Vulnerability Summary for the Week of March 17, 2025

High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source Info Synology--Unified Controller (DSMUC)  Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423…

Comments Off on Vulnerability Summary for the Week of March 17, 2025

Vulnerability Summary for the Week of March 10, 2025

High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source Info 1E--1E Client  Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior…

Comments Off on Vulnerability Summary for the Week of March 10, 2025

CISA Releases Thirteen Industrial Control Systems Advisories

CISA released thirteen Industrial Control Systems (ICS) advisories on March 13, 2025. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. ICSA-25-072-01 Siemens Teamcenter Visualization…

Comments Off on CISA Releases Thirteen Industrial Control Systems Advisories

CISA and Partners Release Cybersecurity Advisory on Medusa Ransomware

Today, CISA—in partnership with the Federal Bureau of Investigation (FBI) and Multi-State Information Sharing and Analysis Center (MS-ISAC)—released joint Cybersecurity Advisory, #StopRansomware: Medusa Ransomware. This advisory provides tactics, techniques, and…

Comments Off on CISA and Partners Release Cybersecurity Advisory on Medusa Ransomware

#StopRansomware: Medusa Ransomware

Summary Note: This joint Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish advisories for network defenders detailing various ransomware variants and ransomware threat actors. These #StopRansomware advisories…

Comments Off on #StopRansomware: Medusa Ransomware

Vulnerability Summary for the Week of March 3, 2025

High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source Info n/a--n/a  Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary code via…

Comments Off on Vulnerability Summary for the Week of March 3, 2025

FBI Warns of Data Extortion Scam Targeting Corporate Executives

The Federal Bureau of Investigation (FBI) Internet Crime Complaint Center (IC3) has released an alert warning of a scam involving criminal actors masquerading as the “BianLian Group.” The cyber criminals target…

Comments Off on FBI Warns of Data Extortion Scam Targeting Corporate Executives

Vulnerability Summary for the Week of February 24, 2025

High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source Info jupyterhub--ltiauthenticator  `jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jupyterhub-ltiauthenticator` 1.3.0 wasn't…

Comments Off on Vulnerability Summary for the Week of February 24, 2025

Vulnerability Summary for the Week of February 17, 2025

High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source Info a1post--A1POST.BG Shipping for Woo  Cross-Site Request Forgery (CSRF) vulnerability in a1post A1POST.BG Shipping for Woo allows Privilege Escalation. This…

Comments Off on Vulnerability Summary for the Week of February 17, 2025