Moby and Open Container Initiative Release Critical Updates for Multiple Vulnerabilities Affecting Docker-related Components

  • Post author:
  • Post category:

Moby and the Open Container Initiative (OCI) have released updates for multiple vulnerabilities (CVE-2024-23651, CVE-2024-23652, CVE-2024-23653, CVE-2024-21626) affecting Docker-related components, including Moby BuildKit and OCI runc. A cyber threat actor could exploit these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review the advisories from Moby BuildKit (CVE-2024-23651, CVE-2024-23652

Continue ReadingMoby and Open Container Initiative Release Critical Updates for Multiple Vulnerabilities Affecting Docker-related Components

CISA Releases Two Industrial Control Systems Advisories

  • Post author:
  • Post category:

CISA released two Industrial Control Systems (ICS) advisories on February 1, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-032-01 Gessler GmbH WEB-MASTER  ICSA-24-032-03 AVEVA Edge products (formerly known as InduSoft Web Studio) CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations.

Continue ReadingCISA Releases Two Industrial Control Systems Advisories

ICS Advisory: AVEVA Edge products (formerly known as InduSoft Web Studio)

  • Post author:
  • Post category:

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 7.3 ATTENTION: Low attack complexity Vendor: AVEVA Equipment: AVEVA Edge products (formerly known as InduSoft Web Studio) Vulnerability: Uncontrolled Search Path Element 2. RISK EVALUATION Successful exploitation of this vulnerability could result in an attacker achieving arbitrary code execution and privilege escalation by tricking AVEVA Edge to load an unsafe DLL. 3. TECHNICAL

Continue ReadingICS Advisory: AVEVA Edge products (formerly known as InduSoft Web Studio)

ICS Advisory: Gessler GmbH WEB-MASTER

  • Post author:
  • Post category:

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.8 ATTENTION: Exploitable Remotely/Low attack complexity Vendor: Gessler GmbH Equipment: WEB-MASTER Vulnerabilities: Use of Weak Credentials, Use of Weak Hash 2. RISK EVALUATION Successful exploitation of these vulnerabilities could allow a user to take control of the web management of the device. An attacker with access to the

Continue ReadingICS Advisory: Gessler GmbH WEB-MASTER

Department of Labor conducted second Pattern of Violations screening to protect miners in 2023; identifies chronic violator

  • Post author:
  • Post category:

WASHINGTON – The U.S. Department of Labor’s Mine Safety and Health Administration today released the results of its second 2023 pattern of violations screening to identify chronic violators and mine operators demonstrating a disregard for the health and safety of miners. This was the first time that the agency conducted more than one POV screening in a

Continue ReadingDepartment of Labor conducted second Pattern of Violations screening to protect miners in 2023; identifies chronic violator