Vulnerabilities

Zoom Patches Critical Vulnerability in Windows Applications

Zoom Patches Critical Vulnerability in Windows Applications 2024-02-14 at 16:17 By Ionut Arghire Zoom patches seven vulnerabilities in its products, including a critical-severity bug in its Windows applications. The post Zoom Patches Critical Vulnerability in Windows Applications appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Zoom Patches Critical Vulnerability in Windows Applications Read More »

KeyTrap DNS Attack Could Disable Large Parts of Internet: Researchers

KeyTrap DNS Attack Could Disable Large Parts of Internet: Researchers 2024-02-14 at 15:01 By Eduard Kovacs Patches released for a new DNSSEC vulnerability named KeyTrap, described as the worst DNS attack ever discovered.   The post KeyTrap DNS Attack Could Disable Large Parts of Internet: Researchers appeared first on SecurityWeek. This article is an excerpt from

KeyTrap DNS Attack Could Disable Large Parts of Internet: Researchers Read More »

SAP Patches Critical Vulnerability Exposing User, Business Data

SAP Patches Critical Vulnerability Exposing User, Business Data 2024-02-14 at 12:32 By Ionut Arghire SAP patches a critical code-injection vulnerability in the SAP ABA (Application Basis) cross-application component. The post SAP Patches Critical Vulnerability Exposing User, Business Data appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

SAP Patches Critical Vulnerability Exposing User, Business Data Read More »

Microsoft Confirms Windows Exploits Bypassing Security Features

Microsoft Confirms Windows Exploits Bypassing Security Features 2024-02-13 at 22:01 By Ryan Naraine Patch Tuesday: Microsoft pushes a massive batch of security-themed updates and calls urgent attention to exploits bypassing security features. The post Microsoft Confirms Windows Exploits Bypassing Security Features appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

Microsoft Confirms Windows Exploits Bypassing Security Features Read More »

Patch Tuesday: Adobe Warns of Critical Flaws in Widely Deployed Software

Patch Tuesday: Adobe Warns of Critical Flaws in Widely Deployed Software 2024-02-13 at 20:01 By Ryan Naraine Adobe ships patches for at least 30 documented security flaws, warning that users are exposed to code execution, security feature bypass and denial-of-service attacks. The post Patch Tuesday: Adobe Warns of Critical Flaws in Widely Deployed Software appeared

Patch Tuesday: Adobe Warns of Critical Flaws in Widely Deployed Software Read More »

CISA Warns of Roundcube Webmail Vulnerability Exploitation

CISA Warns of Roundcube Webmail Vulnerability Exploitation 2024-02-13 at 13:31 By Eduard Kovacs CISA has added the Roundcube flaw tracked as CVE-2023-43770 to its known exploited vulnerabilities catalog. The post CISA Warns of Roundcube Webmail Vulnerability Exploitation appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

CISA Warns of Roundcube Webmail Vulnerability Exploitation Read More »

Exploitation of Another Ivanti VPN Vulnerability Observed

Exploitation of Another Ivanti VPN Vulnerability Observed 2024-02-12 at 13:01 By Ionut Arghire Organizations urged to hunt for potential compromise as exploitation of a recent Ivanti enterprise VPN vulnerability begins. The post Exploitation of Another Ivanti VPN Vulnerability Observed appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Exploitation of Another Ivanti VPN Vulnerability Observed Read More »

Ivanti Patches High-Severity Vulnerability in VPN Appliances

Ivanti Patches High-Severity Vulnerability in VPN Appliances 2024-02-09 at 15:17 By Ionut Arghire An XXE flaw in Ivanti Connect Secure, Ivanti Policy Secure, and ZTA gateways could lead to unauthenticated access to resources. The post Ivanti Patches High-Severity Vulnerability in VPN Appliances appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

Ivanti Patches High-Severity Vulnerability in VPN Appliances Read More »

Fortinet Warns of New FortiOS Zero-Day

Fortinet Warns of New FortiOS Zero-Day 2024-02-09 at 13:46 By Eduard Kovacs Fortinet patches CVE-2024-21762, a critical remote code execution vulnerability that may have been exploited in the wild. The post Fortinet Warns of New FortiOS Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Fortinet Warns of New FortiOS Zero-Day Read More »

Cisco Patches Critical Vulnerabilities in Enterprise Communication Devices

Cisco Patches Critical Vulnerabilities in Enterprise Communication Devices 2024-02-08 at 16:01 By Ionut Arghire Two critical vulnerabilities in Cisco Expressway series devices can be exploited in CSRF attacks without authentication. The post Cisco Patches Critical Vulnerabilities in Enterprise Communication Devices appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Cisco Patches Critical Vulnerabilities in Enterprise Communication Devices Read More »

Most Linux Systems Exposed to Complete Compromise via Shim Vulnerability 

Most Linux Systems Exposed to Complete Compromise via Shim Vulnerability  2024-02-07 at 16:31 By Ionut Arghire A critical remote code execution vulnerability in Shim could allow attackers to take over vulnerable Linux systems. The post Most Linux Systems Exposed to Complete Compromise via Shim Vulnerability  appeared first on SecurityWeek. This article is an excerpt from

Most Linux Systems Exposed to Complete Compromise via Shim Vulnerability  Read More »

JetBrains Patches Critical Authentication Bypass in TeamCity

JetBrains Patches Critical Authentication Bypass in TeamCity 2024-02-07 at 16:31 By Ionut Arghire JetBrains releases patches for a critical-severity TeamCity authentication bypass leading to remote code execution. The post JetBrains Patches Critical Authentication Bypass in TeamCity appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

JetBrains Patches Critical Authentication Bypass in TeamCity Read More »

Fortinet Patches Critical Vulnerabilities in FortiSIEM

Fortinet Patches Critical Vulnerabilities in FortiSIEM 2024-02-07 at 14:16 By Ionut Arghire Two critical OS command injection flaws in FortiSIEM could allow remote attackers to execute arbitrary code. The post Fortinet Patches Critical Vulnerabilities in FortiSIEM appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Fortinet Patches Critical Vulnerabilities in FortiSIEM Read More »

Canon Patches 7 Critical Vulnerabilities in Small Office Printers

Canon Patches 7 Critical Vulnerabilities in Small Office Printers 2024-02-06 at 16:01 By Ionut Arghire Canon announces patches for seven critical-severity remote code execution flaws impacting small office printer models. The post Canon Patches 7 Critical Vulnerabilities in Small Office Printers appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

Canon Patches 7 Critical Vulnerabilities in Small Office Printers Read More »

Critical Remote Code Execution Vulnerability Patched in Android

Critical Remote Code Execution Vulnerability Patched in Android 2024-02-06 at 14:46 By Ionut Arghire Android’s February 2024 security patches resolve 46 vulnerabilities, including a critical remote code execution bug. The post Critical Remote Code Execution Vulnerability Patched in Android appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Critical Remote Code Execution Vulnerability Patched in Android Read More »

QNAP Patches High-Severity Bugs in QTS, Qsync Central

QNAP Patches High-Severity Bugs in QTS, Qsync Central 2024-02-05 at 16:46 By Ionut Arghire Two high-severity vulnerabilities in QNAP’s operating system could lead to command execution over the network. The post QNAP Patches High-Severity Bugs in QTS, Qsync Central appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

QNAP Patches High-Severity Bugs in QTS, Qsync Central Read More »

CISA Sets 48-hour Deadline for Removal of Insecure Ivanti Products

CISA Sets 48-hour Deadline for Removal of Insecure Ivanti Products 2024-02-01 at 19:01 By Ryan Naraine In an unprecedented move, CISA is demanding that federal agencies disconnect all instances of Ivanti Connect Secure and Ivanti Policy Secure products within 48 hours. The post CISA Sets 48-hour Deadline for Removal of Insecure Ivanti Products appeared first

CISA Sets 48-hour Deadline for Removal of Insecure Ivanti Products Read More »

‘Leaky Vessels’ Container Escape Vulnerabilities Impact Docker, Others 

‘Leaky Vessels’ Container Escape Vulnerabilities Impact Docker, Others  2024-02-01 at 18:01 By Eduard Kovacs Snyk discloses information on Leaky Vessels, several potentially serious container escape vulnerabilities affecting Docker and others. The post ‘Leaky Vessels’ Container Escape Vulnerabilities Impact Docker, Others  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

‘Leaky Vessels’ Container Escape Vulnerabilities Impact Docker, Others  Read More »

Scroll to Top