article thumbnail

A zero-day exploit for Log4j Java library could have a tsunami impact on IT giants

Security Affairs

Experts publicly disclose Proof-of-concept exploits for a critical zero-day vulnerability in the Apache Log4j Java-based logging library. Experts publicly disclose Proof-of-concept exploits for a critical remote code execution zero-day vulnerability, tracked a CVE-2021-44228 (aka Log4Shell ), in the Apache Log4j Java-based logging library.

Libraries 136
article thumbnail

Decommissioned medical infusion pumps sold on secondary market could reveal Wi-Fi configuration settings

Security Affairs

Experts warn that decommissioned medical infusion pumps sold via the secondary market could expose Wi-Fi configuration settings. The sale of decommissioned medical infusion pumps through the secondary market may lead to the potential exposure of Wi-Fi configuration settings. ” reads the analysis published by Rapid7.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

A WhatsApp zero-day exploit can cost several million dollars

Security Affairs

“The document said the exploit worked for Android versions 9 to 11, which was released in 2020, and that it took advantage of a flaw in the “image rendering library.” Unlike other zero-day brokers, such as Zerodium and Exodus Intelligence , Operation Zero focuses on the Russian market.

Marketing 125
article thumbnail

Meet The Team Behind Mayhem: Come See Us At These Upcoming June 2023 Events

ForAllSecure

Robert Vamosi , Director of Product Marketing Sheldon Warkentin , Head of Developer Experience Vincent Lussenburg , Director of Sales Engineering Lakshmia Ferba , Product Marketing Manager Q & A Get your burning questions answered by our knowledgeable experts. Share your feedback and shape the future of Mayhem.

article thumbnail

Unsecured Git server exposed Nissan North America

Security Affairs

– Nissan internal core mobile library – Nissan/Infiniti NCAR/ICAR services – client acquisition and retention tools – sale / market research tools + data – various marketing tools – the vehicle logistics portal (2/n) — tillie, doer of crime (@antiproprietary) January 4, 2021.

Libraries 107
article thumbnail

Uncovering the link between PrivateLoader PPI service and RisePro stealer

Security Affairs

The RisePro stealer first appeared in the threat landscape on December 2022, when it was advertised on the Russian Market underground marketplace. At the time of writing, Russian Market announced the availability of over 2,000 logs allegedly sourced from the RisePro infostealer. RisePro stealer logs appear on Russian Market.

article thumbnail

Cyber Defense Magazine – July 2020 has arrived. Enjoy it!

Security Affairs

OVER 165 PAGESALWAYS FREE – LOADED WITH EXCELLENT CONTENT Learn from the experts, cybersecurity best practices Find out about upcoming information security related conferences, expos and trade shows. Checkout our media kit and reach out to marketing@cyberdefensemagazine.com. appeared first on Security Affairs.

B2C 73