All cyber security news in one place, with a practical digest format
Subscribe here on youtube channel or follow me on LinkedIN, for the last weekly cyber security digest.
More news in the video, but for reference, here last week Critical CVEs (CVSS scores higher than 8):
CVE-2024-32850: This vulnerability in SkyBridge routers allows attackers to execute commands remotely or gain unauthorized administrative access. It has a CVSS score of 9.8. The flaw resides in the remote monitoring and control function of the affected routers. Users are advised to update their firmware to the latest version to mitigate this vulnerability (Cybersecurity News).
CVE-2024-28222: Found in Veritas NetBackup, this vulnerability allows unauthenticated attackers to remotely execute malicious code on NetBackup servers and clients. It has a CVSS score of 9.8. The issue lies in inadequate validation of file paths in the NetBackup BPCD process. Users should upgrade to the latest versions to address this critical flaw (Cybersecurity News).
CVE-2024-21899: This authentication bypass vulnerability affects QNAP NAS devices, allowing unauthorized remote access. It also has a CVSS score of 9.8. Users are strongly urged to update to the latest patched versions of QTS, QuTS hero, and other affected software to secure their systems (Cybersecurity News).
CVE-2024-5943: This vulnerability in the Nested Pages plugin for WordPress is due to missing or incorrect nonce validation, leading to a CVSS score of 8.8. It affects all versions up to and including 3.2.7 and allows cross-site request forgery (NIST National Vulnerability Database).
CVE-2024-6319 and CVE-2024-6318: Both vulnerabilities in the IMGspider plugin for WordPress allow arbitrary file uploads due to missing file type validation, each with a CVSS score of 8.8. These affect all versions up to and including 2.3.10 (NIST National Vulnerability Database).
CVE-2024-2385: This vulnerability in the Elementor Addons by Livemesh plugin for WordPress allows local file inclusion via several of the plugin's widgets, with a CVSS score of 8.8. It affects all versions up to and including 8.3.7 (NIST National Vulnerability Database).
#cybersecuritynews
#news
#ciso
#cyberattacks
#cve
#databreach