Vulnerabilities

CISA Announces CVE Enrichment Project ‘Vulnrichment’

CISA Announces CVE Enrichment Project ‘Vulnrichment’ 2024-05-09 at 16:01 By Eduard Kovacs CISA’s Vulnrichment project is adding important information to CVE records to help improve vulnerability management processes. The post CISA Announces CVE Enrichment Project ‘Vulnrichment’ appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

CISA Announces CVE Enrichment Project ‘Vulnrichment’ Read More »

F5 Patches Dangerous Vulnerabilities in BIG-IP Next Central Manager

F5 Patches Dangerous Vulnerabilities in BIG-IP Next Central Manager 2024-05-09 at 14:17 By Eduard Kovacs F5 has patched two potentially serious vulnerabilities in BIG-IP Next that could allow an attacker to take full control of a device. The post F5 Patches Dangerous Vulnerabilities in BIG-IP Next Central Manager appeared first on SecurityWeek. This article is

F5 Patches Dangerous Vulnerabilities in BIG-IP Next Central Manager Read More »

New ‘TunnelVision’ Technique Leaks Traffic From Any VPN System

New ‘TunnelVision’ Technique Leaks Traffic From Any VPN System 2024-05-08 at 17:01 By Ionut Arghire A new VPN bypass technique allows threat actors to snoop on victims’ traffic by forcing it off the VPN tunnel using built-in features of DHCP. The post New ‘TunnelVision’ Technique Leaks Traffic From Any VPN System appeared first on SecurityWeek.

New ‘TunnelVision’ Technique Leaks Traffic From Any VPN System Read More »

Android Update Patches Critical Vulnerability

Android Update Patches Critical Vulnerability 2024-05-08 at 15:31 By Ionut Arghire Android’s May 2024 security update patches 38 vulnerabilities, including a critical bug in the System component. The post Android Update Patches Critical Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Android Update Patches Critical Vulnerability Read More »

CISA, FBI Urge Organizations to Eliminate Path Traversal Vulnerabilities

CISA, FBI Urge Organizations to Eliminate Path Traversal Vulnerabilities 2024-05-03 at 17:09 By Ionut Arghire CISA and the FBI warn of threat actors abusing path traversal software vulnerabilities in attacks targeting critical infrastructure. The post CISA, FBI Urge Organizations to Eliminate Path Traversal Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

CISA, FBI Urge Organizations to Eliminate Path Traversal Vulnerabilities Read More »

Microsoft Warns of ‘Dirty Stream’ Vulnerability in Popular Android Apps

Microsoft Warns of ‘Dirty Stream’ Vulnerability in Popular Android Apps 2024-05-03 at 14:31 By Eduard Kovacs Microsoft has uncovered a new type of attack called Dirty Stream that impacted Android apps with billions of installations.  The post Microsoft Warns of ‘Dirty Stream’ Vulnerability in Popular Android Apps appeared first on SecurityWeek. This article is an

Microsoft Warns of ‘Dirty Stream’ Vulnerability in Popular Android Apps Read More »

Horizon3.ai Introduces AI-Assisted Service to Prioritize and Patch Vulnerabilities Faster

Horizon3.ai Introduces AI-Assisted Service to Prioritize and Patch Vulnerabilities Faster 2024-05-03 at 14:31 By Kevin Townsend SaaS-based, AI-assisted penetration service allows proactive defensive action against exploitation of new vulnerabilities. The post Horizon3.ai Introduces AI-Assisted Service to Prioritize and Patch Vulnerabilities Faster appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

Horizon3.ai Introduces AI-Assisted Service to Prioritize and Patch Vulnerabilities Faster Read More »

1,400 GitLab Servers Impacted by Exploited Vulnerability

1,400 GitLab Servers Impacted by Exploited Vulnerability 2024-05-02 at 15:16 By Ionut Arghire CISA says a critical GitLab password reset flaw is being exploited in attacks and roughly 1,400 servers have not been patched. The post 1,400 GitLab Servers Impacted by Exploited Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

1,400 GitLab Servers Impacted by Exploited Vulnerability Read More »

Adobe Adds Content Credentials and Firefly to Bug Bounty Program

Adobe Adds Content Credentials and Firefly to Bug Bounty Program 2024-05-01 at 18:33 By Ionut Arghire Adobe is providing incentives for bug bounty hackers to report security flaws in its implementation of Content Credentials and Adobe Firefly. The post Adobe Adds Content Credentials and Firefly to Bug Bounty Program appeared first on SecurityWeek. This article

Adobe Adds Content Credentials and Firefly to Bug Bounty Program Read More »

Google Boosts Bug Bounty Payouts Tenfold in Mobile App Security Push

Google Boosts Bug Bounty Payouts Tenfold in Mobile App Security Push 2024-05-01 at 18:33 By Ionut Arghire Researchers can earn as much as $450,000 for a single vulnerability report as Google boosts its mobile vulnerability rewards program. The post Google Boosts Bug Bounty Payouts Tenfold in Mobile App Security Push appeared first on SecurityWeek. This

Google Boosts Bug Bounty Payouts Tenfold in Mobile App Security Push Read More »

Docker Hub Users Targeted With Imageless, Malicious Repositories

Docker Hub Users Targeted With Imageless, Malicious Repositories 2024-04-30 at 20:46 By Ionut Arghire JFrog raises an alarm after finding three large-scale malware campaigns targeting Docker Hub with imageless repositories. The post Docker Hub Users Targeted With Imageless, Malicious Repositories appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Docker Hub Users Targeted With Imageless, Malicious Repositories Read More »

Critical Vulnerabilities in Judge0 Lead to Sandbox Escape, Host Takeover

Critical Vulnerabilities in Judge0 Lead to Sandbox Escape, Host Takeover 2024-04-30 at 20:46 By Ionut Arghire Three vulnerabilities in the Judge0 open source service could allow attackers to escape the sandbox and obtain root privileges on the host. The post Critical Vulnerabilities in Judge0 Lead to Sandbox Escape, Host Takeover appeared first on SecurityWeek. This

Critical Vulnerabilities in Judge0 Lead to Sandbox Escape, Host Takeover Read More »

Vulnerability in R Programming Language Could Fuel Supply Chain Attacks

Vulnerability in R Programming Language Could Fuel Supply Chain Attacks 2024-04-30 at 17:16 By Ionut Arghire A vulnerability (CVE-2024-27322) in the R programming language implementation can be exploited to execute arbitrary and be used as part of a supply chain attack. The post Vulnerability in R Programming Language Could Fuel Supply Chain Attacks appeared first

Vulnerability in R Programming Language Could Fuel Supply Chain Attacks Read More »

Over 1,400 CrushFTP Instances Vulnerable to Exploited Zero-Day

Over 1,400 CrushFTP Instances Vulnerable to Exploited Zero-Day 2024-04-26 at 17:16 By Ionut Arghire More than 1,400 CrushFTP servers remain vulnerable to an actively exploited zero-day for which PoC has been published. The post Over 1,400 CrushFTP Instances Vulnerable to Exploited Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

Over 1,400 CrushFTP Instances Vulnerable to Exploited Zero-Day Read More »

Vulnerabilities Expose Brocade SAN Appliances, Switches to Hacking

Vulnerabilities Expose Brocade SAN Appliances, Switches to Hacking 2024-04-25 at 15:17 By Ionut Arghire The Brocade SANnav management application is affected by multiple vulnerabilities, including a publicly available root password. The post Vulnerabilities Expose Brocade SAN Appliances, Switches to Hacking appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Vulnerabilities Expose Brocade SAN Appliances, Switches to Hacking Read More »

Cisco Raises Alarm for ‘ArcaneDoor’ Zero-Days Hitting ASA Firewall Platforms

Cisco Raises Alarm for ‘ArcaneDoor’ Zero-Days Hitting ASA Firewall Platforms 2024-04-24 at 21:16 By Ryan Naraine Cisco warns that nation state-backed hackers are exploiting at least two zero-day vulnerabilities in its ASA firewall platforms to plant malware on telecommunications and energy sector networks. The post Cisco Raises Alarm for ‘ArcaneDoor’ Zero-Days Hitting ASA Firewall Platforms

Cisco Raises Alarm for ‘ArcaneDoor’ Zero-Days Hitting ASA Firewall Platforms Read More »

CISA Warns of Windows Print Spooler Flaw After Microsoft Sees Russian Exploitation

CISA Warns of Windows Print Spooler Flaw After Microsoft Sees Russian Exploitation 2024-04-24 at 16:16 By Ionut Arghire CISA warns organizations of a two-year-old Windows Print Spooler vulnerability being exploited in the wild. The post CISA Warns of Windows Print Spooler Flaw After Microsoft Sees Russian Exploitation appeared first on SecurityWeek. This article is an

CISA Warns of Windows Print Spooler Flaw After Microsoft Sees Russian Exploitation Read More »

Siemens Industrial Product Impacted by Exploited Palo Alto Firewall Vulnerability

Siemens Industrial Product Impacted by Exploited Palo Alto Firewall Vulnerability 2024-04-23 at 14:02 By Eduard Kovacs Palo Alto Networks firewall vulnerability CVE-2024-3400, exploited as a zero-day, impacts a Siemens industrial product. The post Siemens Industrial Product Impacted by Exploited Palo Alto Firewall Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Siemens Industrial Product Impacted by Exploited Palo Alto Firewall Vulnerability Read More »

Microsoft DRM Hack Could Allow Movie Downloads From Popular Streaming Services

Microsoft DRM Hack Could Allow Movie Downloads From Popular Streaming Services 2024-04-23 at 14:01 By Eduard Kovacs Microsoft PlayReady vulnerabilities that could allow rogue subscribers to illegally download movies from popular streaming services. The post Microsoft DRM Hack Could Allow Movie Downloads From Popular Streaming Services appeared first on SecurityWeek. This article is an excerpt

Microsoft DRM Hack Could Allow Movie Downloads From Popular Streaming Services Read More »

Scroll to Top