A vulnerability (CVE-2024-31497) in PuTTY, a popular SSH and Telnet client, could allow attackers to recover NIST P-521 client keys due to the “heavily biased” ECDSA nonces (random values used once), researchers have discovered.
CVE-2024-31497
“To be more precise, the first 9 bits of each ECDSA ...
Search found 11 matches
- Wed Apr 17, 2024 6:54 am
- Forum: Known Exploited Vulnerability
- Topic: PuTTY vulnerability can be exploited to recover private keys (CVE-2024-31497)
- Replies: 0
- Views: 23652
- Wed Apr 10, 2024 6:40 am
- Forum: Known Exploited Vulnerability
- Topic: Critical takeover vulnerabilities in 92,000 D-Link devices under active exploitation
- Replies: 0
- Views: 9017
Critical takeover vulnerabilities in 92,000 D-Link devices under active exploitation
Hackers are actively exploiting a pair of recently discovered vulnerabilities to remotely commandeer network-attached storage devices manufactured by D-Link, researchers said Monday.
Roughly 92,000 devices are vulnerable to the remote takeover exploits, which can be remotely transmitted by sending ...
Roughly 92,000 devices are vulnerable to the remote takeover exploits, which can be remotely transmitted by sending ...
- Sun Apr 07, 2024 8:20 am
- Forum: Known Exploited Vulnerability
- Topic: Cisco Warns of Vulnerability in Discontinued Small Business Routers
- Replies: 0
- Views: 8172
Cisco Warns of Vulnerability in Discontinued Small Business Routers
Cisco has issued a warning from a cross-site scripting (XSS) vulnerability in end-of-life (EoL) RV series small business routers.
Tracked as CVE-2024-20362 and remotely exploitable without authentication, the flaw impacts the small business RV016, RV042, RV042G, RV082, RV320, and RV325 routers ...
Tracked as CVE-2024-20362 and remotely exploitable without authentication, the flaw impacts the small business RV016, RV042, RV042G, RV082, RV320, and RV325 routers ...
- Tue Apr 02, 2024 10:12 am
- Forum: Known Exploited Vulnerability
- Topic: AT&T Confirms 73M Customers Affected in Data Leak
- Replies: 0
- Views: 9029
AT&T Confirms 73M Customers Affected in Data Leak
AT&T denies any evidence of unauthorized access but admits that a data set released on the Dark Web including Social Security numbers and other sensitive information on tens of millions of customers is genuine.
Two weeks after a massive tranche of data, including purported sensitive information on ...
Two weeks after a massive tranche of data, including purported sensitive information on ...
- Wed Mar 20, 2024 12:36 pm
- Forum: Known Exploited Vulnerability
- Topic: API environments becoming hotspots for exploitation
- Replies: 0
- Views: 9381
API environments becoming hotspots for exploitation
A total of 29% of web attacks targeted APIs over 12 months (January through December 2023), indicating that APIs are a focus area for cybercriminals, according to Akamai.
APIs risk exposure
API integration amplifies risk exposure for enterprises
APIs are at the heart of digital transformation in ...
APIs risk exposure
API integration amplifies risk exposure for enterprises
APIs are at the heart of digital transformation in ...
- Wed Mar 13, 2024 7:56 am
- Forum: Known Exploited Vulnerability
- Topic: March 2024 Patch Tuesday: Microsoft fixes critical bugs in Windows Hyper-V
- Replies: 0
- Views: 26275
March 2024 Patch Tuesday: Microsoft fixes critical bugs in Windows Hyper-V
Last month, though, several days after Patch Tuesday, the company updated two advisories to say that those particular vulnerabilities were being exploited in the wild.
One of the two – CVE-2024-21338, an elevation of privilege vulnerability affecting the Windows Kernel – had been reported to ...
One of the two – CVE-2024-21338, an elevation of privilege vulnerability affecting the Windows Kernel – had been reported to ...
- Wed Feb 21, 2024 8:06 am
- Forum: Known Exploited Vulnerability
- Topic: Rhysida ransomware cracked! Free decryption tool released
- Replies: 0
- Views: 111923
Rhysida ransomware cracked! Free decryption tool released
Good news for organisations who have fallen victim to the notorious Rhysida ransomware.
A group of South Korean security researchers have uncovered a vulnerability in the infamous ransomware. This vulnerability provides a way for encrypted files to be unscrambled.
Researchers from Kookmin ...
A group of South Korean security researchers have uncovered a vulnerability in the infamous ransomware. This vulnerability provides a way for encrypted files to be unscrambled.
Researchers from Kookmin ...
- Sun Feb 04, 2024 7:05 am
- Forum: Known Exploited Vulnerability
- Topic: Cloudflare Falls Victim to Cyberattack Leveraging Credentials from Okta Breach
- Replies: 0
- Views: 82871
Cloudflare Falls Victim to Cyberattack Leveraging Credentials from Okta Breach
Cloudflare disclosed a security breach today, revealing that a suspected nation-state attacker infiltrated its internal Atlassian server.
The attack, which began on November 14, compromised Cloudflare’s Confluence wiki, Jira bug database, and Bitbucket source code management system.
How did ...
The attack, which began on November 14, compromised Cloudflare’s Confluence wiki, Jira bug database, and Bitbucket source code management system.
How did ...
- Sun Feb 04, 2024 6:59 am
- Forum: Known Exploited Vulnerability
- Topic: CISA and FBI Release Secure by Design Alert Urging Manufacturers to Eliminate Defects in SOHO Routers
- Replies: 0
- Views: 225350
CISA and FBI Release Secure by Design Alert Urging Manufacturers to Eliminate Defects in SOHO Routers
CISA and the Federal Bureau of Investigation (FBI) published guidance on Security Design Improvements for SOHO Device Manufacturers as a part of the new Secure by Design (SbD) Alert series that focuses on how manufacturers should shift the burden of security away from customers by integrating ...
- Wed Jan 17, 2024 8:48 am
- Forum: Known Exploited Vulnerability
- Topic: Critical flaw found in WordPress plugin used on over 300,000 websites
- Replies: 0
- Views: 28783
Critical flaw found in WordPress plugin used on over 300,000 websites
A WordPress plugin used on over 300,000 websites has been found to contain vulnerabilities that could allow hackers to seize control.
Security researchers at Wordfence found two critical flaws in the POST SMTP Mailer plugin.
The first flaw made it possible for attackers to reset the plugin's ...
Security researchers at Wordfence found two critical flaws in the POST SMTP Mailer plugin.
The first flaw made it possible for attackers to reset the plugin's ...