Vulnerabilities

Critical WordPress Plugin Flaws Exploited to Inject Malicious Scripts and Backdoors

Critical WordPress Plugin Flaws Exploited to Inject Malicious Scripts and Backdoors 2024-05-30 at 18:17 By Ionut Arghire Malicious campaign exploits high-severity XSS flaws in three WordPress plugins to backdoor websites. The post Critical WordPress Plugin Flaws Exploited to Inject Malicious Scripts and Backdoors appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS […]

Critical WordPress Plugin Flaws Exploited to Inject Malicious Scripts and Backdoors Read More »

NIST Getting Outside Help for National Vulnerability Database

NIST Getting Outside Help for National Vulnerability Database 2024-05-30 at 18:17 By Eduard Kovacs NIST is receiving support to get the NVD and CVE processing back on track within the next few months. The post NIST Getting Outside Help for National Vulnerability Database appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

NIST Getting Outside Help for National Vulnerability Database Read More »

Vulnerabilities in Eclipse ThreadX Could Lead to Code Execution

Vulnerabilities in Eclipse ThreadX Could Lead to Code Execution 2024-05-29 at 18:01 By Ionut Arghire Vulnerabilities in the real-time IoT operating system Eclipse ThreadX before version 6.4 could lead to denial-of-service and code execution. The post Vulnerabilities in Eclipse ThreadX Could Lead to Code Execution appeared first on SecurityWeek. This article is an excerpt from

Vulnerabilities in Eclipse ThreadX Could Lead to Code Execution Read More »

Netflix Paid Out Over $1 Million via Bug Bounty Program

Netflix Paid Out Over $1 Million via Bug Bounty Program 2024-05-29 at 12:31 By Eduard Kovacs Netflix has paid out more than $1 million for vulnerabilities found in its products since the launch of its bug bounty program in 2016. The post Netflix Paid Out Over $1 Million via Bug Bounty Program appeared first on

Netflix Paid Out Over $1 Million via Bug Bounty Program Read More »

JAVS Courtroom Audio-Visual Software Installer Serves Backdoor

JAVS Courtroom Audio-Visual Software Installer Serves Backdoor 2024-05-24 at 16:31 By Ionut Arghire Backdoored JAVS courtroom recording and management software installer puts thousands at risk of complete takeover. The post JAVS Courtroom Audio-Visual Software Installer Serves Backdoor appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

JAVS Courtroom Audio-Visual Software Installer Serves Backdoor Read More »

Google Patches Fourth Chrome Zero-Day in Two Weeks

Google Patches Fourth Chrome Zero-Day in Two Weeks 2024-05-24 at 12:16 By Ionut Arghire Exploited in the wild, Chrome vulnerability CVE-2024-5274 is a high-severity flaw described as a type confusion in the V8 JavaScript and WebAssembly engine. The post Google Patches Fourth Chrome Zero-Day in Two Weeks appeared first on SecurityWeek. This article is an

Google Patches Fourth Chrome Zero-Day in Two Weeks Read More »

Zero-Day Attacks and Supply Chain Compromises Surge, MFA Remains Underutilized: Rapid7 Report

Zero-Day Attacks and Supply Chain Compromises Surge, MFA Remains Underutilized: Rapid7 Report 2024-05-23 at 14:31 By Kevin Townsend Attackers are getting more sophisticated, better armed, and faster. Nothing in Rapid7’s 2024 Attack Intelligence Report suggests that this will change. The post Zero-Day Attacks and Supply Chain Compromises Surge, MFA Remains Underutilized: Rapid7 Report appeared first

Zero-Day Attacks and Supply Chain Compromises Surge, MFA Remains Underutilized: Rapid7 Report Read More »

Critical Authentication Bypass Resolved in GitHub Enterprise Server

Critical Authentication Bypass Resolved in GitHub Enterprise Server 2024-05-22 at 16:01 By Ionut Arghire Critical vulnerability in GitHub Enterprise Server allows unauthenticated attackers to obtain administrative privileges. The post Critical Authentication Bypass Resolved in GitHub Enterprise Server appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Critical Authentication Bypass Resolved in GitHub Enterprise Server Read More »

Critical Veeam Vulnerability Leads to Authentication Bypass

Critical Veeam Vulnerability Leads to Authentication Bypass 2024-05-22 at 16:01 By Ionut Arghire Veeam Backup Enterprise Manager update resolves multiple vulnerabilities, including a critical authentication bypass. The post Critical Veeam Vulnerability Leads to Authentication Bypass appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Critical Veeam Vulnerability Leads to Authentication Bypass Read More »

Ivanti Patches Critical Code Execution Vulnerabilities in Endpoint Manager

Ivanti Patches Critical Code Execution Vulnerabilities in Endpoint Manager 2024-05-22 at 14:46 By Ionut Arghire Ivanti has released product updates to resolve multiple vulnerabilities, including critical code execution flaws in Endpoint Manager. The post Ivanti Patches Critical Code Execution Vulnerabilities in Endpoint Manager appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Ivanti Patches Critical Code Execution Vulnerabilities in Endpoint Manager Read More »

Chrome 125 Update Patches High-Severity Vulnerabilities

Chrome 125 Update Patches High-Severity Vulnerabilities 2024-05-22 at 13:32 By Ionut Arghire Google released a Chrome 125 update to resolve four high-severity vulnerabilities reported by external researchers. The post Chrome 125 Update Patches High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Chrome 125 Update Patches High-Severity Vulnerabilities Read More »

QNAP Rushes Patch for Code Execution Flaw in NAS Devices

QNAP Rushes Patch for Code Execution Flaw in NAS Devices 2024-05-21 at 19:46 By Ionut Arghire QNAP rolls out patches for multiple vulnerabilities after proof-of-concept exploit published for a remote code execution vulnerability. The post QNAP Rushes Patch for Code Execution Flaw in NAS Devices appeared first on SecurityWeek. This article is an excerpt from

QNAP Rushes Patch for Code Execution Flaw in NAS Devices Read More »

CISA Warns of Attacks Exploiting NextGen Healthcare Mirth Connect Flaw

CISA Warns of Attacks Exploiting NextGen Healthcare Mirth Connect Flaw 2024-05-21 at 14:31 By Eduard Kovacs CISA has added CVE-2023-43208, an unauthenticated remote code execution vulnerability, to its KEV catalog.  The post CISA Warns of Attacks Exploiting NextGen Healthcare Mirth Connect Flaw appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

CISA Warns of Attacks Exploiting NextGen Healthcare Mirth Connect Flaw Read More »

Vulnerability Found in Fluent Bit Utility Used by Major Cloud, Tech Companies

Vulnerability Found in Fluent Bit Utility Used by Major Cloud, Tech Companies 2024-05-20 at 18:46 By Eduard Kovacs Linguistic Lumberjack (CVE-2024-4323) is a critical vulnerability in the Fluent Bit logging utility that can allow DoS, information disclosure and possibly RCE. The post Vulnerability Found in Fluent Bit Utility Used by Major Cloud, Tech Companies appeared first

Vulnerability Found in Fluent Bit Utility Used by Major Cloud, Tech Companies Read More »

CISA Warns of Exploited Vulnerabilities in EOL D-Link Products

CISA Warns of Exploited Vulnerabilities in EOL D-Link Products 2024-05-17 at 17:01 By Ionut Arghire CISA has added two vulnerabilities in discontinued D-Link products to its KEV catalog, including a decade-old flaw. The post CISA Warns of Exploited Vulnerabilities in EOL D-Link Products appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

CISA Warns of Exploited Vulnerabilities in EOL D-Link Products Read More »

Third Chrome Zero-Day Patched by Google Within One Week

Third Chrome Zero-Day Patched by Google Within One Week 2024-05-16 at 12:16 By Ionut Arghire Google releases Chrome 125 to the stable channel with patches for nine vulnerabilities, including a zero-day. The post Third Chrome Zero-Day Patched by Google Within One Week appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

Third Chrome Zero-Day Patched by Google Within One Week Read More »

Intel Publishes 41 Security Advisories for Over 90 Vulnerabilities 

Intel Publishes 41 Security Advisories for Over 90 Vulnerabilities  2024-05-15 at 18:31 By Eduard Kovacs Intel has published 41 new May 2024 Patch Tuesday advisories covering a total of more than 90 vulnerabilities.  The post Intel Publishes 41 Security Advisories for Over 90 Vulnerabilities  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Intel Publishes 41 Security Advisories for Over 90 Vulnerabilities  Read More »

Microsoft Warns of Active Zero-Day Exploitation, Patches 60 Windows Vulnerabilities

Microsoft Warns of Active Zero-Day Exploitation, Patches 60 Windows Vulnerabilities 2024-05-14 at 22:47 By Ryan Naraine Patch Tuesday: Microsoft documents 60 security flaws in multiple software products and flags an actively exploited Windows zero-day for urgent attention. The post Microsoft Warns of Active Zero-Day Exploitation, Patches 60 Windows Vulnerabilities appeared first on SecurityWeek. This article

Microsoft Warns of Active Zero-Day Exploitation, Patches 60 Windows Vulnerabilities Read More »

Adobe Patches Critical Flaws in Reader, Acrobat

Adobe Patches Critical Flaws in Reader, Acrobat 2024-05-14 at 21:01 By Ryan Naraine Adobe documents multiple code execution flaws in a wide range of products, including the widely deployed Adobe Acrobat and Reader software. The post Adobe Patches Critical Flaws in Reader, Acrobat appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Adobe Patches Critical Flaws in Reader, Acrobat Read More »

SAP Patches Critical Vulnerabilities in CX Commerce, NetWeaver

SAP Patches Critical Vulnerabilities in CX Commerce, NetWeaver 2024-05-14 at 18:16 By Ionut Arghire SAP has released 14 new and three updated security notes on its May 2024 Security Patch Day. The post SAP Patches Critical Vulnerabilities in CX Commerce, NetWeaver appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

SAP Patches Critical Vulnerabilities in CX Commerce, NetWeaver Read More »

Scroll to Top