Vulnerabilities

CISA Warns of Windows Streaming Service Vulnerability Exploitation

CISA Warns of Windows Streaming Service Vulnerability Exploitation 2024-03-01 at 16:01 By Ionut Arghire CISA says a high-severity elevation of privilege vulnerability in Microsoft Streaming Service is actively exploited in the wild. The post CISA Warns of Windows Streaming Service Vulnerability Exploitation appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed […]

CISA Warns of Windows Streaming Service Vulnerability Exploitation Read More »

Meta Patches Facebook Account Takeover Vulnerability

Meta Patches Facebook Account Takeover Vulnerability 2024-02-29 at 16:34 By Eduard Kovacs Meta has patched a critical vulnerability that could have been exploited to take over any Facebook account via a brute-force attack. The post Meta Patches Facebook Account Takeover Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

Meta Patches Facebook Account Takeover Vulnerability Read More »

The Imperative for Modern Security: Risk-Based Vulnerability Management

The Imperative for Modern Security: Risk-Based Vulnerability Management 2024-02-29 at 15:01 By Torsten George By prioritizing vulnerabilities based on risk and aligning security efforts with business objectives, organizations can enhance their resilience to cyberattacks, optimize resource allocation, and maintain a proactive security posture. The post The Imperative for Modern Security: Risk-Based Vulnerability Management appeared first

The Imperative for Modern Security: Risk-Based Vulnerability Management Read More »

Cisco Patches High-Severity Vulnerabilities in Data Center OS

Cisco Patches High-Severity Vulnerabilities in Data Center OS 2024-02-29 at 15:01 By Ionut Arghire Cisco’s semiannual FXOS and NX-OS security advisory bundle resolves two high- and two medium-severity vulnerabilities. The post Cisco Patches High-Severity Vulnerabilities in Data Center OS appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Cisco Patches High-Severity Vulnerabilities in Data Center OS Read More »

Windows Zero-Day Exploited by North Korean Hackers in Rootkit Attack

Windows Zero-Day Exploited by North Korean Hackers in Rootkit Attack 2024-02-29 at 13:46 By Eduard Kovacs North Korean group Lazarus exploited AppLocker driver zero-day CVE-2024-21338 for privilege escalation in attacks involving FudModule rootkit. The post Windows Zero-Day Exploited by North Korean Hackers in Rootkit Attack appeared first on SecurityWeek. This article is an excerpt from

Windows Zero-Day Exploited by North Korean Hackers in Rootkit Attack Read More »

Zyxel Patches Remote Code Execution Bug in Firewall Products

Zyxel Patches Remote Code Execution Bug in Firewall Products 2024-02-26 at 19:17 By Ryan Naraine Taiwanese networking vendor Zyxel confirms security flaws in firewall and access points put users at risk of remote code execution attacks. The post Zyxel Patches Remote Code Execution Bug in Firewall Products appeared first on SecurityWeek. This article is an

Zyxel Patches Remote Code Execution Bug in Firewall Products Read More »

Critical Flaw in Popular ‘Ultimate Member’ WordPress Plugin

Critical Flaw in Popular ‘Ultimate Member’ WordPress Plugin 2024-02-26 at 17:33 By Ionut Arghire The vulnerability carries a CVSS severity score of 9.8/10 and affects web sites running the Ultimate Member WordPress membership plugin. The post Critical Flaw in Popular ‘Ultimate Member’ WordPress Plugin appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Critical Flaw in Popular ‘Ultimate Member’ WordPress Plugin Read More »

‘SlashAndGrab’ ScreenConnect Vulnerability Widely Exploited for Malware Delivery

‘SlashAndGrab’ ScreenConnect Vulnerability Widely Exploited for Malware Delivery 2024-02-23 at 14:31 By Eduard Kovacs ConnectWise ScreenConnect vulnerability tracked as CVE-2024-1709 and SlashAndGrab exploited to deliver ransomware and other malware. The post ‘SlashAndGrab’ ScreenConnect Vulnerability Widely Exploited for Malware Delivery appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

‘SlashAndGrab’ ScreenConnect Vulnerability Widely Exploited for Malware Delivery Read More »

ConnectWise Confirms ScreenConnect Flaw Under Active Exploitation

ConnectWise Confirms ScreenConnect Flaw Under Active Exploitation 2024-02-21 at 19:16 By Ryan Naraine Security experts describe exploitation of the CVSS 10/10 flaw as “trivial and embarrassingly easy.” The post ConnectWise Confirms ScreenConnect Flaw Under Active Exploitation appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

ConnectWise Confirms ScreenConnect Flaw Under Active Exploitation Read More »

Researchers Devise ‘VoltSchemer’ Attacks Targeting Wireless Chargers

Researchers Devise ‘VoltSchemer’ Attacks Targeting Wireless Chargers 2024-02-21 at 19:16 By Ionut Arghire Researchers document VoltSchemer attacks that manipulate power voltage to take over commercial wireless chargers. The post Researchers Devise ‘VoltSchemer’ Attacks Targeting Wireless Chargers appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Researchers Devise ‘VoltSchemer’ Attacks Targeting Wireless Chargers Read More »

Chrome 122, Firefox 123 Patch High-Severity Vulnerabilities

Chrome 122, Firefox 123 Patch High-Severity Vulnerabilities 2024-02-21 at 13:46 By Ionut Arghire Google and Mozilla resolve high-severity memory safety vulnerabilities with the latest Chrome and Firefox updates. The post Chrome 122, Firefox 123 Patch High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Chrome 122, Firefox 123 Patch High-Severity Vulnerabilities Read More »

ConnectWise Rushes to Patch Critical Vulns in Remote Access Tool

ConnectWise Rushes to Patch Critical Vulns in Remote Access Tool 2024-02-20 at 19:31 By Ryan Naraine ConnectWise ships patches for extremely critical security defects in its ScreenConnect remote desktop access product and urges emergency patching. The post ConnectWise Rushes to Patch Critical Vulns in Remote Access Tool appeared first on SecurityWeek. This article is an

ConnectWise Rushes to Patch Critical Vulns in Remote Access Tool Read More »

Recent Zero-Day Could Impact Up to 97,000 Microsoft Exchange Servers

Recent Zero-Day Could Impact Up to 97,000 Microsoft Exchange Servers 2024-02-20 at 17:02 By Ionut Arghire Shadowserver Foundation has identified roughly 28,000 Microsoft Exchange servers impacted by a recent zero-day. The post Recent Zero-Day Could Impact Up to 97,000 Microsoft Exchange Servers appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

Recent Zero-Day Could Impact Up to 97,000 Microsoft Exchange Servers Read More »

Websites Hacked via Vulnerability in Bricks Builder WordPress Plugin

Websites Hacked via Vulnerability in Bricks Builder WordPress Plugin 2024-02-20 at 16:16 By Ionut Arghire Attackers are exploiting a recent remote code execution flaw in the Bricks Builder WordPress plugin to deploy malware. The post Websites Hacked via Vulnerability in Bricks Builder WordPress Plugin appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Websites Hacked via Vulnerability in Bricks Builder WordPress Plugin Read More »

Vulnerabilities in CUSG CMS Exposed Credit Unions to Attacks

Vulnerabilities in CUSG CMS Exposed Credit Unions to Attacks 2024-02-16 at 15:16 By Ionut Arghire Three vulnerabilities in CU Solutions Group CMS exposed 275 credit unions to credential theft, account takeover. The post Vulnerabilities in CUSG CMS Exposed Credit Unions to Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

Vulnerabilities in CUSG CMS Exposed Credit Unions to Attacks Read More »

Eight Vulnerabilities Disclosed in the AI Development Supply Chain

Eight Vulnerabilities Disclosed in the AI Development Supply Chain 2024-02-16 at 15:16 By Kevin Townsend Details of eight vulnerabilities found in the open source supply chain used to develop in-house AI and ML models have been disclosed. All have CVE numbers, one has critical severity, and seven have high severity. The post Eight Vulnerabilities Disclosed

Eight Vulnerabilities Disclosed in the AI Development Supply Chain Read More »

CISA Urges Patching of Cisco ASA Flaw Exploited in Ransomware Attacks

CISA Urges Patching of Cisco ASA Flaw Exploited in Ransomware Attacks 2024-02-16 at 14:02 By Eduard Kovacs CISA has added CVE-2020-3259, an old Cisco ASA vulnerability exploited by ransomware, to its KEV catalog.  The post CISA Urges Patching of Cisco ASA Flaw Exploited in Ransomware Attacks appeared first on SecurityWeek. This article is an excerpt

CISA Urges Patching of Cisco ASA Flaw Exploited in Ransomware Attacks Read More »

ESET Patches High-Severity Privilege Escalation Vulnerability

ESET Patches High-Severity Privilege Escalation Vulnerability 2024-02-15 at 17:02 By Ionut Arghire ESET has released patches for a high-severity elevation of privilege vulnerability in its Windows security products. The post ESET Patches High-Severity Privilege Escalation Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

ESET Patches High-Severity Privilege Escalation Vulnerability Read More »

Microsoft Warns of Exploited Exchange Server Zero-Day

Microsoft Warns of Exploited Exchange Server Zero-Day 2024-02-15 at 13:46 By Ionut Arghire Microsoft says a newly patched Exchange Server vulnerability (CVE-2024-21410) has been exploited in attacks. The post Microsoft Warns of Exploited Exchange Server Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Microsoft Warns of Exploited Exchange Server Zero-Day Read More »

Chipmaker Patch Tuesday: AMD and Intel Patch Over 100 Vulnerabilities

Chipmaker Patch Tuesday: AMD and Intel Patch Over 100 Vulnerabilities 2024-02-14 at 16:17 By Ionut Arghire AMD and Intel patch dozens of vulnerabilities on February 2024 Patch Tuesday, including multiple high-severity bugs. The post Chipmaker Patch Tuesday: AMD and Intel Patch Over 100 Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Chipmaker Patch Tuesday: AMD and Intel Patch Over 100 Vulnerabilities Read More »

Scroll to Top