CVE-2021-27461
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected webserver applications allow access to stored data that can be obtained by using specially crafted URLs.
Critical Infrastructure Security , Cybercrime , Cybercrime as-a-service Company Says It Will Take Several Days to Restore Supply Chain Scott Ferguson (Ferguson_Writes) • May 12, 2021 Photo: Pete D via Flickr/CC Colonial Pipeline Co. announced Wednesday that it had restarted its operations following a ransomware attack last Friday that forced the company to…
Microsoft patches new Exchange CVEs, credits NSA with discovery | IT Security News Sponsors Endpoint Cybersecurity www.endpoint-cybersecurity.com – Consulting in building your security products– Employee awareness training– Security tests for applications and pentesting… and more. Daily Summary Categories CategoriesSelect Category(ISC)2 Blog (323)(ISC)2 Blog infosec (13)(ISC)² Blog (341)2020-12-08 – Files for an ISC diary (recent Qakbot activity) (1)2020-12-11 – Quick…
London, Oxford University has confirmed that one of its laboratories involved in Covid-19 research suffered cyberattack after an investigation by Forbes suggested that hackers were showing off access to a number of systems. The university on Thursday, however, said that there has been “no impact” on any clinical research. The hack is understood to have…
Endpoint Security , Internet of Things Security Standard Designed to Cut the Cost and Time to Securely Connect IoT Devices Prajeet Nair (@prajeetspeaks) • April 22, 2021 (Source: Pixabay) The Fido Alliance, an association that has developed voluntary authentication standards with a goal of minimizing the use of passwords, has launched an onboarding…
The Biden administration issued new sanctions against Russia on Thursday. The sanctions target over 30 Russian entities and expel 10 Russian diplomats from the US. The sanctions also accuse Russia’s foreign intelligence service of being behind the SolarWinds hack. See more stories on Insider’s business page. The Biden administration on Thursday slapped Russia with a…
Cybersecurity analysts Lloyd Macrohon and Rodel Mendrez have recently inspected a new piece of malware that they’ve encountered during a breach investigation. Dubbed “Pingback”, the malware uses ICMP (Internet Control Message Protocol) tunneling for its backdoor communications and operates with various modes to escalate the chances of a successful attack. Pingback (“oci.dll“) achieves its purpose…