Kyverno resource with a deletionTimestamp may allow policy circumvention

### Impact In versions of Kyverno prior to 1.10.0, resources which have the `deletionTimestamp` field defined can bypass validate, generate, or mutate-existing policies, even in cases where the `valid ...

Continue Reading
(RHSA-2023:3441) Important: Red Hat OpenStack Platform 17.0 (etcd) security update

A highly-available key value store for shared configuration Security Fix(es): * Information discosure via debug function (CVE-2021-28235) * Key name can be accessed via LeaseTimeToLive API (CVE-2023-3 ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

Microsoft: Lace Tempest Hackers Behind Active Exploitation of MOVEit Transfer App

[![MOVEit Transfer App](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Microsoft has officially linked the [ongoing active explo ...

Continue Reading
FTC Slams Amazon with $30.8M Fine for Privacy Violations Involving Alexa and Ring

[![Privacy Violations](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() The U.S. Federal Trade Commission (FTC) has fined Amazon a ...

Continue Reading
New Linux Ransomware Strain BlackSuit Shows Striking Similarities to Royal

[![Linux Ransomware](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() An analysis of the Linux variant of a new ransomware strain ...

Continue Reading
CVE-2023-1945

Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird Read More ...

Continue Reading
DataEase API interface has IDOR vulnerability

### Impact The api interface for DataEase delete dashboard and delete system messages is vulnerable to IDOR. The interface to delete the dashboard: 1. Create two users: user1 and user2 2. User1 create ...

Continue Reading
DataEase API interface has IDOR vulnerability

### Impact The api interface for DataEase delete dashboard and delete system messages is vulnerable to IDOR. The interface to delete the dashboard: 1. Create two users: user1 and user2 2. User1 create ...

Continue Reading

Back to Main

Subscribe for the latest news: