CND News and Blog
New Alerts for TP-Link, Medtronic, BD, PowerDNS, Microsoft and Linux. TP-Link TP-Link router WR710N-V1-151022 and Archer-C5-V2-160201 are susceptible to two vulnerabilities, including a buffer overflow during HTTP Basic Authentication allowing a remote attacker to corrupt memory allocated on a heap causing DoS or RCE, and a side-channel attac...
New Alerts for Cisco, WithSecure, Mitel, and Wireshark. Cisco A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. CVSSv3 score of 4.7More info. WithSecure A DoS vulnera...
New Alerts for GE Digital, IBM, D-Link, Mozilla, Git, and Apache. GE Digital GE Digital Proficy Historian contains multiple vulnerabilities, including Authentication Bypass using an Alternate Path or Channel, Unrestricted Upload of File with Dangerous Type, Improper Access Control, and Weak Encoding for Password. Successful exploitation of th...
For several months we have been seeing a huge interest in the capabilities of ChatGPT and with a high school teacher in the family, we have looked a little deeper in detecting it's use. At Computer Network Defence Ltd (CND) we will often test the resourcefulness of our new cyber security candidates by asking them to research a topic and d...
We have all heard of Phishing attacks, where emails are used as bait to lure us into clicking on a link or opening an attachment. However, because we are now much wiser to the threat, attackers are having to work harder to lure us in by doing some research. These targeted phishing attacks are referred to as Spear Phishing, and humorously, if ...
Quarterly Patches for Oracle are out this afternoon. Pre-release notice is available. New Alerts for Mitsubishi Electric, IBM, and Linux. Mitsubishi Electric An authorization bypass vulnerability exists in the WEB server function of the MELSEC iQ-F/iQ-R Series. An unauthenticated remote attacker may be able to access the WEB server function b...
New Alerts for Xerox, Google ChromeOS, and Linux. Xerox Xerox has updated Xerox WorkCentre models to correct vulnerabilities including insecure password encryption, show embedded system accounts, and remove the ability to disable functionality.More info. Google Google has published a security update for ChromeOS / ChromeOS Flex.More inf...
New Alerts for Sewio, InHand Networks, SAUTER, Microsoft Edge, IBM, NetApp, and Linux. Sewio RTLS Studio contains multiple vulnerabilities, including Use of Hard-coded Password, OS Command Injection, Out-of-bounds Write, Cross-Site Request Forgery, Improper Input Validation, and Cross-site Scripting. Highest CVSSv3 score of 10.More info. InHa...
Quarterly Patches are out for Juniper Networks. New Alerts for Cisco, WAGO, IBM, Zyxel, and Linux. Cisco Cisco has published 11 new bulletins, 1 Critical, 3 High, and the rest Medium. Highest CVSSv3 score of 9.0More info.Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 Rout...
New Alerts for Google Chrome, Moxa, Westermo, MAHO-PBX, NetApp, Western Digital, Black Box, and Linux. Google Google has updated Chrome for Desktop to fix 17 security vulnerabilities.More info.Microsoft is aware. More info. Moxa TN-4900 Series contains a Use of Hard-coded Credentials vulnerability that allows an attacker to gain privile...
Monthly Patches are out for Siemens, Schneider Electric, and SAP. New Alerts for IBM, BD, and Linux. UPDATED TO ADD: Monthly Patches for Microsoft and Adobe are out now. Palo Alto Networks Monthly Patches are expected tomorrow. Microsoft Microsoft Monthly Patches include 98 vulnerabilities, 11 rated Critical (7 of which allow RCE), 1 pub...
New Alerts for IBM and Synology. IBM Multiple security vulnerabilities may affect IBM Robotic Process Automation for Cloud Pak. Highest CVSSv3 score of 9.8More info. And here. Synology A vulnerability allows remote attackers to possibl6 execute arbitrary commands via a susceptible version of Synology VPN Plus Server. CVSSv3 score of 10M...
New Alerts for Digital Arts, HCL Software, and Linux. Digital Arts m-FILTER contains an improper authentication vulnerability when emails are being sent under certain conditions, and unintended emails may be sent by a remote attacker. CVSSv3 score of 5.3More info. And here. HCL Software HCL Compass is affected by an IBM HTTP Serve...
New Alerts for Dell, ManageEngine, and Linux. Dell PowerProtect DD remediation is available for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system. Dell rates this CriticalMore info.Container Storage Modules remediation is available for a golang.org/x/net vulnerability that may b...
Monthly Patches are out for Qualcomm, MediaTek, Google Android, Google Pixel, Samsung, and Fortinet. New Alerts for Dell and Apache Tomcat. Qualcomm Monthly Patches for Qualcomm are out with 22 vulnerabilities, 3 rated Critical, 17 rated High, and 2 rated Medium. Highest CVSSv3 score of 9.3More info. MediaTek Monthly Patches for MediaTe...
New Alert for IBM. IBM Automation Assets in IBM Cloud Pak for Integration is vulnerable to RCE due to an xmldom vulnerability and a webpack loader-utils vulnerability. CVSSv3 score of 9.8More info. And here. Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securitywizardry.com/ Security Wizardry Cyber Threat Intellig...
By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/