Luca Donetti Dontin Il sito di un pazzo sistemista! - page 25

Tentativi di estorsione sfruttano finte vulnerabilità o compromissioni (BL01/221125/CSIRT-ITA)

Campagne di estorsione finalizzate alla richiesta di denaro utilizzano la minaccia di pubblicazione di dati aziendali sensibili nel caso non venga effettuato un pagamento in Bitcoin. Source link Author: csirt@pec.acn.gov.it Article used for cyber security disclosure.

Continue reading →

Cisco Releases Security Updates for Identity Services Engine

Original release date: November 16, 2022 Cisco has released security updates for vulnerabilities affecting Cisco Identity Services Engine (ISE). A remote attacker could exploit some of these vulnerabilities to bypass authorization and access system files. For updates addressing vulnerabilities, see the Cisco Security Advisories page. …

Continue reading →

Rilevate vulnerabilità in Apache AirFlow (AL01/221124/CSIRT-ITA)

Rilevate vulnerabilità con gravità “critica” in Apache Airflow. Tali vulnerabilità, qualora sfruttate, potrebbero permettere ad un utente malintenzionato remoto l’esecuzione di codice arbitrario sui dispositivi interessati. Source link Author: csirt@pec.acn.gov.it Article used for cyber security disclosure.

Continue reading →

CISA Releases Eight Industrial Control Systems Advisories

Original release date: November 22, 2022 CISA has released eight (8) Industrial Control Systems (ICS) advisories on 22 November 2022. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. CISA encourages users and administrators to review the newly released ICS…

Continue reading →

Aggiornamenti per prodotti Zyxel (AL02/221123/CSIRT-ITA)

Zyxel rilascia aggiornamenti di sicurezza per sanare una vulnerabilità nel router LTE3301-M209. Source link Author: csirt@pec.acn.gov.it Article used for cyber security disclosure.

Continue reading →

CISA Releases Two Industrial Control Systems Advisories

Original release date: November 17, 2022 CISA has released two (2) Industrial Control Systems (ICS) advisories on November 17, 2022. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. CISA encourages users and administrators to review the newly released ICS…

Continue reading →

PoC pubblico per lo sfruttamento della CVE-2022-40127 (AL01/221121/CSIRT-ITA)

Disponibile un Proof of Concept (PoC) per la vulnerabilità CVE-2022-40127 presente in Example Dags per Apache Airflow. Tale vulnerabilità, qualora sfruttata, potrebbe permettere ad un utente malintenzionato, remoto e autenticato, l’esecuzione di comandi arbitrari sui sistemi interessati. Source link Author: csirt@pec.acn.gov.it Article used for cyber…

Continue reading →

#StopRansomware: Hive

Original release date: November 17, 2022 Today, CISA, the Federal Bureau of Investigation (FBI), and the Department of Health and Human Services (HHS) released joint Cybersecurity Advisory (CSA) #StopRansomware: Hive Ransomware to provide network defenders tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) associated…

Continue reading →

Page 25 of 58 ← First ... 23 24 25 26 27 ... Last →