Remove category vulnerability
article thumbnail

New Category of DNS Vulnerabilities Impacts Numerous DNSaaS Platforms

Heimadal Security

A brand-new category of DNS flaws that affects important DNS-as-a-Service (DNSaaS) suppliers has been recently discovered by cybersecurity specialists. According to them, these vulnerabilities could enable cybercriminals to gain access and exfiltrate private data belonging to service customers’ corporate systems.

DNS 105
article thumbnail

CISA adds 41 flaws to its Known Exploited Vulnerabilities Catalog

Security Affairs

US Critical Infrastructure Security Agency (CISA) adds 41 new vulnerabilities to its Known Exploited Vulnerabilities Catalog. Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure. SecurityAffairs – hacking, Known Exploited Vulnerabilities Catalog).

Software 145
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

What Is FOSS Software? Definition, Usage, and Vulnerabilities

Heimadal Security

Free Open-Source Software (FOSS) is a software category that incorporates computer programs that are freely licensed and open-source. This article will focus on the major differences between FOSS and OSS (Open-Source Software), applicability, and the various security vulnerabilities associated with this type of […].

article thumbnail

Google announced its Mobile VRP (vulnerability rewards program)

Security Affairs

Google introduced Mobile VRP (vulnerability rewards program), a new bug bounty program for reporting vulnerabilities in its mobile applications. Google announced a new bug bounty program, named Mobile VRP (vulnerability rewards program), that covers its mobile applications. ” states the announcement.

Mobile 97
article thumbnail

Ransomware gangs are exploiting CVE-2022-26134 RCE in Atlassian Confluence servers

Security Affairs

Multiple ransomware groups are actively exploiting the recently disclosed remote code execution (RCE) vulnerability, tracked as CVE-2022-26134 , affecting Atlassian Confluence Server and Data Center. Researchers from cybersecurity firm GreyNoise reported that 23 unique IP addresses were observed exploiting the Atlassian vulnerabilities.

article thumbnail

FISMA Compliance: A Complete Guide to Navigating Low, Moderate, and High Levels

Centraleyes

The resulting security category for this information type is expressed as: “Security Category public information = {(confidentiality, n/a), (integrity, moderate), (availability, moderate)}.” The idea is that the security category should reflect the most significant potential impact.

Risk 52
article thumbnail

Flaw Impacting LibreOffice & OpenOffice Enables Attackers to Spoof Signed Documents

Heimadal Security

Even though the vulnerability is not placed in the ‘High’ severity category being rated as moderate, the consequences could be disastrous. The post Flaw Impacting LibreOffice & OpenOffice Enables Attackers to Spoof Signed Documents appeared first on Heimdal Security Blog.