Vulnerability Summary for the Week of February 17, 2025

High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source Info a1post--A1POST.BG Shipping for Woo  Cross-Site Request Forgery (CSRF) vulnerability in a1post A1POST.BG Shipping for Woo allows Privilege Escalation. This…

Comments Off on Vulnerability Summary for the Week of February 17, 2025

CISA and Partners Release Advisory on Ghost (Cring) Ransomware

Today, CISA—in partnership with the Federal Bureau of Investigation (FBI) and Multi-State Information Sharing and Analysis Center (MS-ISAC)—released a joint Cybersecurity Advisory, #StopRansomware: Ghost (Cring) Ransomware. This advisory provides network…

Comments Off on CISA and Partners Release Advisory on Ghost (Cring) Ransomware

#StopRansomware: Ghost (Cring) Ransomware

Summary Note: This joint Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware…

Comments Off on #StopRansomware: Ghost (Cring) Ransomware

Vulnerability Summary for the Week of February 10, 2025

High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source Info ABB--System 800xA  A vulnerability exists in the VideONet product included in the listed System 800xA versions, where VideONet is…

Comments Off on Vulnerability Summary for the Week of February 10, 2025

Vulnerability Summary for the Week of February 3, 2025

High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source Info .TUBE gTLD--.TUBE Video Curator  Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in .TUBE gTLD .TUBE…

Comments Off on Vulnerability Summary for the Week of February 3, 2025

CISA Partners with ASD’s ACSC, CCCS, NCSC-UK, and Other International and US Organizations to Release Guidance on Edge Devices

CISA—in partnership with international and U.S. organizations—released guidance to help organizations protect their network edge devices and appliances, such as firewalls, routers, virtual private networks (VPN) gateways, Internet of Things…

Comments Off on CISA Partners with ASD’s ACSC, CCCS, NCSC-UK, and Other International and US Organizations to Release Guidance on Edge Devices

Vulnerability Summary for the Week of January 27, 2025

High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source Info 0xPolygonZero--plonky2  Plonky2 is a SNARK implementation based on techniques from PLONK and FRI. Lookup tables, whose length is not…

Comments Off on Vulnerability Summary for the Week of January 27, 2025