ISC Releases Security Advisories for BIND 9

  • Post author:
  • Post category:

An official website of the United States government Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock A locked padlock ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure

Continue ReadingISC Releases Security Advisories for BIND 9

CISA Releases One Industrial Control Systems Advisory

  • Post author:
  • Post category:

CISA released one Industrial Control Systems (ICS) advisory on February 13, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-044-01 Mitsubishi Electric MELSEC iQ-R Series Safety CPU CISA encourages users and administrators to review the newly released ICS advisory for technical details and mitigations.

Continue ReadingCISA Releases One Industrial Control Systems Advisory

ICS Advisory: Mitsubishi Electric MELSEC iQ-R Series Safety CPU

  • Post author:
  • Post category:

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 6.5 ATTENTION: Exploitable remotely/low attack complexity Vendor: Mitsubishi Electric Equipment: MELSEC iQ-R Series Safety CPU and SIL2 Process CPU Module Vulnerability: Incorrect Privilege Assignment 2. RISK EVALUATION Successful exploitation of this vulnerability could allow a non-administrator user to disclose the credentials (user ID and password) of a user

Continue ReadingICS Advisory: Mitsubishi Electric MELSEC iQ-R Series Safety CPU

CISA Adds Two Known Exploited Vulnerabilities to Catalog

  • Post author:
  • Post category:

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2024-21412 Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability CVE-2024-21351 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. 

Continue ReadingCISA Adds Two Known Exploited Vulnerabilities to Catalog