article thumbnail

Canon Printers: Critical CVE-2024-2184 (CVSS 9.8) Flaw Requires Immediate Firmware Update

Penetration Testing

Canon has released a security bulletin addressing a buffer overflow vulnerability (CVE-2024-2184, CVSS 9.8) Risk Assessment If an affected... The post Canon Printers: Critical CVE-2024-2184 (CVSS 9.8) Flaw Requires Immediate Firmware Update appeared first on Penetration Testing. in their WSD protocol process.

Firmware 142
article thumbnail

Supply Chain and Firmware Security Take Center Stage in 2024 NDAA

Security Boulevard

The post Supply Chain and Firmware Security Take Center Stage in 2024 NDAA appeared first on Security Boulevard.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Binarly released the free online scanner to detect the CVE-2024-3094 Backdoor

Security Affairs

Researchers from the firmware security firm Binarly released a free online scanner to detect the CVE-2024-3094 Backdoor Last week, Microsoft engineer Andres Freund discovered a backdoor issue in the latest versions of the “xz” tools and libraries. The vulnerability was tracked as CVE-2024-3094 and received a CVSS score of 10.

Firmware 117
article thumbnail

Google Warns: Android Zero-Day Flaws in Pixel Phones Exploited by Forensic Companies

The Hacker News

The high-severity zero-day vulnerabilities are as follows - CVE-2024-29745 - An information disclosure flaw in the bootloader component CVE-2024-29748 - A privilege escalation flaw in the firmware component "There are indications that the [

Firmware 130
article thumbnail

RSAC 2024 Day 2: IoT Security Questions (and Answers)

Security Boulevard

Whether it’s the UK’s Product Security law going into effect at the end of April, the growing focus by […] The post RSAC 2024 Day 2: IoT Security Questions (and Answers) appeared first on Viakoo, Inc. The post RSAC 2024 Day 2: IoT Security Questions (and Answers) appeared first on Security Boulevard.

IoT 59
article thumbnail

Google fixed two actively exploited Pixel vulnerabilities

Security Affairs

Two issues fixed by the IT giant, tracked as CVE-2024-29745 and CVE-2024-29748, are actively exploited in the wild. ” reads the Android Security Bulletin—April 2024. ” reads the Android Security Bulletin—April 2024. Google addressed 28 vulnerabilities in Android and 25 flaws in Pixel devices.

Spyware 106
article thumbnail

Google patches critical vulnerability for Androids with Qualcomm chips

Malwarebytes

If your Android phone is at patch level 2024-04-05 or later then the issues discussed below have been fixed. Another vulnerability highlighted by Google is CVE-2024-23704 , an elevation of privilege (EoP) vulnerability in the System component that affects Android 13 and Android 14.

Firmware 113