Episode 2: Behind the Scenes of a Tailor-Made Massive Phishing Campaign Part 2
Executive Summary Last summer, we investigated a massive, global phishing campaign impersonating almost 350 legitimate companies. Our continued investigation into this expansive phishing campaign revealed leaked backend source code, shedding light on the infrastructure behind the operation. This...
7AI Score
Security Bulletin: Multiple Vulnerabilities in IBM CloudPak for AIOps
Summary Multiple vulnerabilities were addressed in IBM Cloud Pak for AIOps version 4.6.0 Vulnerability Details ** CVEID: CVE-2022-25857 DESCRIPTION: **Java package org.yaml:snakeyam is vulnerable to a denial of service, caused by missing to nested depth limitation for collections. By sending a...
9.8CVSS
10AI Score
EPSS
Multiple vulnerabilities in TP-Link Omada system could lead to root access
The TP-Link Omada system is a software-defined networking solution for small to medium-sized businesses. It touts cloud-managed devices and local management for all Omada devices. The supported devices in this ecosystem vary greatly but include wireless access points, routers, switches, VPN...
8.1CVSS
9.4AI Score
0.001EPSS
CVE-2023-25801 affecting package tensorflow for versions less than 2.11.1-1
CVE-2023-25801 affecting package tensorflow for versions less than 2.11.1-1. A patched version of the package is...
8CVSS
9.9AI Score
0.0004EPSS
CVE-2023-25660 affecting package tensorflow for versions less than 2.11.1-1
CVE-2023-25660 affecting package tensorflow for versions less than 2.11.1-1. A patched version of the package is...
7.5CVSS
9.1AI Score
0.001EPSS
CVE-2023-25658 affecting package tensorflow for versions less than 2.11.1-1
CVE-2023-25658 affecting package tensorflow for versions less than 2.11.1-1. A patched version of the package is...
7.5CVSS
9.1AI Score
0.001EPSS
CVE-2023-29406 affecting package golang for versions less than 1.20.7-1
CVE-2023-29406 affecting package golang for versions less than 1.20.7-1. A patched version of the package is...
6.5CVSS
7.3AI Score
0.001EPSS
CVE-2023-29403 affecting package golang for versions less than 1.20.7-1
CVE-2023-29403 affecting package golang for versions less than 1.20.7-1. A patched version of the package is...
7.8CVSS
7.3AI Score
0.001EPSS
CVE-2023-29402 affecting package golang for versions less than 1.20.7-1
CVE-2023-29402 affecting package golang for versions less than 1.20.7-1. A patched version of the package is...
9.8CVSS
9.7AI Score
0.005EPSS
CVE-2023-24538 affecting package golang for versions less than 1.19.8-1
CVE-2023-24538 affecting package golang for versions less than 1.19.8-1. A patched version of the package is...
9.8CVSS
10AI Score
0.003EPSS
CVE-2022-41725 affecting package msft-golang for versions less than 1.19.6-1
CVE-2022-41725 affecting package msft-golang for versions less than 1.19.6-1. A patched version of the package is...
7.5CVSS
9.1AI Score
0.001EPSS
CVE-2021-3672 affecting package pgbouncer 1.16.1-1
CVE-2021-3672 affecting package pgbouncer 1.16.1-1. No patch is available...
5.6CVSS
7AI Score
0.002EPSS
CVE-2011-1429 affecting package mutt 2.2.12-1
CVE-2011-1429 affecting package mutt 2.2.12-1. No patch is available...
6.4AI Score
0.003EPSS
CVE-2023-24536 affecting package golang for versions less than 1.21.6-1
CVE-2023-24536 affecting package golang for versions less than 1.21.6-1. A patched version of the package is...
7.5CVSS
7.3AI Score
0.005EPSS
CVE-2023-45287 affecting package golang for versions less than 1.21.6-1
CVE-2023-45287 affecting package golang for versions less than 1.21.6-1. A patched version of the package is...
7.5CVSS
7.3AI Score
0.001EPSS
CVE-2023-45284 affecting package golang for versions less than 1.21.6-1
CVE-2023-45284 affecting package golang for versions less than 1.21.6-1. A patched version of the package is...
5.3CVSS
7.3AI Score
0.001EPSS
CVE-2023-39326 affecting package golang for versions less than 1.21.6-1
CVE-2023-39326 affecting package golang for versions less than 1.21.6-1. A patched version of the package is...
5.3CVSS
7.3AI Score
0.001EPSS
CVE-2023-48795 affecting package moby-engine for versions less than 20.10.27-1
CVE-2023-48795 affecting package moby-engine for versions less than 20.10.27-1. A patched version of the package is...
5.9CVSS
6.8AI Score
0.963EPSS
CVE-2023-45285 affecting package golang for versions less than 1.21.6-1
CVE-2023-45285 affecting package golang for versions less than 1.21.6-1. A patched version of the package is...
7.5CVSS
7.7AI Score
0.001EPSS
CVE-2023-44487 affecting package golang for versions less than 1.21.6-1
CVE-2023-44487 affecting package golang for versions less than 1.21.6-1. A patched version of the package is...
7.5CVSS
7.3AI Score
0.732EPSS
CVE-2023-29400 affecting package golang for versions less than 1.20.7-1
CVE-2023-29400 affecting package golang for versions less than 1.20.7-1. A patched version of the package is...
7.3CVSS
7.3AI Score
0.001EPSS
CVE-2023-24540 affecting package msft-golang for versions less than 1.20.11-1
CVE-2023-24540 affecting package msft-golang for versions less than 1.20.11-1. A patched version of the package is...
9.8CVSS
7.3AI Score
0.003EPSS
CVE-2022-3114 affecting package kernel 5.15.158.2-1
CVE-2022-3114 affecting package kernel 5.15.158.2-1. No patch is available...
5.5CVSS
6.5AI Score
0.0004EPSS
CVE-2022-45885 affecting package kernel 5.15.158.2-1
CVE-2022-45885 affecting package kernel 5.15.158.2-1. No patch is available...
7CVSS
7.3AI Score
0.0004EPSS
CVE-2022-40133 affecting package kernel 5.15.158.2-1
CVE-2022-40133 affecting package kernel 5.15.158.2-1. No patch is available...
6.3CVSS
6.5AI Score
0.0004EPSS
CVE-2022-2961 affecting package kernel 5.15.158.2-1
CVE-2022-2961 affecting package kernel 5.15.158.2-1. No patch is available...
7CVSS
6.8AI Score
0.0004EPSS
CVE-2021-46828 affecting package libtirpc 1.3.3-1
CVE-2021-46828 affecting package libtirpc 1.3.3-1. This CVE either no longer is or was never...
7.5CVSS
9.1AI Score
0.005EPSS
CVE-2021-3847 affecting package kernel 5.15.158.2-1
CVE-2021-3847 affecting package kernel 5.15.158.2-1. No patch is available...
7.8CVSS
7.7AI Score
0.0004EPSS
CVE-2007-6353 affecting package exiv2 0.28.0-1
CVE-2007-6353 affecting package exiv2 0.28.0-1. No patch is available...
6.4AI Score
0.021EPSS
CVE-2023-45283 affecting package golang for versions less than 1.21.6-1
CVE-2023-45283 affecting package golang for versions less than 1.21.6-1. A patched version of the package is...
7.5CVSS
7.3AI Score
0.001EPSS
CVE-2023-45285 affecting package msft-golang for versions less than 1.22.3-1.
CVE-2023-45285 affecting package msft-golang for versions less than 1.22.3-1.. A patched version of the package is...
7.5CVSS
7.7AI Score
0.001EPSS
CVE-2023-45283 affecting package msft-golang for versions less than 1.20.11-1
CVE-2023-45283 affecting package msft-golang for versions less than 1.20.11-1. A patched version of the package is...
7.5CVSS
7.3AI Score
0.001EPSS
CVE-2023-25674 affecting package tensorflow for versions less than 2.11.1-1
CVE-2023-25674 affecting package tensorflow for versions less than 2.11.1-1. A patched version of the package is...
7.5CVSS
9.9AI Score
0.001EPSS
CVE-2023-25663 affecting package tensorflow for versions less than 2.11.1-1
CVE-2023-25663 affecting package tensorflow for versions less than 2.11.1-1. A patched version of the package is...
7.5CVSS
9.9AI Score
0.001EPSS
CVE-2023-25673 affecting package tensorflow for versions less than 2.11.1-1
CVE-2023-25673 affecting package tensorflow for versions less than 2.11.1-1. A patched version of the package is...
7.5CVSS
9.1AI Score
0.001EPSS
CVE-2023-27579 affecting package tensorflow for versions less than 2.11.1-1
CVE-2023-27579 affecting package tensorflow for versions less than 2.11.1-1. A patched version of the package is...
7.5CVSS
9.1AI Score
0.001EPSS
CVE-2023-25671 affecting package tensorflow for versions less than 2.11.1-1
CVE-2023-25671 affecting package tensorflow for versions less than 2.11.1-1. A patched version of the package is...
7.5CVSS
7.7AI Score
0.001EPSS
CVE-2023-25666 affecting package tensorflow for versions less than 2.11.1-1
CVE-2023-25666 affecting package tensorflow for versions less than 2.11.1-1. A patched version of the package is...
7.5CVSS
7.7AI Score
0.001EPSS
CVE-2023-25659 affecting package tensorflow for versions less than 2.11.1-1
CVE-2023-25659 affecting package tensorflow for versions less than 2.11.1-1. A patched version of the package is...
7.5CVSS
9.1AI Score
0.001EPSS
CVE-2023-39318 affecting package msft-golang for versions less than 1.20.10-1
CVE-2023-39318 affecting package msft-golang for versions less than 1.20.10-1. A patched version of the package is...
6.1CVSS
7.3AI Score
0.001EPSS
CVE-2023-29409 affecting package msft-golang for versions less than 1.20.7-1
CVE-2023-29409 affecting package msft-golang for versions less than 1.20.7-1. A patched version of the package is...
5.3CVSS
7.3AI Score
0.001EPSS
CVE-2023-24539 affecting package msft-golang for versions less than 1.20.11-1
CVE-2023-24539 affecting package msft-golang for versions less than 1.20.11-1. A patched version of the package is...
7.3CVSS
7.3AI Score
0.001EPSS
CVE-2024-24784 affecting package golang for versions less than 1.21.6-1
CVE-2024-24784 affecting package golang for versions less than 1.21.6-1. A patched version of the package is...
7.3AI Score
0.0004EPSS
CVE-2022-29526 affecting package golang for versions less than 1.21.6-1
CVE-2022-29526 affecting package golang for versions less than 1.21.6-1. A patched version of the package is...
5.3CVSS
7.3AI Score
0.002EPSS
CVE-2023-24532 affecting package golang for versions less than 1.21.6-1
CVE-2023-24532 affecting package golang for versions less than 1.21.6-1. A patched version of the package is...
5.3CVSS
7.3AI Score
0.001EPSS
CVE-2022-29526 affecting package prometheus for versions less than 2.37.0-1
CVE-2022-29526 affecting package prometheus for versions less than 2.37.0-1. A patched version of the package is...
5.3CVSS
5.7AI Score
0.002EPSS
CVE-2023-51767 affecting package openssh for versions less than 1.9.4-1
CVE-2023-51767 affecting package openssh for versions less than 1.9.4-1. A patched version of the package is...
7CVSS
7AI Score
0.001EPSS
CVE-2023-25670 affecting package tensorflow for versions less than 2.11.1-1
CVE-2023-25670 affecting package tensorflow for versions less than 2.11.1-1. A patched version of the package is...
7.5CVSS
8.1AI Score
0.001EPSS
CVE-2023-25664 affecting package tensorflow for versions less than 2.11.1-1
CVE-2023-25664 affecting package tensorflow for versions less than 2.11.1-1. A patched version of the package is...
9.8CVSS
9.9AI Score
0.001EPSS
CVE-2023-3341 affecting package bind for versions less than 9.16.44-1
CVE-2023-3341 affecting package bind for versions less than 9.16.44-1. A patched version of the package is...
7.5CVSS
8.1AI Score
0.002EPSS