CVE-2023-38902

An issue in RG-EW series home routers and repeaters v.EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P218, RG-EG series business VPN routers v.EG_3.0(1)B11P216, EAP and RAP se ...

Continue Reading
mTLS: When certificate authentication is done wrong

Although [X.509]() certificates have been here for a while, they have become more popular for client authentication in zero-trust networks in recent years. Mutual TLS, or authentication based on X.509 ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

New BlackCat Ransomware Variant Adopts Advanced Impacket and RemCom Tools

[![BlackCat Ransomware](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Microsoft on Thursday disclosed that it found a new versi ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Security Bulletin: Platform Navigator and Automation Assets in IBM Cloud Pak for Integration are vulnerable to permissions bypass, privilege escalation, key generation failure, denial of service and request smuggling due to vulnerabilities in Node.js

## Summary Platform Navigator and Automation Assets in IBM Cloud Pak for Integration are vulnerable to permissions bypass, privilege escalation, key generation failure, denial of service and request s ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

[SECURITY] Fedora 37 Update: opensc-0.23.0-5.fc37

OpenSC provides a set of libraries and utilities to work with smart cards. Its main focus is on cards that support cryptographic operations, and facilitate their use in security applications such as ...

Continue Reading

CVSS3 - HIGH

CVSS2 - LOW

[SECURITY] Fedora 38 Update: opensc-0.23.0-5.fc38

OpenSC provides a set of libraries and utilities to work with smart cards. Its main focus is on cards that support cryptographic operations, and facilitate their use in security applications such as ...

Continue Reading

CVSS3 - HIGH

CVSS2 - LOW

CVE-2023-40165

rubygems.org is the Ruby community's primary gem (library) hosting service. Insufficient input validation allowed malicious actors to replace any uploaded gem version that had a platform, version numb ...

Continue Reading
Karma Catches Up to Global Phishing Service 16Shop

You've probably never heard of "**16Shop**," but there's a good chance someone using it has tried to phish you. ![](https://krebsonsecurity.com/wp-content/uploads/2023/08/16shopphish.png) A 16Shop phi ...

Continue Reading

Back to Main

Subscribe for the latest news: