Vulnerabilities - Security Boulevard https://securityboulevard.com/category/blogs/threats-breaches/vulnerabilities/ The Home of the Security Bloggers Network Tue, 26 Nov 2024 15:00:42 +0000 en-US hourly 1 https://wordpress.org/?v=6.7.1 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png Vulnerabilities - Security Boulevard https://securityboulevard.com/category/blogs/threats-breaches/vulnerabilities/ 32 32 133346385 QNAP’s Buggy Security Fix Causes Chaos https://securityboulevard.com/2024/11/qnap-bad-patch-richixbw/ Tue, 26 Nov 2024 14:54:57 +0000 https://securityboulevard.com/?p=2037597 Three tiny people cleaning the inside of a hard drive

RAID FAIL: NAS Maker does a CrowdStrike—cleanup on /dev/dsk/c1t2d3s4 please

The post QNAP’s Buggy Security Fix Causes Chaos appeared first on Security Boulevard.

]]>
2037597
RF Fortune Telling: Frequency Hopping Predictability https://securityboulevard.com/2024/11/rf-fortune-telling-frequency-hopping-predictability/ https://securityboulevard.com/2024/11/rf-fortune-telling-frequency-hopping-predictability/#respond Tue, 26 Nov 2024 02:18:03 +0000 https://www.praetorian.com/?p=3311 In the world of wireless communications, security vulnerabilities in implemented protocols canremain hidden behind layers of complexity. What appears secure due to the intricate nature ofRF communications may harbor fundamental weaknesses. Let’s dive into a fascinating casethat reveals how a seemingly minor cryptographic weakness in frequency hopping algorithmscan compromise an entire wireless communication stream. Understanding […]

The post RF Fortune Telling: Frequency Hopping Predictability appeared first on Praetorian.

The post RF Fortune Telling: Frequency Hopping Predictability appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2024/11/rf-fortune-telling-frequency-hopping-predictability/feed/ 0 2037585
In a Growing Threat Landscape, Companies Must do Three Things to Get Serious About Cybersecurity https://securityboulevard.com/2024/11/in-a-growing-threat-landscape-companies-must-do-three-things-to-get-serious-about-cybersecurity/ Mon, 25 Nov 2024 13:44:39 +0000 https://securityboulevard.com/?p=2037503 landscape, threat, securing the SMB

Several macro-trends – such as growing digital transformation, rising hybrid work and, especially, booming AI adoption – have created an increasingly sophisticated threat landscape.

The post In a Growing Threat Landscape, Companies Must do Three Things to Get Serious About Cybersecurity appeared first on Security Boulevard.

]]>
2037503
Here’s Yet Another D-Link RCE That Won’t be Fixed https://securityboulevard.com/2024/11/d-link-router-critical-rce-sol-richixbw/ Thu, 21 Nov 2024 17:33:40 +0000 https://securityboulevard.com/?p=2037237 A D-Link DSR-250N, which is now EOL

D-Licious: Stubborn network device maker digs in heels and tells you to buy new gear.

The post Here’s Yet Another D-Link RCE That Won’t be Fixed appeared first on Security Boulevard.

]]>
2037237
Microsoft Veeps Ignite Fire Under CrowdStrike https://securityboulevard.com/2024/11/microsoft-ignite-2024-security-crowdstrike-richixbw/ Wed, 20 Nov 2024 17:03:14 +0000 https://securityboulevard.com/?p=2037060 David “dwizzzle” Weston

BSODs begone! Redmond business leaders line up to say what’s new in Windows security.

The post Microsoft Veeps Ignite Fire Under CrowdStrike appeared first on Security Boulevard.

]]>
2037060
EPA IG Office: ‘High-Risk’ Security Flaws in Hundreds of Water Systems https://securityboulevard.com/2024/11/epa-ig-office-high-risk-security-flaws-in-hundreds-of-water-systems/ Tue, 19 Nov 2024 21:15:39 +0000 https://securityboulevard.com/?p=2036973 water system cyberthreats EPA OIG

The watchdog for the EPA found that, of 1,062 U.S. drinking water systems it assessed, 97 had "critical" or "high-risk" security flaws and another 211 had less dangerous vulnerabilities, risking threats from stolen data to disrupted service.

The post EPA IG Office: ‘High-Risk’ Security Flaws in Hundreds of Water Systems appeared first on Security Boulevard.

]]>
2036973
Zero-Day Exploits Surge in 2023, Cisco, Fortinet Vulnerabilities Targeted https://securityboulevard.com/2024/11/zero-day-exploits-surge-in-2023-cisco-fortinet-vulnerabilities-targeted/ Fri, 15 Nov 2024 09:31:00 +0000 https://securityboulevard.com/?p=2036691 zero-day, vulnerabilities, zero-trust app hardware zero-trust prepare

A report from the Five Eyes cybersecurity alliance, released by the CISA, highlights the majority of the most exploited vulnerabilities last year were initially zero-day flaws, a significant increase compared to 2022 when less than half of the top vulnerabilities were zero-day exploits.

The post Zero-Day Exploits Surge in 2023, Cisco, Fortinet Vulnerabilities Targeted appeared first on Security Boulevard.

]]>
2036691
NIST Clears Backlog of Known Security Flaws but Not All Vulnerabilities https://securityboulevard.com/2024/11/nist-clears-backlog-of-known-security-flaws-but-not-all-vulnerabilities/ Thu, 14 Nov 2024 16:41:27 +0000 https://securityboulevard.com/?p=2036558 NIST CSF vulnerabilities ransomware backlog

NIST, the embattled agency that analyzes security vulnerabilities, has cleared the backlog of known CVEs that hadn't been processed but needs more time to clear the entire backlog of unanalyzed flaws.

The post NIST Clears Backlog of Known Security Flaws but Not All Vulnerabilities appeared first on Security Boulevard.

]]>
2036558
These 20 D-Link Devices Have Critical RCE Bug — but NO Patch NEVER https://securityboulevard.com/2024/11/d-link-nas-wont-fix-richixbw/ Wed, 13 Nov 2024 17:22:08 +0000 https://securityboulevard.com/?p=2036204 xkcd.com/327 — “Exploits of a Mom”

‘Bobby’ flaw flagged WONTFIX: Company doesn’t make storage devices now; has zero interest in fixing this catastrophic vulnerability.

The post These 20 D-Link Devices Have Critical RCE Bug — but NO Patch NEVER appeared first on Security Boulevard.

]]>
2036204
Skeletons in the Closet: Legacy Software, Novel Exploits https://securityboulevard.com/2024/11/skeletons-in-the-closet-legacy-software-novel-exploits/ https://securityboulevard.com/2024/11/skeletons-in-the-closet-legacy-software-novel-exploits/#respond Wed, 13 Nov 2024 15:44:55 +0000 https://www.praetorian.com/?p=3278 The Praetorian team recently discovered a new vulnerability in Ivanti Endpoint Manager (EPM) which serves as a reminder to be aware of legacy systems - patch regularly and test often.

The post Skeletons in the Closet: Legacy Software, Novel Exploits appeared first on Praetorian.

The post Skeletons in the Closet: Legacy Software, Novel Exploits appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2024/11/skeletons-in-the-closet-legacy-software-novel-exploits/feed/ 0 2036321