Severity High Analysis Summary A new campaign targeting Lebanon and the United Arab Emirates (UAE) affecting .gov domains, as well as a private Lebanese airline company. […]
Severity High Analysis Summary The Buhtrap group is well known for its targeting of financial institutions and businesses in Russia. However, since late 2015, an interesting […]
Severity Medium Analysis Summary An email campaign spreading XpertRAT via ISO images with advanced anti-analysis techniques. The phishing email in this campaign mimics a well-known Italian […]
Severity Medium Analysis Summary An out-of-bounds vulnerability exists and could be exploited by the application processing a specially crafted project file. Exploitation could cause a software […]
Severity Medium Analysis Summary CVE-2011-3389 The SSL protocol encrypts data by using CBC mode with chained initialization vectors, which may allow a man-in-the-middle attack to obtain […]
Severity High Analysis Summary The integrated configuration web application (TIA Administrator) may allow an attacker to execute certain application commands without proper authentication. Impact Improper Access […]
Severity Medium Analysis Summary The SIMATIC WinCC DataMonitor web application of the affected products allows an authenticated user with network access to the WinCC DataMonitor application […]
Severity Medium Analysis Summary CVE-2019-10982 Multiple heap-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files, allowing an attacker to remotely execute arbitrary […]
Severity Medium Analysis Summary An error related to the “net_hash_mix()” function (include/net/netns/hash.h) can be exploited to disclose certain kernel memory addresses and subsequently bypass KASLR. Impact […]