CISA Adds One Known Exploited Vulnerability to Catalog

  • Post author:
  • Post category:

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2024-4978 Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the

Continue ReadingCISA Adds One Known Exploited Vulnerability to Catalog

The Bank of Russia recommends disclosing more information when conducting an IPO

  • Post author:
  • Post category:

Банк России рекомендует эмитентам при публичном размещении акций раскрывать информацию о принципах и подходах к распределению бумаг среди инвесторов до начала сбора заявок, а также о фактическом получении актива по итогам продаж. Сейчас только отдельные компании сообщают о том, как будут распределяться акции на IPO. В результате большинство инвесторов не может оценить возможный объем бумаг, который они рассчитывают получить, что приводит в том числе к дополнительному замораживанию денежных средств при подаче заявок на участие в публичном

Continue ReadingThe Bank of Russia recommends disclosing more information when conducting an IPO

CISA Releases One Industrial Control Systems Advisory

  • Post author:
  • Post category:

CISA released one Industrial Control Systems (ICS) advisory on May 28, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-149-01 Campbell Scientific CSI Web Server CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.

Continue ReadingCISA Releases One Industrial Control Systems Advisory

ICS Advisory: Campbell Scientific CSI Web Server

  • Post author:
  • Post category:

View CSAF 1. EXECUTIVE SUMMARY CVSS v4 6.9 ATTENTION: Exploitable remotely/low attack complexity Vendor: Campbell Scientific Equipment: CSI Web Server Vulnerabilities: Path Traversal, Weak Encoding for Password 2. RISK EVALUATION Successful exploitation of these vulnerabilities could allow an attacker to download files and decode stored passwords. 3. TECHNICAL DETAILS 3.1 AFFECTED PRODUCTS The following versions

Continue ReadingICS Advisory: Campbell Scientific CSI Web Server

CISA Adds One Known Exploited Vulnerability to Catalog

  • Post author:
  • Post category:

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2024-5274 Google Chromium V8 Type Confusion Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known

Continue ReadingCISA Adds One Known Exploited Vulnerability to Catalog