article thumbnail

NIST Deprioritizes Pre-2018 CVEs as Backlog Struggles Continue

Security Boulevard

NIST, which for more than a year has been struggling to address a backlog of CVEs in its database following budget cuts, is now putting pre-2018 vulnerabilities on the back burner to give itself more time to address the rapidly growing number of new software security flaws.

article thumbnail

Threat Spotlight: Credential Theft vs. Admin Control—Two Devastating Paths to VPN Exploitation

Digital Shadows

Key Findings Even years after their disclosure, VPN-related vulnerabilities like CVE-2018-13379 and CVE-2022-40684 remain essential tools for attackers, driving large-scale campaigns of credential theft and administrative control. CVE-2018-13379: The Eternal Exploit What is CVE-2018-13379?

VPN 133
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

RotaJakiro Linux backdoor has flown under the radar since 2018

Security Affairs

RotaJakiro is a Linux backdoor recently discovered by researchers at Qihoo 360’s Network Security Research Lab (360 Netlab). ” The RotaJakiro backdoor was first spotted in 2018 when a sample was uploaded on VirusTotal’s anti-malware service. Follow me on Twitter: @securityaffairs and Facebook.

article thumbnail

Hackers Leak VPN Account Passwords From 87,000 Fortinet FortiGate Devices

The Hacker News

Network security solutions provider Fortinet confirmed that a malicious actor had unauthorizedly disclosed VPN login names and passwords associated with 87,000 FortiGate SSL-VPN devices. These credentials were obtained from systems that remained unpatched against CVE-2018-13379 at the time of the actor's scan.

VPN 133
article thumbnail

Network Security Organization COO Accused of Cyberattack on Medical Center

Heimadal Security

Vikas Singla, the chief operating officer of a network security enterprise working for the healthcare sector has been accused by federal prosecutors of alleged crimes coming from a cyberattack on Georgia-based Gwinnett Medical Center (GMC) back in September 2018.

article thumbnail

Seven Years Later: Cisco CVE-2018-0171 Still Exposes Thousands to RCE

Penetration Testing

In a deep dive published by Guy Bruneau, Senior Security Consultant and former network engineer, the lingering dangers of a years-old Cisco vulnerabilityCVE-2018-0171are laid bare with fresh insights and real-world testing.

article thumbnail

Get ready for security in the age of the Extended Internet of Things, says Claroty

Tech Republic Security

ICS vulnerability disclosures have grown by 110% since 2018, which Claroty said suggests more types of operational technologies are coming online and presenting soft targets. The post Get ready for security in the age of the Extended Internet of Things, says Claroty appeared first on TechRepublic.

Internet 175