the future
-
68 tech and security titans commit to building secure software
Amazon Web Services, Cisco, Google and Microsoft are among companies that have signed Cybersecurity and Infrastructure Security Agency Secure by Design pledge
-
CrowdStrike's ‘safety net’ catches the breaches that Microsoft Defender misses
“We are doing this primarily because customers that who are just purely running Microsoft are unable to stop the breach to keep their estates safe,” CrowdStrike's Raj Rajamani said.
-
VU#163057: BMC software fails to validate IPMI session.
Overview The Intelligent Platform Management Interface (IPMI) implementations in multiple manufacturer's Baseboard Management Controller (BMC) software are vulnerable to IPMI session hijacking. An attacker with access to the BMC -
Akamai combines ZTNA, microsegmentation, MFA into zero-trust platform
The Akamai Guardicore Platform uses generative artificial intelligence to streamline the zero-trust implementation.
-
Siemens product impacted by Palo Alto Networks firewall vulnerability
The vulnerability (CVE-2024-3400) has the highest severity score of 10.0 on the Common Vulnerability Scoring System.
-
Comcast launches MDR for enterprises, taps Rapid7’s SecOps
The solution combines Comcast Business’s security services with Rapid7’s security operations platform and expertise.
-
Red Hat builds DevSecOps trust in the software supply chain
The updates to Red Hat Trusted Software Supply Chain improve IT teams’ ability to embed security into the application development lifecycle. -
Cisco redesigns data center security in AI era, calls Hypershield its 'most consequential security innovation'
The Cisco Hypershield is “probably the most consequential security innovation we have done in the 40 years that Cisco has been around,” EVP Jeetu Patel said
-
VU#253266: Keras 2 Lambda Layers Allow Arbitrary Code Injection in TensorFlow Models
Overview Lambda Layers in third party TensorFlow-based Keras models allow attackers to inject arbitrary code into versions built prior to Keras 2.13 that may then unsafely run with the -
OpenSSF, CISA, Homeland Security team to boost software supply chain security
Protobom is an open source tool that simplifies creating, reading and translating software bill of materials data across various industry standard formats. -
DDoS attacks jump by 50% to start 2024
Cloudflare mitigated 4.5 million distributed denial of service attacks in the first three months of the year, equal to a third of all DDoS attacks in 2023. -
VU#123335: Multiple Programming Languages Fail to Escape Arguments Properly in Microsoft Windows
Overview Various programming languages lack proper validation mechanisms for commands and in some cases also fail to escape arguments correctly when invoking commands within a Microsoft Windows environment. The -
VU#155143: Linux kernel on Intel systems is susceptible to Spectre v2 attacks
Overview A new cross-privilege Spectre v2 vulnerability that impacts modern CPU architectures supporting speculative execution has been discovered. CPU hardware utilizing speculative execution that are vulnerable to Spectre v2 -
Google Cloud brings Gemini genAI to security services
The cloud provider integrates Gemini with its security operations, threat intelligence and Security Command Center services. -
VU#421644: HTTP/2 CONTINUATION frames can be utilized for DoS attacks
Overview HTTP allows messages to include named fields in both header and trailer sections. These header and trailer fields are serialised as field blocks in HTTP/2, so that they -
VU#417980: UDP-based, application-layer protocol implementations are vulnerable to network loops
Overview A novel traffic-loop vulnerability has been identified against certain implementations of UDP-based applications protocols. An unauthenticated attacker can use maliciously-crafted packets against a UDP-based vulnerable implementation of application -
Fortinet discloses 5 critical and high severity vulnerabilities
The Cybersecurity and Infrastructure Security Agency urges users and administrators to review Fortinet's advisories and apply necessary updates. -
Zscaler buys Avalor for AI-enabled security analytics
The deal, reportedly valued at $350 million, closed on March 13