Friday Squid Blogging: Sunscreen from Squid Pigments
Friday Squid Blogging: Sunscreen from Squid Pigments

Friday Squid Blogging: Sunscreen from Squid Pigments

2024-07-26 21:02

About Bruce Schneier I am a public-interest technologist, working at the intersection of...

Crypto exchange Gemini discloses third-party data breach

Crypto exchange Gemini discloses third-party data breach

2024-07-26 19:31

Cryptocurrency exchange Gemini is warning it suffered a data breach incident caused by a...

Google fixes Chrome Password Manager bug that hides credentials

Google fixes Chrome Password Manager bug that hides credentials

2024-07-26 19:04

Google has fixed a bug in Chrome's Password Manager that caused user credentials to...

FBCS data breach impact now reaches 4.2 million people

FBCS data breach impact now reaches 4.2 million people

2024-07-26 18:47

Debt collection agency Financial Business and Consumer Solutions has again increased the number...

CrowdStrike meets Murphy's Law: Anything that can go wrong will

CrowdStrike meets Murphy's Law: Anything that can go wrong will

2024-07-26 18:36

Opinion CrowdStrike's recent Windows debacle will surely earn a prominent place in the...

July Windows Server updates break Remote Desktop connections

July Windows Server updates break Remote Desktop connections

2024-07-26 17:22

Microsoft has confirmed that July's security updates break remote desktop connections in...

Acronis warns of Cyber Infrastructure default password abused in attacks

Acronis warns of Cyber Infrastructure default password abused in attacks

2024-07-26 16:39

Acronis warned customers to patch a critical Cyber Infrastructure security flaw that lets...

Vulnerabilities by Risk level (Last 12 months)

Risk level Last 12 months #
Critical 3381
High 8264
Medium 10147
Low 343

Vulnerabilities by Vendor (Last 12 months)

Vendor Last 12 months #
Google 1049
Microsoft 826
Adobe 619
Linux 509
Fedoraproject 449

Latest Vulnerabilities

  • CVE-2024-38103

    5.9

    Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

    network
    high complexity
    CWE-359
  • CVE-2024-6589

    8.8

    The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.6.8.2 via the 'render_content_block_template' function....

    network
    low complexity
  • CVE-2024-22444

    6.1

    A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user...

    network
    low complexity
    CWE-79
  • CVE-2024-31970

    8.8

    AdTran SRG 834-5 HDC17600021F1 devices (with SmartOS 11.1.1.1 and fixed in Version 12.1.3.1) have SSH enabled by default, accessible both over the LAN and the Internet. During a window of time...

    network
    low complexity
  • CVE-2024-36541 - Incorrect Default Permissions vulnerability in Kube-Logging Logging-Operator 4.6.0

    8.8

    Insecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

    network
    low complexity
    kube-logging CWE-276

Latest Critical Vulnerabilities