Rewterz

Rewterz Threat Advisory – CVE-2021-27274 – Netgear ProSAFE Network Management System Arbitrary File Upload

June 28, 2021
Rewterz

Rewterz Threat Alert – Phobos Ransomware – Active IOCs

June 28, 2021

Rewterz Threat Advisory – CVE-2021-1073 – NVIDIA GeForce Experience Vulnerability

Severity

High

Analysis Summary

CVE-2021-1073

NVIDIA GeForce Experience software contains a vulnerability where, if a user clicks on a maliciously formatted link that opens the GeForce Experience login page in a new browser tab instead of the GeForce Experience application and enters their login information, the malicious site can get access to the token of the user login session. Such an attack may lead to these targeted users’ data being accessed, altered, or lost.

Impact

  • Credential Theft
  • Unauthorized Access

Affected Vendors

NVIDIA

Affected Products

  • GeForce Experience

Remediation

Refer to NVIDIA advisory for the list of upgraded patches.

https://nvidia.custhelp.com/app/answers/detail/a_id/5199#security-updates

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.