Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Cisco, Hitachi, Microsoft and Deficiency Progress actively operated – Cisa sounds alarm
Global Security

Cisco, Hitachi, Microsoft and Deficiency Progress actively operated – Cisa sounds alarm

AdminBy AdminMarch 4, 2025No Comments2 Mins Read
New Exploited Vulnerabilities
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


04 March 2025Hacker NewsCyber ​​-aataka / vulnerability

New exploited vulnerabilities

Cybersecurity and US Infrastructure Agency (CISA) added Five Safety Disadvantages affecting Cisco, Hitachi Vantara, Microsoft Windows and Progress Whatsup Gold for their famous exploited vulnecs (Ship) A catalog based on evidence of active operation.

The list of vulnerabilities is the following –

  • Cve-2013-20118 (CVSS assessment: 6.5) -Touity of teams of introduction to the online router RV Cisco Small Business Router, which allows authentication, remote attackers, receive privileges at the root level and access unauthorized data (unlikely due to routers)
  • Cve-2022-43939 (CVSS assessment: 8.6) – vulnerability of the income vulnerability in Hitachi Vantara Pentaho Ba Server, resulting from non -canonical use
  • Cve-2022-43769 (CVSS assessment: 8.8) – Vulnerability of special introduction into Hitachi Vantara Pentaho Ba Server, which allows the attacker to enter spring templates into the properties files, which allows to perform arbitrary execution of commands (fixed in August 2024 with versions 9.3.2 and 9.4.0.1)
  • Cve-2018-8639 (CVSS assessment: 7.8) – Invalid resources or release vulnerability in Microsoft Windows Win32K, which allows local, valid escalation of privileges and launch of arbitrary code in the kernel mode (fixed in December 2018)
  • Cve-2024-4885 (CVSS assessment: 9.8) – vulnerability of the path that goes through Whatsup Gold, which allows an unauthorized attacker to achieve a remote code (recorded in version 2023.3 in June 2024)
Cybersecurity

There is little reports on how some of the aforementioned shortcomings are armed in the wild, but the French Cybersecurity Company disclosed Last week, the threatening subjects abuse CVE-2013-20118 to redirect the routers in a botnet called Polaredge.

As for the CVE-2024-4885, the Shadowserver Foundation said he has observe Attempts to operate against the lack of August 1, 2024. Data from Greynoise show What as many as eight unique IPs from Hong Kong, Russia, Brazil, South Korea and UK are associated with malicious exploitation of vulnerability.

In light of the active exploitation, the Federal Civil Executive Agency (FCEB) is urged to apply the necessary mitigations by March 24, 2025 to ensure their networks.

Found this article interesting? This article is a contribution to one of our esteemed partners. Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025

Malicious Pypi Masquerade Package as chimera module for theft Aws, CI/CD and MacOS

June 16, 2025

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025

Malicious Pypi Masquerade Package as chimera module for theft Aws, CI/CD and MacOS

June 16, 2025

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.