"GeoServer Vulnerability Targeted by Hackers to Deliver Backdoors and Botnet Malware"

"GeoServer Vulnerability Targeted by Hackers to Deliver Backdoors and Botnet Malware"

Multiple campaigns have exploited a recently disclosed OSGeo GeoServer GeoTools security flaw to deliver cryptocurrency miners, botnet malware, and a backdoor. The critical Remote Code Execution (RCE) bug enables malicious actors to take over vulnerable instances. Due to its active exploitation, the US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog in mid-July. This article continues to discuss the exploitation of a security vulnerability in OSGeo GeoServer GeoTools.

Submitted by Gregory Rigby on

IEEE/ACM International Symposium on Microarchitecture (MICRO)

"The IEEE/ACM International Symposium on Microarchitecture (MICRO) is the premier forum for for presenting, discussing, and debating innovative microarchitecture ideas and techniques for advanced computing and communication systems. This symposium brings together researchers in fields related to microarchitecture, compilers, chips, and systems for technical exchange on traditional microarchitecture topics and emerging research areas."

Topics of interest include, but are not limited to privacy and security.

 

2024 International Conference on Research in Adaptive and Convergent Systems (RACS)

"The RACS conference aims primarily at researchers who have experience in reliable and convergent computing systems and are engaged in the design and implementation of new computing applications. Each year RACS brings together engineers and scientists from diverse communities with interests in practical computing technologies and creates an environment for them to discuss and report experimental results, novel designs, work-in-progress, experiences, case studies, and trend-setting ideas."

Topics of interest include, but are not limited to security.

2024 ACM/IEEE International Conference on Computer-Aided Design

"The International Conference on Computer-Aided Design focuses on advancements and research in the field of electronic design automation (EDA) and computer-aided design (CAD) for integrated circuits and systems. Topics include innovations in design methodologies, tools, algorithms, and technologies related to the development of electronic systems."

Topics of interest include, but are not limited to privacy and security.

 

39th IEEE/ACM International Conference on Automated Software Engineering (ASE 2024)

"The ASE conference is the premier research forum for Automated Software Engineering. Each year, it brings together researchers and practitioners from academia and industry to discuss foundations, techniques, and tools for automating the analysis, design, implementation, testing, and maintenance of large software systems."

Topics of interest include, but are not limited to privacy and security.

2024 International Conference on Information and Knowledge Management (CIKM)

"The Conference on Information and Knowledge Management (CIKM) provides an international forum for presentation and discussion of research on information and knowledge management, as well as recent advances on data and knowledge bases. The purpose of the conference is to identify challenging problems facing the development of future knowledge and information systems, and to shape future directions of research by soliciting and reviewing high quality, applied and theoretical research findings."

2024 ACM Special Interest Group on Design of Communication (SIGDOC ‘24) Conference

"In recent years, technical communication scholars and practitioners are increasingly engaging with augmented and virtual reality, augmentation technologies, and now generative AI. These technologies, for better or worse, are increasingly integrated into our toolsets, including but not limited to content management systems, graphic design software, learning management systems, and research software. These emerging tools and technologies promise to make us more efficient and connected, but at what cost? Will automation devalue the human in human-computer interaction?

"Veeam Patches Critical Vulnerabilities in Enterprise Products"

"Veeam Patches Critical Vulnerabilities in Enterprise Products"

Veeam recently announced patches for multiple vulnerabilities in its enterprise products, including critical severity bugs that could lead to remote code execution (RCE).  The company resolved six flaws in its Backup & Replication product, including a critical severity issue that could be exploited remotely, without authentication, to execute arbitrary code.  Tracked as CVE-2024-40711, the security defect has a CVSS score of 9.8.

Submitted by Adam Ekwall on
Subscribe to