Vulnerabilities

Patch Tuesday: Remote Code Execution Flaw in Microsoft Message Queuing

Patch Tuesday: Remote Code Execution Flaw in Microsoft Message Queuing 2024-06-12 at 00:46 By Ryan Naraine The Windows vulnerability carries a CVSS severity score of 9.8/10 and can be exploited by via specially crafted malicious MSMQ packets. The post Patch Tuesday: Remote Code Execution Flaw in Microsoft Message Queuing appeared first on SecurityWeek. This article […]

Patch Tuesday: Remote Code Execution Flaw in Microsoft Message Queuing Read More »

Adobe Plugs Code Execution Holes in After Effects, Illustrator

Adobe Plugs Code Execution Holes in After Effects, Illustrator 2024-06-11 at 21:46 By Ryan Naraine Patch Tuesday: Adobe fixes critical flaws and warns of the risk of code execution attacks on Windows and macOS platforms. The post Adobe Plugs Code Execution Holes in After Effects, Illustrator appeared first on SecurityWeek. This article is an excerpt

Adobe Plugs Code Execution Holes in After Effects, Illustrator Read More »

Multiple Vulnerabilities Plague Discontinued Netgear WNR614 Routers

Multiple Vulnerabilities Plague Discontinued Netgear WNR614 Routers 2024-06-11 at 17:01 By Ionut Arghire Redfox Security warns of multiple vulnerabilities in Netgear WNR614 routers discontinued three years ago. The post Multiple Vulnerabilities Plague Discontinued Netgear WNR614 Routers appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Multiple Vulnerabilities Plague Discontinued Netgear WNR614 Routers Read More »

SAP Patches High-Severity Vulnerabilities in Financial Consolidation, NetWeaver

SAP Patches High-Severity Vulnerabilities in Financial Consolidation, NetWeaver 2024-06-11 at 15:16 By Ionut Arghire SAP has released 10 new security notes on June 2024 Security Patch Day, including two addressing high-severity vulnerabilities. The post SAP Patches High-Severity Vulnerabilities in Financial Consolidation, NetWeaver appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

SAP Patches High-Severity Vulnerabilities in Financial Consolidation, NetWeaver Read More »

Arm Warns of Exploited Kernel Driver Vulnerability

Arm Warns of Exploited Kernel Driver Vulnerability 2024-06-11 at 13:16 By Ionut Arghire Arm warns that CVE-2024-4610, a Mali GPU kernel driver vulnerability addressed two years ago, is exploited in attacks. The post Arm Warns of Exploited Kernel Driver Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Arm Warns of Exploited Kernel Driver Vulnerability Read More »

Critical PyTorch Vulnerability Can Lead to Sensitive AI Data Theft

Critical PyTorch Vulnerability Can Lead to Sensitive AI Data Theft 2024-06-10 at 17:31 By Ionut Arghire A critical vulnerability in the PyTorch distributed RPC framework could be exploited for remote code execution. The post Critical PyTorch Vulnerability Can Lead to Sensitive AI Data Theft appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Critical PyTorch Vulnerability Can Lead to Sensitive AI Data Theft Read More »

PHP Patches Critical Remote Code Execution Vulnerability

PHP Patches Critical Remote Code Execution Vulnerability 2024-06-10 at 16:31 By Ionut Arghire PHP has released patches for CVE-2024-4577, a critical vulnerability that could lead to arbitrary code execution on remote servers. The post PHP Patches Critical Remote Code Execution Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

PHP Patches Critical Remote Code Execution Vulnerability Read More »

Nvidia Patches High-Severity GPU Driver Vulnerabilities

Nvidia Patches High-Severity GPU Driver Vulnerabilities 2024-06-10 at 16:01 By Ionut Arghire Nvidia patches multiple high-severity vulnerabilities in GPU display drivers and virtual GPU software. The post Nvidia Patches High-Severity GPU Driver Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Nvidia Patches High-Severity GPU Driver Vulnerabilities Read More »

In Other News: TikTok Zero-Day, DMM Bitcoin Hack, Free VPN App Analysis

In Other News: TikTok Zero-Day, DMM Bitcoin Hack, Free VPN App Analysis 2024-06-07 at 18:46 By SecurityWeek News Noteworthy stories that might have slipped under the radar: TikTok patches account hijacking zero-day, $300 million DMM Bitcoin hack, free Android VPN apps analyzed. The post In Other News: TikTok Zero-Day, DMM Bitcoin Hack, Free VPN App

In Other News: TikTok Zero-Day, DMM Bitcoin Hack, Free VPN App Analysis Read More »

SolarWinds Patches High-Severity Vulnerability Reported by NATO Pentester

SolarWinds Patches High-Severity Vulnerability Reported by NATO Pentester 2024-06-07 at 14:01 By Ionut Arghire SolarWinds has released patches for high-severity vulnerabilities in Serv-U and the SolarWinds Platform. The post SolarWinds Patches High-Severity Vulnerability Reported by NATO Pentester appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

SolarWinds Patches High-Severity Vulnerability Reported by NATO Pentester Read More »

Chinese Hackers Exploit Old ThinkPHP Vulnerabilities in New Attacks

Chinese Hackers Exploit Old ThinkPHP Vulnerabilities in New Attacks 2024-06-06 at 20:33 By Ionut Arghire Akamai warns that a Chinese threat actor is exploiting years-old remote code execution vulnerabilities in ThinkPHP in new attacks. The post Chinese Hackers Exploit Old ThinkPHP Vulnerabilities in New Attacks appeared first on SecurityWeek. This article is an excerpt from

Chinese Hackers Exploit Old ThinkPHP Vulnerabilities in New Attacks Read More »

Exploitation of Recent Check Point VPN Zero-Day Soars

Exploitation of Recent Check Point VPN Zero-Day Soars 2024-06-06 at 16:46 By Ionut Arghire GreyNoise has observed a rapid increase in the number of exploitation attempts targeting a recent Check Point VPN zero-day. The post Exploitation of Recent Check Point VPN Zero-Day Soars appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Exploitation of Recent Check Point VPN Zero-Day Soars Read More »

Vulnerabilities Patched in Kiuwan Code Security Products After Long Disclosure Process

Vulnerabilities Patched in Kiuwan Code Security Products After Long Disclosure Process 2024-06-06 at 15:31 By Eduard Kovacs It took code security firm Kiuwan nearly two years to patch several serious vulnerabilities found in its SAST products. The post Vulnerabilities Patched in Kiuwan Code Security Products After Long Disclosure Process appeared first on SecurityWeek. This article

Vulnerabilities Patched in Kiuwan Code Security Products After Long Disclosure Process Read More »

‘NsaRescueAngel’ Backdoor Account Again Discovered in Zyxel Products

‘NsaRescueAngel’ Backdoor Account Again Discovered in Zyxel Products 2024-06-05 at 15:03 By Ionut Arghire Critical vulnerabilities in discontinued Zyxel NAS products allow unauthenticated attackers to execute arbitrary code and OS commands. The post ‘NsaRescueAngel’ Backdoor Account Again Discovered in Zyxel Products appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

‘NsaRescueAngel’ Backdoor Account Again Discovered in Zyxel Products Read More »

Cisco Patches Webex Bugs Following Exposure of German Government Meetings

Cisco Patches Webex Bugs Following Exposure of German Government Meetings 2024-06-05 at 13:02 By Eduard Kovacs Cisco has released a security advisory after researchers discovered that the German government’s Webex meetings were exposed. The post Cisco Patches Webex Bugs Following Exposure of German Government Meetings appeared first on SecurityWeek. This article is an excerpt from

Cisco Patches Webex Bugs Following Exposure of German Government Meetings Read More »

Details of Atlassian Confluence RCE Vulnerability Disclosed

Details of Atlassian Confluence RCE Vulnerability Disclosed 2024-06-04 at 17:16 By Ionut Arghire SonicWall has shared technical details on a recently addressed high-severity remote code execution flaw in Confluence. The post Details of Atlassian Confluence RCE Vulnerability Disclosed appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Details of Atlassian Confluence RCE Vulnerability Disclosed Read More »

Progress Patches Critical Vulnerability in Telerik Report Server

Progress Patches Critical Vulnerability in Telerik Report Server 2024-06-04 at 15:46 By Ionut Arghire A critical vulnerability in the Progress Telerik Report Server could allow unauthenticated attackers to access restricted functionality. The post Progress Patches Critical Vulnerability in Telerik Report Server appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

Progress Patches Critical Vulnerability in Telerik Report Server Read More »

CISA Warns of Exploited Linux Kernel Vulnerability

CISA Warns of Exploited Linux Kernel Vulnerability 2024-05-31 at 14:46 By Ionut Arghire CISA instructs federal agencies to mitigate CVE-2024-1086, a Linux kernel flaw leading to privilege escalation. The post CISA Warns of Exploited Linux Kernel Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

CISA Warns of Exploited Linux Kernel Vulnerability Read More »

Critical WordPress Plugin Flaws Exploited to Inject Malicious Scripts and Backdoors

Critical WordPress Plugin Flaws Exploited to Inject Malicious Scripts and Backdoors 2024-05-30 at 18:17 By Ionut Arghire Malicious campaign exploits high-severity XSS flaws in three WordPress plugins to backdoor websites. The post Critical WordPress Plugin Flaws Exploited to Inject Malicious Scripts and Backdoors appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Critical WordPress Plugin Flaws Exploited to Inject Malicious Scripts and Backdoors Read More »

NIST Getting Outside Help for National Vulnerability Database

NIST Getting Outside Help for National Vulnerability Database 2024-05-30 at 18:17 By Eduard Kovacs NIST is receiving support to get the NVD and CVE processing back on track within the next few months. The post NIST Getting Outside Help for National Vulnerability Database appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

NIST Getting Outside Help for National Vulnerability Database Read More »

Scroll to Top