Vulnerabilities

Pentagon Received Over 50,000 Vulnerability Reports Since 2016

Pentagon Received Over 50,000 Vulnerability Reports Since 2016 2024-03-18 at 15:17 By Ionut Arghire Since 2016, the US DoD has received over 50,000 submissions through its vulnerability disclosure program. The post Pentagon Received Over 50,000 Vulnerability Reports Since 2016 appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Pentagon Received Over 50,000 Vulnerability Reports Since 2016 Read More »

PoC Published for Critical Fortra Code Execution Vulnerability

PoC Published for Critical Fortra Code Execution Vulnerability 2024-03-18 at 13:46 By Ionut Arghire A critical directory traversal vulnerability in Fortra FileCatalyst Workflow could lead to remote code execution. The post PoC Published for Critical Fortra Code Execution Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

PoC Published for Critical Fortra Code Execution Vulnerability Read More »

Discontinued Security Plugins Expose Many WordPress Sites to Takeover

Discontinued Security Plugins Expose Many WordPress Sites to Takeover 2024-03-15 at 14:17 By Ionut Arghire Thousands of WordPress sites are at risk of takeover due to a critical privilege escalation vulnerability in two closed MiniOrange plugins. The post Discontinued Security Plugins Expose Many WordPress Sites to Takeover appeared first on SecurityWeek. This article is an

Discontinued Security Plugins Expose Many WordPress Sites to Takeover Read More »

Cisco Patches High-Severity IOS RX Vulnerabilities 

Cisco Patches High-Severity IOS RX Vulnerabilities  2024-03-14 at 15:43 By Ionut Arghire Cisco releases patches for high-severity denial-of-service and elevation of privilege vulnerabilities in IOS RX software. The post Cisco Patches High-Severity IOS RX Vulnerabilities  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Cisco Patches High-Severity IOS RX Vulnerabilities  Read More »

Kubernetes Vulnerability Allows Remote Code Execution on Windows Endpoints

Kubernetes Vulnerability Allows Remote Code Execution on Windows Endpoints 2024-03-14 at 14:01 By Ionut Arghire A high-severity Kubernetes vulnerability tracked as CVE-2023-5528 can be exploited to execute arbitrary code on Windows endpoints. The post Kubernetes Vulnerability Allows Remote Code Execution on Windows Endpoints appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Kubernetes Vulnerability Allows Remote Code Execution on Windows Endpoints Read More »

Fortinet Patches Critical Vulnerabilities Leading to Code Execution

Fortinet Patches Critical Vulnerabilities Leading to Code Execution 2024-03-13 at 12:33 By Ionut Arghire Fortinet has released patches for critical code execution vulnerabilities in FortiOS, FortiProxy, and FortiClientEMS. The post Fortinet Patches Critical Vulnerabilities Leading to Code Execution appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Fortinet Patches Critical Vulnerabilities Leading to Code Execution Read More »

Patch Tuesday: Microsoft Flags Major Bugs in HyperV, Exchange Server 

Patch Tuesday: Microsoft Flags Major Bugs in HyperV, Exchange Server  2024-03-12 at 21:51 By Ryan Naraine Microsoft ships patches for at least 60 security vulnerabilities in the Windows ecosystem and warned of remote code execution risks. The post Patch Tuesday: Microsoft Flags Major Bugs in HyperV, Exchange Server  appeared first on SecurityWeek. This article is

Patch Tuesday: Microsoft Flags Major Bugs in HyperV, Exchange Server  Read More »

SAP Patches Critical Command Injection Vulnerabilities

SAP Patches Critical Command Injection Vulnerabilities 2024-03-12 at 20:21 By Ionut Arghire Enterprise software maker SAP documents multiple critical-severity issues and warns of risk of command injection attacks. The post SAP Patches Critical Command Injection Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

SAP Patches Critical Command Injection Vulnerabilities Read More »

Google Paid Out $10 Million via Bug Bounty Programs in 2023

Google Paid Out $10 Million via Bug Bounty Programs in 2023 2024-03-12 at 20:21 By Eduard Kovacs Google paid out $10 million via its bug bounty programs in 2023, bringing the total to nearly $60 million since 2010. The post Google Paid Out $10 Million via Bug Bounty Programs in 2023 appeared first on SecurityWeek.

Google Paid Out $10 Million via Bug Bounty Programs in 2023 Read More »

Adobe Patches Critical Flaws in Enterprise Products

Adobe Patches Critical Flaws in Enterprise Products 2024-03-12 at 20:21 By Ryan Naraine Patch Tuesday: Adobe ships a hefty batch of security updates to fix critical-severity vulnerabilities in multiple enterprise-facing products. The post Adobe Patches Critical Flaws in Enterprise Products appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Adobe Patches Critical Flaws in Enterprise Products Read More »

Ultimate Member Plugin Flaw Exposes 100,000 WordPress Sites to Attacks

Ultimate Member Plugin Flaw Exposes 100,000 WordPress Sites to Attacks 2024-03-11 at 17:18 By Ionut Arghire A high-severity XSS vulnerability in the Ultimate Member plugin allows attackers to inject scripts into WordPress sites. The post Ultimate Member Plugin Flaw Exposes 100,000 WordPress Sites to Attacks appeared first on SecurityWeek. This article is an excerpt from

Ultimate Member Plugin Flaw Exposes 100,000 WordPress Sites to Attacks Read More »

Possibly Exploited Fortinet Flaw Impacts Many Systems, but No Signs of Mass Attacks

Possibly Exploited Fortinet Flaw Impacts Many Systems, but No Signs of Mass Attacks 2024-03-11 at 16:01 By Eduard Kovacs 150,000 systems possibly impacted by the recent Fortinet vulnerability ​​CVE-2024-21762, but there is still no evidence of widespread exploitation.  The post Possibly Exploited Fortinet Flaw Impacts Many Systems, but No Signs of Mass Attacks appeared first

Possibly Exploited Fortinet Flaw Impacts Many Systems, but No Signs of Mass Attacks Read More »

Critical Vulnerability Allows Access to QNAP NAS Devices

Critical Vulnerability Allows Access to QNAP NAS Devices 2024-03-11 at 16:01 By Ionut Arghire Critical-severity vulnerability could allow network attackers to access QNAP NAS devices without authentication. The post Critical Vulnerability Allows Access to QNAP NAS Devices appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Critical Vulnerability Allows Access to QNAP NAS Devices Read More »

In Other News: Google AI Hacking, Font Vulnerabilities, IBM Training Facility

In Other News: Google AI Hacking, Font Vulnerabilities, IBM Training Facility 2024-03-08 at 16:59 By SecurityWeek News Noteworthy stories that might have slipped under the radar: Google AI bug bounties, font vulnerabilities, IBM opens new training facility. The post In Other News: Google AI Hacking, Font Vulnerabilities, IBM Training Facility appeared first on SecurityWeek. This

In Other News: Google AI Hacking, Font Vulnerabilities, IBM Training Facility Read More »

Cisco Patches High-Severity Vulnerabilities in VPN Product

Cisco Patches High-Severity Vulnerabilities in VPN Product 2024-03-07 at 16:40 By Ionut Arghire High-severity flaws in Cisco Secure Client could lead to code execution and unauthorized remote access VPN sessions. The post Cisco Patches High-Severity Vulnerabilities in VPN Product appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Cisco Patches High-Severity Vulnerabilities in VPN Product Read More »

CISA Warns of Pixel Phone Vulnerability Exploitation

CISA Warns of Pixel Phone Vulnerability Exploitation 2024-03-06 at 14:07 By Eduard Kovacs CISA adds Pixel Android phone (CVE-2023-21237) and Sunhillo SureLine (CVE-2021-36380) flaws to its known exploited vulnerabilities catalog.  The post CISA Warns of Pixel Phone Vulnerability Exploitation appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

CISA Warns of Pixel Phone Vulnerability Exploitation Read More »

Apple Blunts Zero-Day Attacks With iOS 17.4 Update

Apple Blunts Zero-Day Attacks With iOS 17.4 Update 2024-03-05 at 23:01 By Ryan Naraine Apple rolls out urgent patches to fix multiple security flaws in its flagship iOS platform and warned about zero-day exploits in the wild. The post Apple Blunts Zero-Day Attacks With iOS 17.4 Update appeared first on SecurityWeek. This article is an

Apple Blunts Zero-Day Attacks With iOS 17.4 Update Read More »

VMware Patches Critical ESXi Sandbox Escape Flaws

VMware Patches Critical ESXi Sandbox Escape Flaws 2024-03-05 at 21:17 By Ryan Naraine The most serious flaws allow hackers with local admin rights to execute code as the virtual machine’s VMX process running on the host. The post VMware Patches Critical ESXi Sandbox Escape Flaws appeared first on SecurityWeek. This article is an excerpt from

VMware Patches Critical ESXi Sandbox Escape Flaws Read More »

Critical Vulnerability Exposes TeamCity Servers to Takeover

Critical Vulnerability Exposes TeamCity Servers to Takeover 2024-03-05 at 14:03 By Ionut Arghire A critical authentication bypass in TeamCity allows remote attackers to take full control of vulnerable servers. The post Critical Vulnerability Exposes TeamCity Servers to Takeover appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Critical Vulnerability Exposes TeamCity Servers to Takeover Read More »

Hikvision Patches High-Severity Vulnerability in Security Management System

Hikvision Patches High-Severity Vulnerability in Security Management System 2024-03-04 at 15:47 By Ionut Arghire A high-severity vulnerability in HikCentral Professional could lead to unauthorized access to certain URLs. The post Hikvision Patches High-Severity Vulnerability in Security Management System appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Hikvision Patches High-Severity Vulnerability in Security Management System Read More »

Scroll to Top