Vulnerabilities

Microsoft Warns of OpenVPN Vulnerabilities, Potential for Exploit Chains

Microsoft Warns of OpenVPN Vulnerabilities, Potential for Exploit Chains 2024-08-12 at 19:01 By Ryan Naraine The vulnerabilities, patched in OpenVPN 2.6.10, expose users on the Windows platform to remote code execution attacks. The post Microsoft Warns of OpenVPN Vulnerabilities, Potential for Exploit Chains appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS […]

Microsoft Warns of OpenVPN Vulnerabilities, Potential for Exploit Chains Read More »

Several Vulnerabilities Found in Google’s Quick Share Data Transfer Utility

Several Vulnerabilities Found in Google’s Quick Share Data Transfer Utility 2024-08-12 at 19:01 By Ionut Arghire SafeBreach identified 10 vulnerabilities in Google Quick Share and devised a remote code execution chain targeting the file sharing utility for Windows. The post Several Vulnerabilities Found in Google’s Quick Share Data Transfer Utility appeared first on SecurityWeek. This

Several Vulnerabilities Found in Google’s Quick Share Data Transfer Utility Read More »

Warnings Issued Over Cisco Device Hacking, Unpatched Vulnerabilities

Warnings Issued Over Cisco Device Hacking, Unpatched Vulnerabilities 2024-08-09 at 15:01 By Eduard Kovacs CISA is warning organizations about abuse of Cisco Smart Install feature, as Cisco is notifying customers about critical phone vulnerabilities it’s not patching. The post Warnings Issued Over Cisco Device Hacking, Unpatched Vulnerabilities appeared first on SecurityWeek. This article is an

Warnings Issued Over Cisco Device Hacking, Unpatched Vulnerabilities Read More »

CrowdStrike Dismisses Claims of Exploitability in Falcon Sensor Bug

CrowdStrike Dismisses Claims of Exploitability in Falcon Sensor Bug 2024-08-08 at 20:46 By Ryan Naraine CrowdStrike dismissed claims that the Falcon EDR sensor bug could be exploited for privilege escalation or remote code execution. The post CrowdStrike Dismisses Claims of Exploitability in Falcon Sensor Bug appeared first on SecurityWeek. This article is an excerpt from

CrowdStrike Dismisses Claims of Exploitability in Falcon Sensor Bug Read More »

Vulnerabilities Exposed Widely Used Solar Power Systems to Hacking, Disruption

Vulnerabilities Exposed Widely Used Solar Power Systems to Hacking, Disruption 2024-08-08 at 16:16 By Eduard Kovacs Vulnerabilities found in solar power systems could have been exploited by hackers to cause disruption and possibly blackouts. The post Vulnerabilities Exposed Widely Used Solar Power Systems to Hacking, Disruption appeared first on SecurityWeek. This article is an excerpt

Vulnerabilities Exposed Widely Used Solar Power Systems to Hacking, Disruption Read More »

GhostWrite Vulnerability Facilitates Attacks on Devices With RISC-V CPU

GhostWrite Vulnerability Facilitates Attacks on Devices With RISC-V CPU 2024-08-07 at 22:16 By Eduard Kovacs Researchers disclose the details of GhostWrite, a RISC-V CPU vulnerability that can be exploited to gain full access to targeted devices. The post GhostWrite Vulnerability Facilitates Attacks on Devices With RISC-V CPU appeared first on SecurityWeek. This article is an

GhostWrite Vulnerability Facilitates Attacks on Devices With RISC-V CPU Read More »

Researcher Sounds Alarm on Windows Update Flaws Allowing Undetectable Downgrade Attacks

Researcher Sounds Alarm on Windows Update Flaws Allowing Undetectable Downgrade Attacks 2024-08-07 at 18:16 By Ryan Naraine Researcher showcases hack against Microsoft Windows Update architecture, turning fixed vulnerabilities into zero-days. The post Researcher Sounds Alarm on Windows Update Flaws Allowing Undetectable Downgrade Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Researcher Sounds Alarm on Windows Update Flaws Allowing Undetectable Downgrade Attacks Read More »

Chrome, Firefox Updates Patch Serious Vulnerabilities 

Chrome, Firefox Updates Patch Serious Vulnerabilities  2024-08-07 at 11:31 By Eduard Kovacs A Chrome 127 update patches five vulnerabilities, and Firefox 129 addresses over a dozen security holes. The post Chrome, Firefox Updates Patch Serious Vulnerabilities  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Chrome, Firefox Updates Patch Serious Vulnerabilities  Read More »

CrowdStrike Releases Root Cause Analysis of Falcon Sensor BSOD Crash

CrowdStrike Releases Root Cause Analysis of Falcon Sensor BSOD Crash 2024-08-06 at 21:16 By Ryan Naraine CrowdStrike says the Falcon sensor crash that blue-screened Windows machines was caused by a “confluence” of vulnerabilities and testing gaps. The post CrowdStrike Releases Root Cause Analysis of Falcon Sensor BSOD Crash appeared first on SecurityWeek. This article is

CrowdStrike Releases Root Cause Analysis of Falcon Sensor BSOD Crash Read More »

Microsoft Bug Bounty Payouts Increased to $16.6 Million in Past Year

Microsoft Bug Bounty Payouts Increased to $16.6 Million in Past Year 2024-08-06 at 13:16 By Eduard Kovacs Microsoft paid out $16.6 million to over 340 security researchers through its bug bounty programs over the past year. The post Microsoft Bug Bounty Payouts Increased to $16.6 Million in Past Year appeared first on SecurityWeek. This article

Microsoft Bug Bounty Payouts Increased to $16.6 Million in Past Year Read More »

Google Patches Android Zero-Day Exploited in Targeted Attacks

Google Patches Android Zero-Day Exploited in Targeted Attacks 2024-08-06 at 11:01 By Eduard Kovacs Google has patched CVE-2024-36971, a high-severity kernel zero-day vulnerability in Android that has been exploited in targeted attacks.  The post Google Patches Android Zero-Day Exploited in Targeted Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

Google Patches Android Zero-Day Exploited in Targeted Attacks Read More »

New SLUBStick Attack Makes Linux Kernel Vulnerabilities More Dangerous

New SLUBStick Attack Makes Linux Kernel Vulnerabilities More Dangerous 2024-08-05 at 16:47 By Eduard Kovacs A new Linux kernel exploitation technique named SLUBStick makes heap vulnerabilities more dangerous.  The post New SLUBStick Attack Makes Linux Kernel Vulnerabilities More Dangerous appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

New SLUBStick Attack Makes Linux Kernel Vulnerabilities More Dangerous Read More »

Apache OFBiz Users Warned of New and Exploited Vulnerabilities

Apache OFBiz Users Warned of New and Exploited Vulnerabilities 2024-08-05 at 15:01 By Eduard Kovacs Organizations are being warned of a newly discovered Apache OFBiz vulnerability as exploitation of another recent flaw is observed. The post Apache OFBiz Users Warned of New and Exploited Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from

Apache OFBiz Users Warned of New and Exploited Vulnerabilities Read More »

In Other News: European Banks Put to Test, Voting DDoS Attacks, Tenable Exploring Sale

In Other News: European Banks Put to Test, Voting DDoS Attacks, Tenable Exploring Sale 2024-08-02 at 17:16 By SecurityWeek News Noteworthy stories that might have slipped under the radar: over 100 European banks undergo cyber resilience test, DDoS attacks don’t impact voting, and Tenable exploring a potential sale. The post In Other News: European Banks

In Other News: European Banks Put to Test, Voting DDoS Attacks, Tenable Exploring Sale Read More »

CISA Warns of Avtech Camera Vulnerability Exploited in Wild

CISA Warns of Avtech Camera Vulnerability Exploited in Wild 2024-08-02 at 13:46 By Eduard Kovacs An Avtech camera vulnerability that likely remains unfixed has been exploited in the wild, according to CISA. The post CISA Warns of Avtech Camera Vulnerability Exploited in Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

CISA Warns of Avtech Camera Vulnerability Exploited in Wild Read More »

Exploited Vulnerability Could Impact 20k Internet-Exposed VMware ESXi Instances

Exploited Vulnerability Could Impact 20k Internet-Exposed VMware ESXi Instances 2024-08-01 at 16:16 By Ionut Arghire Shadowserver has observed over 20,000 internet-accessible VMware ESXi instances impacted by an exploited vulnerability. The post Exploited Vulnerability Could Impact 20k Internet-Exposed VMware ESXi Instances appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Exploited Vulnerability Could Impact 20k Internet-Exposed VMware ESXi Instances Read More »

Homebrew Security Audit Finds 25 Vulnerabilities

Homebrew Security Audit Finds 25 Vulnerabilities 2024-08-01 at 15:16 By Ionut Arghire Vulnerabilities in Homebrew could have allowed attackers to load executable code and modify binary builds, security audit finds. The post Homebrew Security Audit Finds 25 Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Homebrew Security Audit Finds 25 Vulnerabilities Read More »

Apple Rolls Out Security Updates for iOS, macOS

Apple Rolls Out Security Updates for iOS, macOS 2024-07-30 at 12:01 By Ionut Arghire Apple has released security patches for dozens of vulnerabilities in iOS, macOS, tvOS, visionOS, watchOS, and Safari. The post Apple Rolls Out Security Updates for iOS, macOS appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

Apple Rolls Out Security Updates for iOS, macOS Read More »

Microsoft Says Ransomware Gangs Exploiting Just-Patched VMware ESXi Flaw

Microsoft Says Ransomware Gangs Exploiting Just-Patched VMware ESXi Flaw 2024-07-29 at 21:46 By Ryan Naraine VMware did not mention in-the-wild exploitation for CVE-2024-37085 but Microsoft says ransomware gangs are abusing the just-patched flaw. The post Microsoft Says Ransomware Gangs Exploiting Just-Patched VMware ESXi Flaw appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Microsoft Says Ransomware Gangs Exploiting Just-Patched VMware ESXi Flaw Read More »

Acronis Product Vulnerability Exploited in the Wild

Acronis Product Vulnerability Exploited in the Wild 2024-07-29 at 15:16 By Ionut Arghire Acronis warns of a critical-severity Acronis Cyber Infrastructure (ACI) vulnerability being exploited in attacks. The post Acronis Product Vulnerability Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Acronis Product Vulnerability Exploited in the Wild Read More »

Scroll to Top