-
CVE-2024-20154: Critical RCE Flaw in MediaTek Chipsets Impacts Millions
CVE-2024-20154: Critical RCE Flaw in MediaTek Chipsets Impacts Millions MediaTek has released its January 2025 Product Security Bulletin, addressing a range of security vulnerabilities affecting its various chipsets. The bulletin details flaws found in products ranging fr … Read more Published Date: Jan 07, 2025 (7 hours, 30 minutes ago) Vulnerabilities has been mentioned in this article.…
-
CVE-2024-43096 and More: Critical RCE Flaws Patched in Android Security Update
CVE-2024-43096 and More: Critical RCE Flaws Patched in Android Security Update The Android Security Bulletin for January 2025 highlights critical security vulnerabilities affecting millions of Android devices globally. With the 2025-01-05 security patch level, Google has address … Read more Published Date: Jan 07, 2025 (7 hours, 24 minutes ago) Vulnerabilities has been mentioned in this article.…
-
CVE-2024-51741 and CVE-2024-46981: Redis Flaws Expose Millions to DoS and RCE Risks
CVE-2024-51741 and CVE-2024-46981: Redis Flaws Expose Millions to DoS and RCE Risks Two vulnerabilities have been discovered in Redis, the popular in-memory database, leaving millions of users at risk. CVE-2024-51741 allows attackers to trigger a denial-of-service (DoS) attack, while … Read more Published Date: Jan 07, 2025 (7 hours, 17 minutes ago) Vulnerabilities has been mentioned in…
-
CVE-2024-8474: OpenVPN Connect Vulnerability Leaks Private Keys
CVE-2024-8474: OpenVPN Connect Vulnerability Leaks Private Keys Popular VPN client app, OpenVPN Connect, patched a critical security flaw that could have exposed users’ private keys and decrypted their VPN traffic.A recently disclosured vulnerability (CVE-2024-847 … Read more Published Date: Jan 07, 2025 (7 hours, 47 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2024-8474 CVE-2023-46850 Go…
-
Exploiting Misconfigurations in Argo Workflows for Kubernetes Cluster Takeover
Exploiting Misconfigurations in Argo Workflows for Kubernetes Cluster Takeover Argo Workflows, a widely-used open-source tool for orchestrating workflows in Kubernetes, has become a valuable asset for cloud-native automation. However, recent findings by Yali Mintus, a Cloud Secu … Read more Published Date: Jan 07, 2025 (7 hours, 41 minutes ago) Vulnerabilities has been mentioned in this article.…
-
Thousands of SonicWall Devices Remain Vulnerable to CVE-2024-40766
Thousands of SonicWall Devices Remain Vulnerable to CVE-2024-40766 In September 2024, a critical vulnerability in SonicWall NSA devices, tracked as CVE-2024-40766, was disclosed. Since then, threat actors Akira and Fog have reportedly exploited this flaw to infiltrat … Read more Published Date: Jan 07, 2025 (7 hours, 37 minutes ago) Vulnerabilities has been mentioned in this article.…
-
Windows 11’s TPM 2.0: Free Software Foundation Fights Forced Upgrades and E-Waste
Windows 11’s TPM 2.0: Free Software Foundation Fights Forced Upgrades and E-Waste The Free Software Foundation (FSF) is fresh off a successful International Day Against DRM (IDAD), held on December 20th, 2024. This year’s focus was on Microsoft’s controversial requirement of a hard … Read more Published Date: Jan 07, 2025 (8 hours, 8 minutes ago) Vulnerabilities…
-
Vulnerability Overload: 40,000+ CVEs in 2024
Vulnerability Overload: 40,000+ CVEs in 2024 Security researcher Jerry Gamblin has released his annual CVE data review. 2024 saw an unprecedented surge in published Common Vulnerabilities and Exposures (CVEs), reaching a record high of 40,009. T … Read more Published Date: Jan 07, 2025 (7 hours, 50 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2024-20433…
-
CVE-2025-21617 – Guzzle OAuth Subscriber Low-Entropy Nonce Generation Vulnerability
CVE ID : CVE-2025-21617 Published : Jan. 6, 2025, 8:15 p.m. | 44 minutes ago Description : Guzzle OAuth Subscriber signs Guzzle requests using OAuth 1.0. Prior to 0.8.1, Nonce generation does not use sufficient entropy nor a cryptographically secure pseudorandom source. This can leave servers vulnerable to replay attacks when TLS is not used. This…
-
CVE-2024-55408 – ASUS System Analysis IO Arbitrary Read and Write Vulnerability
CVE ID : CVE-2024-55408 Published : Jan. 6, 2025, 7:15 p.m. | 1 hour, 45 minutes ago Description : An issue in the AsusSAIO.sys component of ASUS System Analysis IO v1.0.0 allows attackers to perform arbitrary read and write actions via supplying crafted IOCTL requests. Severity: 0.0 | NA Visit the link for more details, such as…