Advertisement
Top

Tag: vulnerabilities


Threats & Malware, Vulnerabilities

Microsoft Message Queuing Vulnerabilities Allow Remote Code Execution, DoS Attacks

July 26, 2023

Via: SecurityWeek

Two of these flaws, tracked as CVE-2023-21554 and CVE-2023-28302, could lead to remote code execution (RCE) and denial-of-service (DoS) and were addressed by Microsoft with its April 2023 Patch Tuesday updates. No CVE identifier has been provided for the third […]


Threats & Malware, Vulnerabilities

Atlassian Releases Patches for Critical Flaws in Confluence and Bamboo

July 25, 2023

Via: The Hacker News

Atlassian has released updates to address three security flaws impacting its Confluence Server, Data Center, and Bamboo Data Center products that, if successfully exploited, could result in remote code execution on susceptible systems. The list of the flaws is below […]


Threats & Malware, Vulnerabilities

Critical Zero-Days in Atera Windows Installers Expose Users to Privilege Escalation Attacks

July 24, 2023

Via: The Hacker News

Zero-day vulnerabilities in Windows Installers for the Atera remote monitoring and management software could act as a springboard to launch privilege escalation attacks. The flaws, discovered by Mandiant on February 28, 2023, have been assigned the identifiers CVE-2023-26077 and CVE-2023-26078, […]


Application security, Security

Apache OpenMeetings Web Conferencing Tool Exposed to Critical Vulnerabilities

July 20, 2023

Via: The Hacker News

Multiple security flaws have been disclosed in Apache OpenMeetings, a web conferencing solution, that could be potentially exploited by malicious actors to seize control of admin accounts and run malicious code on susceptible servers. “Attackers can bring the application into […]


Threats & Malware, Vulnerabilities

Rockwell Automation ControlLogix Bugs Expose Industrial Systems to Remote Attacks

July 13, 2023

Via: The Hacker News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has alerted of two security flaws impacting Rockwell Automation ControlLogix EtherNet/IP (ENIP) communication module models that could be exploited to achieve remote code execution and denial-of-service (DoS). “The results and impact of […]


Mobile, Mobile security

Google Releases Android Patch Update for 3 Actively Exploited Vulnerabilities

July 7, 2023

Via: The Hacker News

Google has released its monthly security updates for the Android operating system, addressing 46 new software vulnerabilities. Among these, three vulnerabilities have been identified as actively exploited in targeted attacks. One of the vulnerabilities tracked as CVE-2023-26083 is a memory […]


Application security, Security

Node.js Users Beware: Manifest Confusion Attack Opens Door to Malware

July 5, 2023

Via: The Hacker News

The npm registry for the Node.js JavaScript runtime environment is susceptible to what’s called a manifest confusion attack that could potentially allow threat actors to conceal malware in project dependencies or perform arbitrary script execution during installation. “A npm package’s […]


Threats & Malware, Vulnerabilities

CISA Flags 8 Actively Exploited Flaws in Samsung and D-Link Devices

July 3, 2023

Via: The Hacker News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has placed a set of eight flaws to the Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. This includes six shortcomings affecting Samsung smartphones and two vulnerabilities impacting D-Link […]


Threats & Malware, Vulnerabilities

Critical SQL Injection Flaws Expose Gentoo Soko to Remote Code Execution

June 28, 2023

Via: The Hacker News

Multiple SQL injection vulnerabilities have been disclosed in Gentoo Soko that could lead to remote code execution (RCE) on vulnerable systems. “These SQL injections happened despite the use of an Object-Relational Mapping (ORM) library and prepared statements,” SonarSource researcher Thomas […]


Network security, Security

Cl0p in Your Network? Here’s How to Find Out

June 26, 2023

Via: Dark Reading

Widespread attacks against companies and government agencies through a trio of zero-day vulnerabilities in the MOVEit Managed File Transfer platform has granted notoriety to the Cl0p ransomware group. The list of affected data continues to grow, including personal data on […]


Threats & Malware, Vulnerabilities

Remotely Exploitable DoS Vulnerabilities Patched in BIND

June 26, 2023

Via: SecurityWeek

Tracked as CVE-2023-2828, CVE-2023-2829 and CVE-2023-2911, these high-severity issues could be exploited to exhaust the available memory, or could cause named – BIND’s daemon that functions both as a recursive resolver and as an authoritative name server – to crash. […]


Threats & Malware, Vulnerabilities

Severe Vulnerabilities Reported in Microsoft Azure Bastion and Container Registry

June 14, 2023

Via: The Hacker News

Two “dangerous” security vulnerabilities have been disclosed in Microsoft Azure Bastion and Azure Container Registry that could have been exploited to carry out cross-site scripting (XSS) attacks. “The vulnerabilities allowed unauthorized access to the victim’s session within the compromised Azure […]


Application security, Security

Over Half of Security Leaders Lack Confidence in Protecting App Secrets, Study Reveals

June 13, 2023

Via: The Hacker News

It might come as a surprise, but secrets management has become the elephant in the AppSec room. While security vulnerabilities like Common Vulnerabilities and Exposures (CVEs) often make headlines in the cybersecurity world, secrets management remains an overlooked issue that […]


Threats & Malware, Vulnerabilities

Password Reset Hack Exposed in Honda’s E-Commerce Platform, Dealers Data at Risk

June 12, 2023

Via: The Hacker News

Security vulnerabilities discovered in Honda’s e-commerce platform could have been exploited to gain unrestricted access to sensitive dealer information. “Broken/missing access controls made it possible to access all data on the platform, even when logged in as a test account,” […]


Application security, Security

Hackers Win $105,000 for Reporting Critical Security Flaws in Sonos One Speakers

May 30, 2023

Via: The Hacker News

Multiple security flaws uncovered in Sonos One wireless speakers could be potentially exploited to achieve information disclosure and remote code execution, the Zero Day Initiative (ZDI) said in a report published last week. The vulnerabilities were demonstrated by three different […]


Threats & Malware, Vulnerabilities

Zyxel Issues Critical Security Patches for Firewall and VPN Products

May 25, 2023

Via: The Hacker News

Zyxel has released software updates to address two critical security flaws affecting select firewall and VPN products that could be abused by remote attackers to achieve code execution. Both the flaws – CVE-2023-33009 and CVE-2023-33010 – are buffer overflow vulnerabilities […]


Cloud security, Security

Google Cloud Bug Allows Server Takeover From CloudSQL Service

May 25, 2023

Via: Dark Reading

Google has fixed a critical flaw in its Google Cloud Platform’s database service that researchers used to gain access to sensitive data and secrets, as well as escalate privileges to breach other cloud services, including potentially those in customer environments. […]


Threats & Malware, Vulnerabilities

WebKit Under Attack: Apple Issues Emergency Patches for 3 New Zero-Day Vulnerabilities

May 19, 2023

Via: The Hacker News

Apple on Thursday rolled out security updates to iOS, iPadOS, macOS, tvOS, watchOS, and the Safari web browser to address three new zero-day flaws that it said are being actively exploited in the wild. The three security shortcomings are listed […]


Threats & Malware, Vulnerabilities

Cisco squashes critical bugs in small biz switches

May 18, 2023

Via: The Register

Cisco rolled out patches for four critical security vulnerabilities in several of its network switches for small businesses that can be exploited to remotely hijack the equipment. Specifically, the flaws in the web user interface can be used to run […]


Threats & Malware, Vulnerabilities

Microsoft’s May Patch Tuesday Fixes 38 Flaws, Including Active Zero-Day Bug

May 10, 2023

Via: The Hacker News

Microsoft has rolled out Patch Tuesday updates for May 2023 to address 38 security flaws, including one zero-day bug that it said is being actively exploited in the wild. Trend Micro’s Zero Day Initiative (ZDI) said the volume is the […]