Advertisement
Top

Category: Vulnerabilities


Threats & Malware, Vulnerabilities

Four in five Apache Struts 2 downloads are for versions featuring critical flaw

December 21, 2023

Via: The Register

Security vendor Sonatype believes developers are failing to address the critical remote code execution (RCE) vulnerability in the Apache Struts 2 framework, based on recent downloads of the code. The vulnerability, tracked as CVE-2023-50164, is rated 9.8 out of 10 […]


Threats & Malware, Vulnerabilities

SSH shaken, not stirred by Terrapin vulnerability

December 20, 2023

Via: The Register

A vulnerability in the SSH protocol can be exploited by a well-placed adversary to weaken the security of people’s connections, if conditions are right. In a successful man-in-the-middle attack, the adversary may be able to force SSH clients to use […]


Threats & Malware, Vulnerabilities

Before you go away for Xmas: You’ve patched that critical Perforce Server hole, right?

December 19, 2023

Via: The Register

Four vulnerabilities in Perforce Helix Core Server, including one critical remote code execution bug, should be patched “immediately,” according to Microsoft, which spotted the flaws and disclosed them to the software vendor. Perforce Server is a source code management platform […]


Threats & Malware, Vulnerabilities

Report: Attackers Move Lightning Fast to Capitalize on  Vulnerabilities

December 19, 2023

Via: SecureWorld

This morning, the Qualys Threat Research Unit released its 2023 Threat Landscape Year in Review report. In 2023, the Qualys Threat Research Unit (TRU) witnessed a critical trend in exploiting high-risk vulnerabilities. Its analysis reveals a startling insight into how […]


Threats & Malware, Vulnerabilities

Multiple flaws in pfSense firewall can lead to arbitrary code execution

December 15, 2023

Via: Security Affairs

pfSense is a popular open-source firewall solution maintained by Netgate, researchers discovered multiple security issues affecting it. Researchers from SonarCloud discovered several security issues, Cross-Site Scripting (XSS) vulnerabilities and a Command Injection vulnerability in pfSense CE (CVE-2023-42325, CVE-2023-42327, CVE-2023-42326). The […]


Threats & Malware, Vulnerabilities

Lazarus APT Continues to Exploit Log4j Vulnerability

December 13, 2023

Via: SecureWorld

Lazarus, the notorious North Korean hacking group, has once again made headlines, this time by exploiting the Log4j vulnerability, despite it being disclosed two years ago. The Log4j vulnerability, officially known as CVE-2021-44228, continues to pose significant risks to organizations […]


Threats & Malware, Vulnerabilities

Atlassian security advisory reveals four fresh critical flaws – in mail with dead links

December 6, 2023

Via: The Register

Atlassian has emailed its customers to warn of four critical vulnerabilities, but the message had flaws of its own – the links it contained weren’t live for all readers at the time of despatch. The email, seen by The Register, […]


Threats & Malware, Vulnerabilities

A year on, CISA realizes debunked vuln actually a dud and removes it from must-patch list

December 6, 2023

Via: The Register

A security vulnerability previously added to CISA’s Known Exploited Vulnerability catalog (KEV), which was recognized by CVE Numbering Authorities (CNA), and included in reputable threat reports is now being formally rejected by infosec organizations. CISA removed CVE-2022-28958 from its KEV […]


Threats & Malware, Vulnerabilities

Apple slaps patch on WebKit holes in iPhones and Macs amid fears of active attacks

December 1, 2023

Via: The Register

Apple has issued emergency fixes to plug security flaws in iPhones, iPads, and Macs that may already be under attack. The software updates for iOS, iPadOS, macOS Sonoma, and Safari web browser address two bugs: an out-of-bounds read flaw tracked […]


Threats & Malware, Vulnerabilities

Weak session keys let snoops take a byte out of your Bluetooth traffic

November 30, 2023

Via: The Register

Multiple Bluetooth chips from major vendors such as Qualcomm, Broadcom, Intel, and Apple are vulnerable to a pair of security flaws that allow a nearby miscreant to impersonate other devices and intercept data. The weaknesses were identified by Daniele Antonioli, […]


Threats & Malware, Vulnerabilities

PoC for Splunk Enterprise RCE flaw released (CVE-2023-46214)

November 27, 2023

Via: Help Net Security

A proof-of-concept (PoC) exploit for a high-severity flaw in Splunk Enterprise (CVE-2023-46214) that can lead to remote code execution has been made public. Users are advised to implement the provided patches or workarounds quickly. About CVE-2023-46214 Splunk Enterprise is a […]


Threats & Malware, Vulnerabilities

A critical OS command injection flaw affects Fortinet FortiSIEM

November 17, 2023

Via: Security Affairs

Fortinet is warning customers of a critical OS command injection vulnerability, tracked as CVE-2023-36553 (CVSS score 9.3), in FortiSIEM report server. A remote, unauthenticated attacker can exploit the flaw to execute commands by sending specially crafted API requests. “An improper […]


Threats & Malware, Vulnerabilities

Another month, another bunch of fixes for Microsoft security bugs exploited in the wild

November 15, 2023

Via: The Register

Heads up: Microsoft’s November Patch Tuesday includes fixes for about 60 vulnerabilities – including three that have already been found and abused in the wild. First of that trio is CVE-2023-36033: a Windows Desktop Manager (WDM) Core Library elevation-of-privilege vulnerability. […]


Threats & Malware, Vulnerabilities

VMware disclosed a critical and unpatched authentication bypass flaw in VMware Cloud Director Appliance

November 15, 2023

Via: Security Affairs

VMware disclosed an authentication bypass vulnerability, tracked as CVE-2023-34060 (CVSS score 9.8), in its Cloud Director Appliance that can be exploited by an attacker with network access to the appliance bypassing login restrictions when authenticating on port 22 (ssh) or […]


Threats & Malware, Vulnerabilities

Royal Mail cybersecurity still a bit of a mess, infosec bods claim

November 13, 2023

Via: The Register

After spending almost a year cleaning up after various security snafus, the UK’s Royal Mail had an open redirect flaw on one of its sites, according to infosec types. We’re told this vulnerability potentially exposes customers to malware infections and […]


Threats & Malware, Vulnerabilities

CISA adds SLP flaw to its Known Exploited Vulnerabilities catalog

November 9, 2023

Via: Security Affairs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability CVE-2023-29552 (CVSS score: 7.5) in the Service Location Protocol (SLP) to its Known Exploited Vulnerabilities catalog. The Service Location Protocol (SLP) is a legacy service discovery protocol that allows […]


Threats & Malware, Vulnerabilities

Atlassian cranks up the threat meter to max for Confluence authorization flaw

November 8, 2023

Via: The Register

Atlassian reassessed the severity rating of the recent improper authorization vulnerability in Confluence Data Center and Server, raising the CVSS score from 9.1 to a maximum of 10. The company overhauled its security advisory for CVE-2023-22518 after it realized there […]


Threats & Malware, Vulnerabilities

Microsoft 365 apps have a lot of new security vulnerabilities – here’s what we know

November 6, 2023

Via: TechRadar

Cybersecurity researchers from Zscaler have discovered more than a hundred vulnerabilities in Microsoft 365 that were introduced with the addition of SketchUp into the cloud productivity suite. To make matters worse, they claim to have managed to bypass the patches […]


Threats & Malware, Vulnerabilities

Critical Apache ActiveMQ flaw under attack by ‘clumsy’ ransomware crims

November 2, 2023

Via: The Register

Security researchers have confirmed that ransomware criminals are capitalizing on a maximum-severity vulnerability in Apache ActiveMQ. Announced on October 25 and tracked as CVE-2023-46604, the insecure deserialization vulnerability allows for remote code execution (RCE) on affected versions. “Apache ActiveMQ is […]


Threats & Malware, Vulnerabilities

‘Citrix Bleed’ Vulnerability Raises Concerns as Exploits Continue

November 2, 2023

Via: SecureWorld

In the ever-evolving landscape of cybersecurity threats, the discovery of serious vulnerabilities can send shockwaves through the digital world. One such recent incident that has captured the attention of security professionals is the exploitation of a critical vulnerability known as […]