Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-33128PUBLISHED: 2022-06-25RG-EG series gateway EG350 EG_RGOS 11.1(6) was discovered to contain a SQL injection vulnerability via the function get_alarmAction at /alarm_pi/alarmService.php.
CVE-2021-40894PUBLISHED: 2022-06-24A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in underscore-99xp v1.7.2 when the deepValueSearch function is called.
CVE-2022-32997PUBLISHED: 2022-06-24The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
CVE-2022-32998PUBLISHED: 2022-06-24The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
CVE-2022-32999PUBLISHED: 2022-06-24The cloudlabeling package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
User Rank: Ninja
12/6/2014 | 10:49:21 PM
I knew you would be all over this story Sara ! : ) This one really tops the cake. I have not stopped laughing since I heard the news ! Matter of fact I am laugh now.
Easily one of the most arrogant companies around - Sony thought they could take a light hearted ( an oxymoron for sure in the case of Sony ) poke at a leader of a country known to harbor hackers or at least have an connection to the network of hackers that routinely breeches U.S. systems from banking to retail ?
Knowing that their systems have already been compromised. Can you say "arrogance" ? And once the arrogant bully was hit in the eye - he ran to the FBI and cried foul. ( I can barely finished this post - as the chuckle rises from my belly.)
So initially it was a handful of yet to be released ( block busters ) , and now we learn the damage includes salaries and social security numbers !
I am not laughing anymore. And neither are the people who have been compromised by Sony's habitual incompetence and arrogance.
Sony a technology company ? I think that is a reach to be honest.