Author: DEFENDEDGE
-
Vulnerability Summary for the Week of August 9, 2021
Original release date: August 16, 2021 High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info alg_ds_project — alg_ds An issue was discovered in the alg_ds crate through 2020-08-25 for Rust. There is a drop of uninitialized memory in Matrix::new(). 2021-08-08 7.5 CVE-2020-36432 MISC MISC care2x — hospital_information_management_system SQL Injection… Read more
-
Exchange Servers Under Active Attack via ProxyShell Bugs
There’s an entirely new attack surface in Exchange, a researcher revealed at Black Hat, and threat actors are now exploiting servers vulnerable to the RCE bugs. Read more
-
WordPress Sites Abused in Aggah Spear-Phishing Campaign
The Pakistan-linked threat group’s campaign uses compromised WordPress sites to deliver the Warzone RAT to manufacturing companies in Taiwan and South Korea. Read more
-
Black Hat: Novel DNS Hack Spills Confidential Corp Data
Threatpost interviews Wiz CTO about a vulnerability recently patched by Amazon Route53’s DNS service and Google Cloud DNS. Read more
-
Mozilla Releases Security Updates for Thunderbird
Original release date: August 12, 2021 Mozilla has released security updates to address vulnerabilities in Thunderbird. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review the Mozilla Security Advisory for Thunderbird 91 and apply the necessary updates. This product is provided subject to… Read more
-
Microsoft Warns: Another Unpatched PrintNightmare Zero-Day
The out-of-band warning pairs with a working proof-of-concept exploit for the issue, circulating since mid-July. Read more
-
Accenture Confirms LockBit Ransomware Attack
LockBit offered Accenture’s purported databases and made a requisite jab at its purportedly sad security. Accenture says it recovered just fine from backups. Read more
-
SAP Patches Nine Critical & High-Severity Bugs
Experts urged enterprises to patch fast: SAP vulnerabilities are being weaponized in a matter of hours. Read more
-
Connected Farms Easy Pickings for Global Food Supply-Chain Hack
John Deere security bugs could allow cyberattackers to damage crops, surrounding property or even people; impact harvests; or destroy farmland for years. Read more
-
Actively Exploited Windows Zero-Day Gets a Patch
Microsoft’s August 2021 Patch Tuesday addressed a smaller set of bugs than usual, including more Print Spooler problems, a zero-day and seven critical vulnerabilities. Read more