ar
Feedback
SysAdmin 24x7

SysAdmin 24x7

الذهاب إلى القناة على Telegram

Noticias y alertas de seguridad informática. Chat y contacto: t.me/sysadmin24x7chat

إظهار المزيد
4 392
المشتركون
-124 ساعات
-17 أيام
+1430 أيام
أرشيف المشاركات
USN-4989-2: BlueZ vulnerabilities Several security issues were fixed in BlueZ. https://ubuntu.com/security/notices/USN-4989-2

Cisco AnyConnect Secure Mobility Client for Windows with VPN Posture (HostScan) Module DLL Hijacking Vulnerability A vulnerability in the DLL loading mechanism of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-pos-dll-ff8j6dFv

Cisco AnyConnect Secure Mobility Client for Windows Denial of Service Vulnerability A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-dos-hMhyDfb8

Schneider Electric Security Notification PowerLogic EGX100 and PowerLogicEGX300 Vulnerabilities discovered in some older Schneider Electric PowerLogic products can allow hackers to remotely take control of devices or disrupt them. https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-03

Una vulnerabilidad en Microsoft Power Apps permite el robo de credenciales en Microsoft Teams https://unaaldia.hispasec.com/2021/06/una-vulnerabilidad-en-microsoft-power-apps-permite-el-robo-de-credenciales-en-microsoft-teams.html

[Actualización 14/06/2021] Vulnerabilidad en el core de Drupal Fecha de publicación: 27/05/2021 Importancia: 3 - Media Recursos afectados: Versiones anteriores a: 9.1; 9.0; 8.9. Descripción: Descubierta en la librería CKEditor un error en el análisis de HTML que podría conducir a un ataque XSS. https://www.incibe-cert.es/alerta-temprana/avisos-seguridad/vulnerabilidad-el-core-drupal-3

Unpatched Bugs Found Lurking in Provisioning Platform Used with Cisco UC A trio of security flaws open the door to remote-code execution and a malware tsunami. https://threatpost.com/unpatched-bugs-provisioning-cisco-uc/166882/

ALPACA: New TLS Attack Allows User Data Extraction, Code Execution. https://www.securityweek.com/alpaca-new-tls-attack-allows-user-data-extraction-code-execution

McDonald’s latest company to be hit by a data breach. https://apnews.com/article/technology-business-b020bd79e428ae0005884beb40c85475

Spotify, PayPal, GitHub, and other major websites down due to Fastly CDN outage A large number of popular websites including Reddit, Spotify, PayPal, GitHub, gov.uk, CNN, and the BBC are currently facing problems due to a glitch at Fastly CDN provider. https://securityaffairs.co/wordpress/118732/breaking-news/fastly-cdn-outage.html