Security
Headlines
HeadlinesLatestCVEs

Tag

#vmware

Deserialized web security roundup – Slack, Okta security breaches, lax US government passwords report, and more 

Your fortnightly rundown of AppSec vulnerabilities, new hacking techniques, and other cybersecurity news

PortSwigger
#csrf#vulnerability#web#android#mac#windows#google#amazon#cisco#git#intel#c++#backdoor#rce#vmware#aws#auth#chrome#firefox
WhatsApp lawsuit against NSO Group greenlit by Supreme Court

Categories: News Tags: Pegasus Tags: spyware Tags: Pegasus spyware Tags: NSO Group Tags: NSO Tags: Apple Tags: WhatsApp Tags: Meta Tags: Foreign Sovereign Immunity Act The US Supreme Court essentially gave Meta’s WhatsApp the go ahead to pursue their case against Pegasus’s NSO Group. (Read more...) The post WhatsApp lawsuit against NSO Group greenlit by Supreme Court appeared first on Malwarebytes Labs.

Twitter Scraping Breach: 209 Million Accounts Leaked on Hacker Forum

By Waqas The data was collected through web scraping techniques however some sites are reporting it as a "Twitter data breach," or " Twitter being hacked." This is a post from HackRead.com Read the original post: Twitter Scraping Breach: 209 Million Accounts Leaked on Hacker Forum

CVE-2022-42267: Security Bulletin: NVIDIA GPU Display Driver - November 2022

NVIDIA GPU Display Driver for Windows contains a vulnerability where a regular user can cause an out-of-bounds read, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

CVE-2022-4780: ISOS release notes - Elvexys SA

ISOS firmwares from versions 1.81 to 2.00 contain hardcoded credentials from embedded StreamX installer that integrators are not forced to change.

Healthcare Providers and Hospitals Under Ransomware's Siege

According to the FBI and Internet Crime Complaint Center, 25% of ransomware complaints involve healthcare providers.

Supply Chain Risks Got You Down? Keep Calm and Get Strategic!

Security leaders must maintain an effective cybersecurity strategy to help filter some of the noise on new vulnerabilities.

CVE-2022-31708: VMSA-2022-0034

vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4.

CVE-2022-31703: VMSA-2022-0031

vRealize Network Insight (vRNI) directory traversal vulnerability in vRNI REST API. A malicious actor with network access to the vRNI REST API can read arbitrary files from the server.