Advertisement
Top

Tag: Vulnerability


Threats & Malware, Vulnerabilities

SSH shaken, not stirred by Terrapin vulnerability

December 20, 2023

Via: The Register

A vulnerability in the SSH protocol can be exploited by a well-placed adversary to weaken the security of people’s connections, if conditions are right. In a successful man-in-the-middle attack, the adversary may be able to force SSH clients to use […]


Data loss, Threats & Malware

Millions of Xfinity customers’ info, hashed passwords feared stolen in cyberattack

December 19, 2023

Via: The Register

Millions of Comcast Xfinity subscribers’ personal data – including potentially their usernames, hashed passwords, contact details, and secret security question-answers – was likely stolen by one or more miscreants exploiting Citrix Bleed in October. The internet, voice, and cable TV […]


Threats & Malware, Vulnerabilities

Lazarus APT Continues to Exploit Log4j Vulnerability

December 13, 2023

Via: SecureWorld

Lazarus, the notorious North Korean hacking group, has once again made headlines, this time by exploiting the Log4j vulnerability, despite it being disclosed two years ago. The Log4j vulnerability, officially known as CVE-2021-44228, continues to pose significant risks to organizations […]


Threats & Malware, Vulnerabilities

Atlassian security advisory reveals four fresh critical flaws – in mail with dead links

December 6, 2023

Via: The Register

Atlassian has emailed its customers to warn of four critical vulnerabilities, but the message had flaws of its own – the links it contained weren’t live for all readers at the time of despatch. The email, seen by The Register, […]


Threats & Malware, Vulnerabilities

A year on, CISA realizes debunked vuln actually a dud and removes it from must-patch list

December 6, 2023

Via: The Register

A security vulnerability previously added to CISA’s Known Exploited Vulnerability catalog (KEV), which was recognized by CVE Numbering Authorities (CNA), and included in reputable threat reports is now being formally rejected by infosec organizations. CISA removed CVE-2022-28958 from its KEV […]


Mobile, Mobile security

Google fixed critical zero-click RCE in Android

December 5, 2023

Via: Security Affairs

Google December 2023 Android security updates addressed 85 vulnerabilities, including a critical zero-click remote code execution (RCE) flaw tracked as CVE-2023-40088. The vulnerability resides in Android’s System component, it doesn’t require additional privileges to be triggered. An attacker can exploit […]


Threats & Malware, Vulnerabilities

Apple slaps patch on WebKit holes in iPhones and Macs amid fears of active attacks

December 1, 2023

Via: The Register

Apple has issued emergency fixes to plug security flaws in iPhones, iPads, and Macs that may already be under attack. The software updates for iOS, iPadOS, macOS Sonoma, and Safari web browser address two bugs: an out-of-bounds read flaw tracked […]


Threats & Malware, Vulnerabilities

PoC for Splunk Enterprise RCE flaw released (CVE-2023-46214)

November 27, 2023

Via: Help Net Security

A proof-of-concept (PoC) exploit for a high-severity flaw in Splunk Enterprise (CVE-2023-46214) that can lead to remote code execution has been made public. Users are advised to implement the provided patches or workarounds quickly. About CVE-2023-46214 Splunk Enterprise is a […]


Data loss, Threats & Malware

Samsung UK discloses year-long breach, leaked customer data

November 17, 2023

Via: The Register

The UK division of Samsung Electronics has allegedly alerted customers of a year-long data security breach – the third such incident the South Korean giant has experienced around the world in the past two years. An email to customers, shared […]


Threats & Malware, Vulnerabilities

A critical OS command injection flaw affects Fortinet FortiSIEM

November 17, 2023

Via: Security Affairs

Fortinet is warning customers of a critical OS command injection vulnerability, tracked as CVE-2023-36553 (CVSS score 9.3), in FortiSIEM report server. A remote, unauthenticated attacker can exploit the flaw to execute commands by sending specially crafted API requests. “An improper […]


Threats & Malware, Vulnerabilities

VMware disclosed a critical and unpatched authentication bypass flaw in VMware Cloud Director Appliance

November 15, 2023

Via: Security Affairs

VMware disclosed an authentication bypass vulnerability, tracked as CVE-2023-34060 (CVSS score 9.8), in its Cloud Director Appliance that can be exploited by an attacker with network access to the appliance bypassing login restrictions when authenticating on port 22 (ssh) or […]


Threats & Malware, Vulnerabilities

CISA adds SLP flaw to its Known Exploited Vulnerabilities catalog

November 9, 2023

Via: Security Affairs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability CVE-2023-29552 (CVSS score: 7.5) in the Service Location Protocol (SLP) to its Known Exploited Vulnerabilities catalog. The Service Location Protocol (SLP) is a legacy service discovery protocol that allows […]


Threats & Malware, Vulnerabilities

Atlassian cranks up the threat meter to max for Confluence authorization flaw

November 8, 2023

Via: The Register

Atlassian reassessed the severity rating of the recent improper authorization vulnerability in Confluence Data Center and Server, raising the CVSS score from 9.1 to a maximum of 10. The company overhauled its security advisory for CVE-2023-22518 after it realized there […]


Threats & Malware, Vulnerabilities

Critical Apache ActiveMQ flaw under attack by ‘clumsy’ ransomware crims

November 2, 2023

Via: The Register

Security researchers have confirmed that ransomware criminals are capitalizing on a maximum-severity vulnerability in Apache ActiveMQ. Announced on October 25 and tracked as CVE-2023-46604, the insecure deserialization vulnerability allows for remote code execution (RCE) on affected versions. “Apache ActiveMQ is […]


Threats & Malware, Vulnerabilities

‘Citrix Bleed’ Vulnerability Raises Concerns as Exploits Continue

November 2, 2023

Via: SecureWorld

In the ever-evolving landscape of cybersecurity threats, the discovery of serious vulnerabilities can send shockwaves through the digital world. One such recent incident that has captured the attention of security professionals is the exploitation of a critical vulnerability known as […]


Threats & Malware, Vulnerabilities

Critical vulnerability in F5 BIG-IP under active exploitation

November 1, 2023

Via: The Register

Vulnerabilities in F5’s BIG-IP suite are already being exploited after proof of concept (PoC) code began circulating online. The cybersecurity biz confirmed in an update to its advisory for CVE-2023-46747 that it has evidence of active exploitation in the wild, […]


Threats & Malware, Vulnerabilities

US cybercops urge admins to patch amid ongoing Confluence chaos

October 17, 2023

Via: The Register

US authorities have issued an urgent plea to network admins to patch the critical vulnerability in Atlassian Confluence Data Center and Server amid ongoing nation-state exploitation. The joint cybersecurity advisory from CISA, FBI, and Multi-State Information Sharing and Analysis Center […]


Mobile, Mobile security

Signal denies claims of an alleged zero-day flaw in its platform

October 16, 2023

Via: Security Affairs

The popular encrypted messaging app Signal denied claims of an alleged zero-day vulnerability in its platform. The company launched an investigation into the claims after they have seen the vague viral reports alleging a zero-day vulnerability. “PSA: we have seen […]


Threats & Malware, Virus & Malware

HTTP/2 Rapid Reset Zero-Day Largest DDoS Attack in Internet History

October 12, 2023

Via: SecureWorld

In recent months, the cybersecurity world has been shaken by the revelation of a sophisticated and unprecedented cyber threat: the HTTP/2 Rapid Reset Zero-Day vulnerability. This exploit, tracked as CVE-2023-44487, enabled cybercriminals to orchestrate what has been dubbed the largest […]


Threats & Malware, Virus & Malware

CISA Warns of Attacks Exploiting Adobe Acrobat Vulnerability 

October 11, 2023

Via: SecurityWeek

The Adobe Acrobat and Reader issue is CVE-2023-21608, a use-after-free vulnerability which can be exploited to achieve remote code execution (RCE) with the privileges of the current user. Adobe released patches for this flaw in January 2023, but numerous proof-of-concept […]