Remove 01
Remove 2020 Remove 2024 Remove Access Remove Risk
article thumbnail

CISA adds Apache Flink flaw to its Known Exploited Vulnerabilities catalog

Security Affairs

CISA adds Apache Flink improper access control vulnerability to its Known Exploited Vulnerabilities catalog. The issue, tracked as CVE-2020-17519 , is an improper access control vulnerability in Apache Flink. This type of vulnerability can lead to unauthorized access, data breaches, and other security issues.

IT 93
article thumbnail

CISA adds Microsoft Windows Print Spooler flaw to its Known Exploited Vulnerabilities catalog

Security Affairs

Since at least June 2020, and possibly earlier, the cyberespionage group has used the tool GooseEgg to exploit the CVE-2022-38028 vulnerability. APT28 deployed GooseEgg to gain elevated access to target systems and steal credentials and sensitive information. CISA orders federal agencies to fix this vulnerability by May 14, 2024.

IT 117
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

CISA adds Roundcube Webmail Persistent XSS bug to its Known Exploited Vulnerabilities catalog

Security Affairs

It provides a user-friendly interface for accessing email accounts via a web browser. CISA orders federal agencies to fix this vulnerability by March 4, 2024. ESET researchers pointed out that is a different vulnerability than CVE-2020-35730 , that the group exploited in other attacks. x before 1.5.4, x before 1.6.3.

IT 99
article thumbnail

CNIL publishes a draft TIA guide

Data Protection Report

It is currently in a consultation phase, with the consultation due to close on 12 February 2024 and the final guidance expected later in the year. 2] EDPB, Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data, 18 June 2021. [3] 31, 39, 44, 45. [10]

GDPR 75