Top

Tag: vulnerabilities


Threats & Malware, Vulnerabilities

Jenkins Server Vulnerabilities Chained for Remote Code Execution 

March 9, 2023

Via: Security Week

Tracked as CVE-2023-27898 and CVE-2023-27905 and impacting both Jenkins Server and Update Center, the two security defects are described as cross-site scripting (XSS) bugs that can be exploited by providing a malicious plugin. Rated ‘high severity’, CVE-2023-27898 exists because Jenkins […]


Threats & Malware, Vulnerabilities

Chrome 111 Patches 40 Vulnerabilities

March 8, 2023

Via: Security Week

A total of 24 of the addressed security defects were reported by external researchers. These include eight high-severity flaws, 11 medium-severity bugs, and five low-severity issues. Three of the high-severity vulnerabilities reported by external researchers are use-after-free bugs impacting Swiftshader, […]


Threats & Malware, Vulnerabilities

Critical Vulnerabilities Allow Hackers to Take Full Control of Wago PLCs

March 6, 2023

Via: Security Week

The vulnerabilities were discovered by Ryan Pickren from the Georgia Institute of Technology’s Cyber-Physical Security Lab. The issues were identified by the researcher as part of a PhD project on the security of industrial control systems (ICS). Pickren previously earned […]


Access control, Security

Sale of Stolen Credentials and Initial Access Dominate Dark Web Markets

March 2, 2023

Via: Dark Reading

The cybercrime economy centered around access to compromised systems, services, and networks has grown dramatically in the past year — with a sixfold increase in the number of credentials stolen via malware and offered for sale. With cyberattackers using information-stealing […]


Threats & Malware, Vulnerabilities

BlackLotus is the first bootkit bypassing UEFI Secure Boot on Windows 11

March 1, 2023

Via: Security Affairs

Researchers from ESET discovered a new stealthy Unified Extensible Firmware Interface (UEFI) bootkit, named BlackLotus, that is able to bypass Secure Boot on Windows 11. Secure Boot is a security feature of the latest Unified Extensible Firmware Interface (UEFI) 2.3.1 […]


Threats & Malware, Vulnerabilities

Researchers find hidden vulnerabilities in hundreds of Docker containers

February 23, 2023

Via: Help Net Security

Rezilion uncovered the presence of hundreds of Docker container images containing vulnerabilities that are not detected by most standard vulnerability scanners and SCA tools. The research revealed numerous high-severity/critical vulnerabilities hidden in hundreds of popular container images, downloaded billions of […]


Cyber-crime, Malware, Threats & Malware, Vulnerabilities

Most vulnerabilities associated with ransomware are old

February 22, 2023

Via: Help Net Security

Researchers identified 56 new vulnerabilities associated with ransomware threats among a total of 344 threats identified in 2022 – marking a 19% increase year-over-year. Threat actors are actively searching the internet and deep and dark web for 180 vulnerabilities known […]


Threats & Malware, Vulnerabilities

Fortinet plugs critical security hole in FortiNAC, with a PoC incoming (CVE-2022-39952)

February 20, 2023

Via: Help Net Security

Fortinet has dropped fixes for 40 vulnerabilities in a variety of its products, including two critical vulnerabilities (CVE-2022-39952, CVE-2021-42756) affecting its FortiNAC and FortiWeb solutions. Since cyberattackers love to exploit vulnerabilities in Fortinet enterprise solutions and a PoC exploit for […]


Threats & Malware, Vulnerabilities

Researchers Warn of Critical Security Bugs in Schneider Electric Modicon PLCs

February 16, 2023

Via: The Hacker News

Security researchers have disclosed two new vulnerabilities affecting Schneider Electric Modicon programmable logic controllers (PLCs) that could allow for authentication bypass and remote code execution. The flaws, tracked as CVE-2022-45788 (CVSS score: 7.5) and CVE-2022-45789 (CVSS score: 8.1), are part […]


Threats & Malware, Vulnerabilities

Oligo Security Takes Aim at Open Source Vulnerabilities

February 16, 2023

Via: Dark Reading

Oligo Security launched out of stealth on Wednesday with its runtime application security platform for detecting vulnerabilities in open source components. Oligo generates a dynamic bill of materials (BOM), identifies vulnerabilities in packages, and sets fix priorities for vulnerabilities based […]


Threats & Malware, Vulnerabilities

Update Now: Microsoft Releases Patches for 3 Actively Exploited Windows Vulnerabilities

February 15, 2023

Via: The Hacker News

Microsoft on Tuesday released security updates to address 75 flaws spanning its product portfolio, three of which have come under active exploitation in the wild. The updates are in addition to 22 flaws the Windows maker patched in its Chromium-based […]


Threats & Malware, Vulnerabilities

Splunk Enterprise Updates Patch High-Severity Vulnerabilities

February 15, 2023

Via: Security Week

The most severe vulnerabilities are CVE-2023-22939 and CVE-2023-22935 (CVSS score of 8.1), two issues that could lead to the bypass of search processing language (SPL) safeguards for risky commands. Both flaws affect instances with Splunk Web enabled and require a […]


Threats & Malware, Vulnerabilities

Critical Infrastructure at Risk from New Vulnerabilities Found in Wireless IIoT Devices

February 9, 2023

Via: The Hacker News

A set of 38 security vulnerabilities has been uncovered in wireless industrial internet of things (IIoT) devices from four different vendors that could pose a significant attack surface for threat actors looking to exploit operational technology (OT) environments. “Threat actors […]


Hacker, Threats & Malware

Hackers Exploit Vulnerabilities in Sunlogin to Deploy Sliver C2 Framework

February 7, 2023

Via: The Hacker News

Threat actors are leveraging known flaws in Sunlogin software to deploy the Sliver command-and-control (C2) framework for carrying out post-exploitation activities. The findings come from AhnLab Security Emergency response Center (ASEC), which found that security vulnerabilities in Sunlogin, a remote […]


Threats & Malware, Vulnerabilities

CISA Alert: Oracle E-Business Suite and SugarCRM Vulnerabilities Under Attack

February 3, 2023

Via: The Hacker News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on February 2 added two security flaws to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation. The first of the two vulnerabilities is CVE-2022-21587 (CVSS score: 9.8), a critical […]


Threats & Malware, Vulnerabilities

New High-Severity Vulnerabilities Discovered in Cisco IOx and F5 BIG-IP Products

February 3, 2023

Via: The Hacker News

F5 has warned of a high-severity flaw impacting BIG-IP appliances that could lead to denial-of-service (DoS) or arbitrary code execution. The issue is rooted in the iControl Simple Object Access Protocol (SOAP) interface and affects the following versions of BIG-IP […]


Threats & Malware, Vulnerabilities

Additional Supply Chain Vulnerabilities Uncovered in AMI MegaRAC BMC Software

February 1, 2023

Via: The Hacker News

Two more supply chain security flaws have been disclosed in AMI MegaRAC Baseboard Management Controller (BMC) software, nearly two months after three security vulnerabilities were brought to light in the same product. Firmware security firm Eclypsium said the two shortcomings […]


Threats & Malware, Vulnerabilities

Experts warn of a surge of attacks exploiting a Realtek Jungle SDK RCE (CVE-2021-35394)

January 26, 2023

Via: Security Affairs

Palo Alto Networks researchers reported that between August and October 2022 the number of attacks that attempted to exploit a Realtek Jungle SDK RCE (CVE-2021-35394) (CVSS score 9.8) accounted for more than 40% of the total number of attacks. “Realtek […]


Threats & Malware, Vulnerabilities

Trained developers get rid of more vulnerabilities than code scanning tools

January 23, 2023

Via: Help Net Security

An EMA survey of 129 software development professionals uncovered that for those using code scanning tools, only 10% of organizations prevented a higher percentage of vulnerabilities than organizations not using code scanning tools, while continuous training greatly improved code security […]


Threats & Malware, Vulnerabilities

Drupal Patches Vulnerabilities Leading to Information Disclosure

January 20, 2023

Via: Security Week

The Drupal core issue exists because the Media Library module does not perform proper checks on entity access in some cases, which could allow users who can edit content to view metadata about media items that they should not have […]