Sep 12, 2024Ravie LakshmananDevSecOps / Vulnerability GitLab on Wednesday released security updates to address 17 security vulnerabilities, including a critical flaw that allows an attacker to run pipeline jobs as an arbitrary user. The issue, tracked as CVE-2024-6678, carries a CVSS score of 9.9 out of a maximum of 10.0 “An issue was discovered in…

Read More

Sep 12, 2024Ravie LakshmananMobile Security / Financial Fraud Bank customers in the Central Asia region have been targeted by a new strain of Android malware codenamed Ajina.Banker since at least November 2024 with the goal of harvesting financial information and intercepting two-factor authentication (2FA) messages. Singapore-headquartered Group-IB, which discovered the threat in May 2024, said…

Read More

‘At every turn, we’re putting partners first because we cannot succeed without you,’ ServiceNow Channel Chief Erica Volini said. Major changes to who qualifies as an Elite partner, growing the percentage of partner-sourced net-new annual contract value for ServiceNow Now Assist artificial intelligence tools, and a leadership team that is all in on partners are…

Read More

Hackers have been leveraging publicly available exploit code for two critical vulnerabilities in the WhatsUp Gold network availability and performance monitoring solution from Progress Software. The two flaws exploited in attacks since August 30 are SQL injection vulnerabilities tracked as CVE-2024-6670 and CVE-2024-6671 that allow retrieving encrypted passwords without authentication. Despite the vendor addressing the security issues…

Read More

U.K.’s National Crime Agency says it arrested a 17-year-old teenager who is suspected of being connected to the cyberattack on Transport for London, the city’s public transportation agency. “A teenager has been arrested in Walsall by the National Crime Agency, as part of the investigation into a cyber security incident affecting Transport for London (TfL),”…

Read More

Cisco released security updates to address vulnerabilities in Cisco ISO XR software. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system.  CISA encourages users and administrators to review the following advisories and apply the necessary updates:  Source link lol

Read More

CISA released twenty-five Industrial Control Systems (ICS) advisories on September 12, 2024. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-24-256-01 Siemens SINEMA Remote Connect Server ICSA-24-256-02 Siemens SINUMERIK ONE, SINUMERIK 840D and SINUMERIK 828D ICSA-24-256-03 Siemens User Management Component (UMC) ICSA-24-256-04 Siemens SINUMERIK Systems ICSA-24-256-05 Siemens Mendix Runtime…

Read More

Adobe released security updates to address multiple vulnerabilities in Adobe software. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system.    CISA encourages users and administrators to review the following Adobe Security Bulletins and apply the necessary updates:   Security update available for Adobe Media Encoder | APSB24-53 Security…

Read More

CRN breaks down six significant recent executive departures and hires at Google Cloud, including the exit of Google’s Kubernetes leader and the hiring of Microsoft’s former corporate vice president. From the departure of Google Cloud’s Kubernetes and serverless general manager to the hiring of Microsoft’s former corporate vice president, Google Cloud’s top executive lineup continues…

Read More

The outage Thursday morning had prevented some AT&T users from accessing Microsoft 365 and Azure services. AT&T said that “connections are operating normally” as of mid-morning Thursday, EDT, following reports that Microsoft 365 and Azure services were inaccessible for AT&T users earlier in the morning. Microsoft also confirmed that the issues that caused the outage…

Read More