Cyber Newsroom Feed
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
- Zero Day Initiative
The April 2024 Security Updates Review
None ... Read more
- 0patch.com
Micropatches for Windows Local Session Manager Elevation of Privilege (CVE-2023-21771)
In December of 2022, Ben Barnea of Akamai posted an X thread about a bug they had found in Windows Local Service Manager (LSM) that can lead to local privilege escalation from regular user account to ... Read more
- cert.pl
Vulnerability in Apaczka plugin for PrestaShop
CVE ID CVE-2024-2759 Publication date 04 April 2024 Vendor Alsendo Sp. z o. o. Product Apaczka (PrestaShop plugin) Vulnerable versions through v4 Vulnerability type (CWE) Improper Access Control (CWE- ... Read more
- 0patch.com
Micropatches for Leaking NTLM Credentials Through Windows Themes (CVE-2024-21320)
January 2024 Windows Updates brought a patch for CVE-2024-21320, a privilege escalation vulnerability in Windows. The vulnerability allows a remote attacker to acquire user's NTLM credentials when the ... Read more
- cert.pl
Vulnerabilities in CDeX software
CVE ID CVE-2024-2463 Publication date 21 March 2024 Vendor CDeX PSA Product CDeX Vulnerable versions through 5.71 Vulnerability type (CWE) Weak Password Recovery Mechanism for Forgotten Password (CWE- ... Read more
- Trend Micro
TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types
On March 4, 2024, JetBrains disclosed two critical vulnerabilities — CVE-2024-27198 and CVE-2024-27199 — within the TeamCity On-Premises platform that allow attackers to bypass authentication measures ... Read more
- Trend Micro
Jenkins Args4j CVE-2024-23897: Files Exposed, Code at Risk
Exploits & Vulnerabilities Jenkins, a popular open-source automation server, was discovered to be affected by a file read vulnerability, CVE-2024-23897. Jenkins, a popular open-source automation serve ... Read more
- cert.pl
Vulnerabilities in BMC Control-M software
CVE ID CVE-2024-1604 Publication date 18 March 2024 Vendor BMC Product Control-M Vulnerable versions from 9.0.20 before 9.0.20.238, from 9.0.21 before 9.0.21.201 Vulnerability type (CWE) Incorrect Aut ... Read more
- 0patch.com
Micropatches Released for Microsoft Outlook "MonikerLink" Remote Code Execution Vulnerability (CVE-2024-21413)
Update 7/31/2024: Additional exploitation variants for this vulnerability were subsequently discovered. Consequently, original micropatches were revoked and new micropatches issued to cover these new ... Read more
- Zero Day Initiative
CVE-2023-36049: Microsoft .NET CRLF Injection Arbitrary File Write/Deletion Vulnerability
None ... Read more