vulnerability

Vulnerabilities in ICS: A Detailed Analysis of Recent Security Advisories and Threats 

Vulnerabilities in ICS: A Detailed Analysis of Recent Security Advisories and Threats  2024-12-04 at 16:31 By Cyble Overview  The recent Weekly Industrial Control System Vulnerability Intelligence Report from Cyble Research & Intelligence Labs (CRIL) covers the vulnerabilities disclosed by the Cybersecurity and Infrastructure Security Agency (CISA) from November 26, 2024, to December 02, 2024.   The […]

Vulnerabilities in ICS: A Detailed Analysis of Recent Security Advisories and Threats  Read More »

Australia’s ACSC and ASD Team Up with CISA, NSA, FBI, and International Allies to Protect Communications Infrastructure

Australia’s ACSC and ASD Team Up with CISA, NSA, FBI, and International Allies to Protect Communications Infrastructure 2024-12-04 at 16:18 By Cyble Overview  A coalition of cybersecurity agencies, including the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), Australia’s Australian Signals Directorate (ASD), the Australian Cyber

Australia’s ACSC and ASD Team Up with CISA, NSA, FBI, and International Allies to Protect Communications Infrastructure Read More »

PoC exploit for critical WhatsUp Gold RCE vulnerability released (CVE-2024-8785)

PoC exploit for critical WhatsUp Gold RCE vulnerability released (CVE-2024-8785) 2024-12-04 at 13:38 By Zeljka Zorz Researchers have published a proof-of-concept (PoC) exploit for CVE-2024-8785, a critical remote code execution vulnerability affecting Progress WhatsUp Gold, a popular network monitoring solution for enterprises. CVE-2024-8785 and the PoC exploit CVE-2024-8785 stems from the incorrect use of a

PoC exploit for critical WhatsUp Gold RCE vulnerability released (CVE-2024-8785) Read More »

Veeam plugs serious holes in Service Provider Console (CVE-2024-42448, CVE-2024-42449)

Veeam plugs serious holes in Service Provider Console (CVE-2024-42448, CVE-2024-42449) 2024-12-03 at 19:48 By Zeljka Zorz Veeam has fixed two vulnerabilities in Veeam Service Provider Console (VSPC), one of which (CVE-2024-42448) may allow remote attackers to achieve code exection on the VSPC server machine. The vulnerabilities Veeam Service Provider Console is a cloud-enabled platform that

Veeam plugs serious holes in Service Provider Console (CVE-2024-42448, CVE-2024-42449) Read More »

CISA Releases New List of Known Exploited Vulnerabilities, Urges Immediate Actions 

CISA Releases New List of Known Exploited Vulnerabilities, Urges Immediate Actions  2024-12-02 at 14:15 By Cyble Overview  The Cybersecurity and Infrastructure Security Agency (CISA) has once again emphasized the critical importance of addressing IT vulnerabilities. This week, Cyble has reported multiple vulnerabilities across IT devices based on the findings published in the Known Exploited Vulnerabilities

CISA Releases New List of Known Exploited Vulnerabilities, Urges Immediate Actions  Read More »

Top ICS Vulnerabilities This Week: Schneider Electric, mySCADA, and Automated Logic

Top ICS Vulnerabilities This Week: Schneider Electric, mySCADA, and Automated Logic 2024-11-28 at 13:32 By daksh sharma This week’s Cyble ICS vulnerability report includes critical vulnerabilities like CVE-2024-10575 in Schneider Electric’s EcoStruxure IT Gateway, CVE-2024-47407 in mySCADA myPRO Manager/Runtime, and CVE-2024-8525 in Automated Logic that need urgent patching. Overview Cyble Research and Intelligence Labs (CRIL)

Top ICS Vulnerabilities This Week: Schneider Electric, mySCADA, and Automated Logic Read More »

Researchers reveal exploitable flaws in corporate VPN clients

Researchers reveal exploitable flaws in corporate VPN clients 2024-11-26 at 17:33 By Zeljka Zorz Researchers have discovered vulnerabilities in the update process of Palo Alto Networks (CVE-2024-5921) and SonicWall (CVE-2024-29014) corporate VPN clients that could be exploited to remotely execute code on users’ devices. CVE-2024-5921 CVE-2024-5921 affects various versions of Palo Alto’s GlobalProtect App on

Researchers reveal exploitable flaws in corporate VPN clients Read More »

CERT-In Alert: Multiple Vulnerabilities in Android Impacting Millions of Devices

CERT-In Alert: Multiple Vulnerabilities in Android Impacting Millions of Devices 2024-11-26 at 16:48 By daksh sharma Overview The Computer Emergency Response Team of India (CERT-In) has issued an urgent vulnerability note (CIVN-2024-0349) regarding multiple security flaws in Android. These vulnerabilities, identified as “High” in severity, affect Android versions 12, 12L, 13, 14, and 15, potentially

CERT-In Alert: Multiple Vulnerabilities in Android Impacting Millions of Devices Read More »

CISA Releases Seven Critical ICS Advisories to Address Vulnerabilities in Industrial Control Systems

CISA Releases Seven Critical ICS Advisories to Address Vulnerabilities in Industrial Control Systems 2024-11-26 at 13:03 By daksh sharma Overview The Cybersecurity and Infrastructure Security Agency (CISA) published seven detailed security advisories to address critical vulnerabilities in various Industrial Control Systems (ICS). These advisories cover a range of products, from web-based control servers to automated

CISA Releases Seven Critical ICS Advisories to Address Vulnerabilities in Industrial Control Systems Read More »

Weekly IT Vulnerability Report: Critical Exploits Highlighted in This Week’s Analysis

Weekly IT Vulnerability Report: Critical Exploits Highlighted in This Week’s Analysis 2024-11-25 at 15:04 By daksh sharma Overview Cyble Research and Intelligence Labs (CRIL) analyzed 25 vulnerabilities between November 13 and November 19, 2024, identifying several high-priority threats that security teams must address. This blog also highlights 10 exploit discussions on underground forums, increasing the

Weekly IT Vulnerability Report: Critical Exploits Highlighted in This Week’s Analysis Read More »

Top ICS Vulnerabilities This Week: Siemens, Baxter, and Subnet Solutions

Top ICS Vulnerabilities This Week: Siemens, Baxter, and Subnet Solutions 2024-11-22 at 14:33 By daksh sharma This week’s Cyble ICS vulnerability report includes critical vulnerabilities like CVE-2024-39332 in Siemens, CVE-2024-9834 in Baxter Life2000 Ventilation System, and CVE-2024-45490 in Subnet Solutions that need urgent patching. Overview Cyble Research & Intelligence Labs (CRIL) has analyzed key Industrial

Top ICS Vulnerabilities This Week: Siemens, Baxter, and Subnet Solutions Read More »

German CERT Warns ‘Attacks are Happening,’ Urges PAN-OS Chained Vulnerabilities’ Patching

German CERT Warns ‘Attacks are Happening,’ Urges PAN-OS Chained Vulnerabilities’ Patching 2024-11-21 at 16:18 By daksh sharma Overview The German CERT has raised the alarm bells for the exploitation of chained vulnerabilities, urging users to patch them urgently as hundreds of vulnerable instances remain exposed around the country and the globe. CERT-Bund warned in a

German CERT Warns ‘Attacks are Happening,’ Urges PAN-OS Chained Vulnerabilities’ Patching Read More »

CWE top 25 most dangerous software weaknesses

CWE top 25 most dangerous software weaknesses 2024-11-21 at 07:33 By Help Net Security The CWE list of the 25 most dangerous software weaknesses demonstrates the currently most common and impactful software flaws. Identifying the root causes of these vulnerabilities provides insights to shape investments, policies, and practices that proactively prevent their occurrence. The CWE

CWE top 25 most dangerous software weaknesses Read More »

Apple Rolls Out Urgent Security Updates to Address Actively Exploited Zero-Day Vulnerabilities

Apple Rolls Out Urgent Security Updates to Address Actively Exploited Zero-Day Vulnerabilities 2024-11-20 at 16:54 By daksh sharma Apple has released a new security update to address two zero-day vulnerabilities that have been actively exploited in the wild. The update, released on November 19, 2024, affects iOS, iPadOS, macOS, visionOS, and the Safari browser and

Apple Rolls Out Urgent Security Updates to Address Actively Exploited Zero-Day Vulnerabilities Read More »

CISA Adds Three Critical Vulnerabilities to the Known Exploited Vulnerabilities Catalog

CISA Adds Three Critical Vulnerabilities to the Known Exploited Vulnerabilities Catalog 2024-11-19 at 11:01 By daksh sharma Overview The Cybersecurity and Infrastructure Security Agency (CISA) has recently added three significant vulnerabilities to its Known Exploited Vulnerabilities Catalog (KEV), based on evidence of active exploitation. These vulnerabilities, identified in popular networking and security products, represent a

CISA Adds Three Critical Vulnerabilities to the Known Exploited Vulnerabilities Catalog Read More »

CERT-In Flags Two High-Risk Cisco Vulnerabilities Targeting Key Infrastructure

CERT-In Flags Two High-Risk Cisco Vulnerabilities Targeting Key Infrastructure 2024-11-18 at 13:48 By daksh sharma Overview The Indian Computer Emergency Response Team (CERT-In) has recently added two Cisco vulnerabilities to its catalog. Both vulnerabilities target Cisco products, with high severity ratings and potential for impacts on the confidentiality, integrity, and availability of affected systems.  The

CERT-In Flags Two High-Risk Cisco Vulnerabilities Targeting Key Infrastructure Read More »

CISA Adds Two Critical Palo Alto Networks Vulnerabilities to Known Exploited Catalog

CISA Adds Two Critical Palo Alto Networks Vulnerabilities to Known Exploited Catalog 2024-11-18 at 09:33 By daksh sharma Overview The Cybersecurity and Infrastructure Security Agency (CISA) has officially added two high-severity vulnerabilities affecting Palo Alto Networks Expedition to its Known Exploited Vulnerability (KEV) Catalog. The two Palo Alto Networks vulnerabilities, which are actively being targeted

CISA Adds Two Critical Palo Alto Networks Vulnerabilities to Known Exploited Catalog Read More »

How a Windows zero-day was exploited in the wild for months (CVE-2024-43451)

How a Windows zero-day was exploited in the wild for months (CVE-2024-43451) 2024-11-14 at 12:02 By Zeljka Zorz CVE-2024-43451, a Windows zero-day vulnerability for which Microsoft released a fix on November 2024 Patch Tuesday, has been exploited since at least April 2024, ClearSky researchers have revealed. About the vulnerability CVE-2024-43451 affects all supported Windows versions

How a Windows zero-day was exploited in the wild for months (CVE-2024-43451) Read More »

Zero-days dominate top frequently exploited vulnerabilities

Zero-days dominate top frequently exploited vulnerabilities 2024-11-14 at 07:03 By Mirko Zorz A joint report by leading cybersecurity agencies from the U.S., UK, Canada, Australia, and New Zealand has identified the most commonly exploited vulnerabilities of 2023. Zero-day vulnerabilities on the rise The advisory highlights that malicious cyber actors increasingly targeted zero-day vulnerabilities, posing significant

Zero-days dominate top frequently exploited vulnerabilities Read More »

IT Vulnerability Report: Exposed Fortinet Vulnerabilities Approach 1 Million

IT Vulnerability Report: Exposed Fortinet Vulnerabilities Approach 1 Million 2024-11-13 at 16:18 By Paul Shread Cyble Research and Intelligence Labs (CRIL) researchers investigated 18 vulnerabilities and 10 dark web exploits in the last week – including an actively exploited Fortinet vulnerability with nearly 1 million exposed assets on the internet. Other vulnerabilities analyzed by Cyble

IT Vulnerability Report: Exposed Fortinet Vulnerabilities Approach 1 Million Read More »

Scroll to Top