An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about internal network resources via the hardcoded DNS resolver configuration.
Daily Archives: March 10, 2022
CVE-2020-36123
saitoha libsixel v1.8.6 was discovered to contain a double free via the component sixel_chunk_destroy at /root/libsixel/src/chunk.c.
CVE-2020-14115
A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code.
CVE-2020-14112
Information Leak Vulnerability exists in the Xiaomi Router AX6000. The vulnerability is caused by incorrect routing configuration. Attackers can exploit this vulnerability to download part of the files in Xiaomi Router AX6000.
CVE-2020-14111
A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code.
Qakbot Debuts New Technique
Old botnet performs new trick by inserting itself into the middle of email threads
Alleged Kaseya Attacker Extradited to US
Defendant indicted over deployment of REvil ransomware arrives in America
AI Accountability Framework Created to Guide Use of AI in Security
The framework aims to mitigate ethical issues surrounding use of AI in security
Ragnar Locker ransomware – what you need to know
The FBI has warned that the Ragnar Locker gang has infected at least 52 critical infrastructure organisations across America with its ransomware.
Read more in my article on the Tripwire State of Security blog.
No, women in Ukraine aren’t up for a sexy webcam chat right now
No – there aren’t women in Ukraine are keen to have a sexy webcam chat with you right now.