Vulnerabilities

Juniper Networks Warns of Critical Authentication Bypass Vulnerability

Juniper Networks Warns of Critical Authentication Bypass Vulnerability 2024-07-01 at 14:31 By Ionut Arghire Juniper Networks warns of a critical authentication bypass flaw impacting Session Smart routers and conductors. The post Juniper Networks Warns of Critical Authentication Bypass Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Juniper Networks Warns of Critical Authentication Bypass Vulnerability Read More »

Fortra Patches Critical SQL Injection in FileCatalyst Workflow

Fortra Patches Critical SQL Injection in FileCatalyst Workflow 2024-06-28 at 14:16 By Ionut Arghire Fortra has patched a critical-severity vulnerability in FileCatalyst Workflow leading to the creation of administrator accounts. The post Fortra Patches Critical SQL Injection in FileCatalyst Workflow appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Fortra Patches Critical SQL Injection in FileCatalyst Workflow Read More »

GitLab Security Updates Patch 14 Vulnerabilities

GitLab Security Updates Patch 14 Vulnerabilities 2024-06-27 at 17:01 By Ionut Arghire GitLab CE and EE updates resolve 14 vulnerabilities, including a critical- and three high-severity bugs. The post GitLab Security Updates Patch 14 Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

GitLab Security Updates Patch 14 Vulnerabilities Read More »

CISA Warns of Exploited GeoServer, Linux Kernel, and Roundcube Vulnerabilities

CISA Warns of Exploited GeoServer, Linux Kernel, and Roundcube Vulnerabilities 2024-06-27 at 15:31 By Ionut Arghire CISA on Wednesday warned that three older flaws in GeoServer, Linux kernel, and Roundcube webmail are exploited in the wild. The post CISA Warns of Exploited GeoServer, Linux Kernel, and Roundcube Vulnerabilities appeared first on SecurityWeek. This article is

CISA Warns of Exploited GeoServer, Linux Kernel, and Roundcube Vulnerabilities Read More »

Exploitation Attempts Target New MOVEit Transfer Vulnerability

Exploitation Attempts Target New MOVEit Transfer Vulnerability 2024-06-26 at 13:01 By Eduard Kovacs Exploitation attempts targeting CVE-2024-5806, a critical MOVEit Transfer vulnerability patched recently, have started. The post Exploitation Attempts Target New MOVEit Transfer Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Exploitation Attempts Target New MOVEit Transfer Vulnerability Read More »

Meta’s Virtual Reality Headset Vulnerable to Ransomware Attacks: Researcher

Meta’s Virtual Reality Headset Vulnerable to Ransomware Attacks: Researcher 2024-06-25 at 15:01 By Kevin Townsend Researcher shows how hackers could use social engineering to deliver ransomware and other malware to Meta’s Quest 3 VR headset. The post Meta’s Virtual Reality Headset Vulnerable to Ransomware Attacks: Researcher appeared first on SecurityWeek. This article is an excerpt

Meta’s Virtual Reality Headset Vulnerable to Ransomware Attacks: Researcher Read More »

New SnailLoad Attack Relies on Network Latency Variations to Infer User Activity

New SnailLoad Attack Relies on Network Latency Variations to Infer User Activity 2024-06-24 at 19:31 By Eduard Kovacs New attack named SnailLoad allows a remote attacker to infer websites and videos viewed by a user without direct access to network traffic. The post New SnailLoad Attack Relies on Network Latency Variations to Infer User Activity

New SnailLoad Attack Relies on Network Latency Variations to Infer User Activity Read More »

EFF Issues New Warning After Discovery of Automated License Plate Reader Vulnerabilities

EFF Issues New Warning After Discovery of Automated License Plate Reader Vulnerabilities 2024-06-24 at 18:31 By Eduard Kovacs The EFF has issued a warning over the use of automated license plate readers following the discovery of serious vulnerabilities.  The post EFF Issues New Warning After Discovery of Automated License Plate Reader Vulnerabilities appeared first on

EFF Issues New Warning After Discovery of Automated License Plate Reader Vulnerabilities Read More »

In Other News: Microsoft Email Spoofing, Snowflake Hack Ransoms, LogoFail Follow-Up

In Other News: Microsoft Email Spoofing, Snowflake Hack Ransoms, LogoFail Follow-Up 2024-06-21 at 16:32 By SecurityWeek News Noteworthy stories that might have slipped under the radar: Microsoft email spoofing vulnerability, Snowflake hack victims get ransom demands, LogoFail still around. The post In Other News: Microsoft Email Spoofing, Snowflake Hack Ransoms, LogoFail Follow-Up appeared first on

In Other News: Microsoft Email Spoofing, Snowflake Hack Ransoms, LogoFail Follow-Up Read More »

Recent SolarWinds Serv-U Vulnerability Exploited in the Wild

Recent SolarWinds Serv-U Vulnerability Exploited in the Wild 2024-06-21 at 16:32 By Ionut Arghire Threat actors are exploiting a recent path traversal vulnerability in SolarWinds Serv-U using public PoC code. The post Recent SolarWinds Serv-U Vulnerability Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Recent SolarWinds Serv-U Vulnerability Exploited in the Wild Read More »

Atlassian Patches High-Severity Vulnerabilities in Confluence, Crucible, Jira

Atlassian Patches High-Severity Vulnerabilities in Confluence, Crucible, Jira 2024-06-20 at 14:01 By Ionut Arghire Atlassian has released Confluence, Crucible, and Jira updates to address multiple high-severity vulnerabilities. The post Atlassian Patches High-Severity Vulnerabilities in Confluence, Crucible, Jira appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Atlassian Patches High-Severity Vulnerabilities in Confluence, Crucible, Jira Read More »

Chrome 126 Update Patches Vulnerability Exploited at Hacking Competition

Chrome 126 Update Patches Vulnerability Exploited at Hacking Competition 2024-06-19 at 14:31 By Ionut Arghire Google has released a Chrome 126 security update with six fixes, including four for externally reported high-severity flaws. The post Chrome 126 Update Patches Vulnerability Exploited at Hacking Competition appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Chrome 126 Update Patches Vulnerability Exploited at Hacking Competition Read More »

Rockwell Automation Patches High-Severity Vulnerabilities in FactoryTalk View SE

Rockwell Automation Patches High-Severity Vulnerabilities in FactoryTalk View SE 2024-06-14 at 13:46 By Eduard Kovacs Rockwell Automation has patched three high-severity vulnerabilities in its FactoryTalk View SE HMI software. The post Rockwell Automation Patches High-Severity Vulnerabilities in FactoryTalk View SE appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Rockwell Automation Patches High-Severity Vulnerabilities in FactoryTalk View SE Read More »

French Bug Bounty Platform YesWeHack Raises $28 Million

French Bug Bounty Platform YesWeHack Raises $28 Million 2024-06-14 at 10:01 By Ionut Arghire YesWeHack has raised more than $52 million to date to build and market a crowdsourced vulnerability reporting platform. The post French Bug Bounty Platform YesWeHack Raises $28 Million appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

French Bug Bounty Platform YesWeHack Raises $28 Million Read More »

Google Warns of Pixel Firmware Zero-Day Under Limited, Targeted Exploitation

Google Warns of Pixel Firmware Zero-Day Under Limited, Targeted Exploitation 2024-06-12 at 21:16 By Ryan Naraine The zero-day is tagged as CVE-2024-32896 and described as an elevation of privilege issue in Pixel Firmware. The post Google Warns of Pixel Firmware Zero-Day Under Limited, Targeted Exploitation appeared first on SecurityWeek. This article is an excerpt from

Google Warns of Pixel Firmware Zero-Day Under Limited, Targeted Exploitation Read More »

Fortinet Patches Code Execution Vulnerability in FortiOS

Fortinet Patches Code Execution Vulnerability in FortiOS 2024-06-12 at 19:46 By Ionut Arghire Fortinet has patched multiple vulnerabilities in FortiOS, including a high-severity code execution security flaw. The post Fortinet Patches Code Execution Vulnerability in FortiOS appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Fortinet Patches Code Execution Vulnerability in FortiOS Read More »

Microsoft Patches Zero-Click Outlook Vulnerability That Could Soon Be Exploited

Microsoft Patches Zero-Click Outlook Vulnerability That Could Soon Be Exploited 2024-06-12 at 19:46 By Ionut Arghire Microsoft’s June 2024 Patch Tuesday updates resolve a zero-click Outlook vulnerability leading to remote code execution. The post Microsoft Patches Zero-Click Outlook Vulnerability That Could Soon Be Exploited appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Microsoft Patches Zero-Click Outlook Vulnerability That Could Soon Be Exploited Read More »

Chrome 126, Firefox 127 Patch High-Severity Vulnerabilities

Chrome 126, Firefox 127 Patch High-Severity Vulnerabilities 2024-06-12 at 13:31 By Ionut Arghire Google and Mozilla have released patches for 21 and 15 vulnerabilities in Chrome and Firefox, respectively. The post Chrome 126, Firefox 127 Patch High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Chrome 126, Firefox 127 Patch High-Severity Vulnerabilities Read More »

Scroll to Top