CISA adds Oracle, SugarCRM bugs to its Known Exploited Vulnerabilities Catalog

US CISA added actively exploited vulnerabilities in SugarCRM and Oracle products to its Known Exploited Vulnerabilities Catalog. The Cybersecurity and Infrastructure Security Agency (CISA) added Oracle and SugarCRM flaws, respectively tracked as CVE-2022-21587 and CVE-2023-22952, to its Known Exploited Vulnerabilities Catalog. The CVE-2022-21587 flaw (CVSS score 9.8) affects the Oracle E-Business Suite, which is a set […]

The post CISA adds Oracle, SugarCRM bugs to its Known Exploited Vulnerabilities Catalog appeared first on Security Affairs.

Onenote Malware: Classification and Personal Notes

During the past 4 months Microsoft Onenote file format has been (ab)used as Malware carrier by different criminal groups. While the main infection vector is still on eMail side – so nothing really relevant to write on – the used techniques, the templates and the implemented code to inoculate Malware changed a lot. So it […]

India’s Largest Truck Brokerage Company Leaking 140GB of Data

By Waqas
The cause of the data leak is an ongoing server misconfiguration, identified by researchers on Shodan, the search engine for IoT devices.
This is a post from HackRead.com Read the original post: India’s Largest Truck Brokerage Company Le…

Tesla Asleep at the Wheel

Tesla has been charged multiple times with engineering design failures related to their driver alertness system. These failures are implicated in sky rocketing Tesla deaths. And so in 2023 here’s yet more proof that the company, some would argue …

Exploitation attempts for Oracle E-Business Suite flaw observed after PoC release

Threat actors started exploiting a critical Oracle E-Business Suite flaw, tracked as CVE-2022-21587, shortly after a PoC was published. Shadowserver researchers warn that threat actors have started attempting to exploit critical Oracle E-Business Suite flaw (CVE-2022-21587) shortly after a PoC was published. The E-Business Suite is a set of enterprise applications that allows organizations automate […]

The post Exploitation attempts for Oracle E-Business Suite flaw observed after PoC release appeared first on Security Affairs.