Vulnerabilities

Apple Patches Vision Pro Vulnerability as CISA Warns of iOS Flaw Exploitation

Apple Patches Vision Pro Vulnerability as CISA Warns of iOS Flaw Exploitation 2024-02-01 at 12:47 By Eduard Kovacs Apple releases first security update for Vision Pro VR headset as CISA issues warning about exploitation of iOS vulnerability. The post Apple Patches Vision Pro Vulnerability as CISA Warns of iOS Flaw Exploitation appeared first on SecurityWeek. […]

Apple Patches Vision Pro Vulnerability as CISA Warns of iOS Flaw Exploitation Read More »

GNU C Library Vulnerability Leads to Full Root Access

GNU C Library Vulnerability Leads to Full Root Access 2024-01-31 at 19:47 By Ionut Arghire Researchers at Qualys call attention to a vulnerability in Linux’s GNU C Library (glibc) that allows full root access to a system. The post GNU C Library Vulnerability Leads to Full Root Access appeared first on SecurityWeek. This article is

GNU C Library Vulnerability Leads to Full Root Access Read More »

After Delays, Ivanti Patches Zero-Days and Confirms New Exploit

After Delays, Ivanti Patches Zero-Days and Confirms New Exploit 2024-01-31 at 19:47 By Ryan Naraine Ivanti documents a brand-new zero-day and belatedly ships patches; Mandiant is reporting “broad exploitation activity.” The post After Delays, Ivanti Patches Zero-Days and Confirms New Exploit appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

After Delays, Ivanti Patches Zero-Days and Confirms New Exploit Read More »

Tor Code Audit Finds 17 Vulnerabilities

Tor Code Audit Finds 17 Vulnerabilities 2024-01-31 at 15:47 By Eduard Kovacs Over a dozen vulnerabilities discovered in Tor audit, including a high-risk flaw that can be exploited to inject arbitrary bridges.  The post Tor Code Audit Finds 17 Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Tor Code Audit Finds 17 Vulnerabilities Read More »

45,000 Exposed Jenkins Instances Found Amid Reports of In-the-Wild Exploitation

45,000 Exposed Jenkins Instances Found Amid Reports of In-the-Wild Exploitation 2024-01-31 at 14:40 By Eduard Kovacs Shadowserver Foundation has seen 45,000 Jenkins instances affected by CVE-2024-23897, which may already be exploited in attacks. The post 45,000 Exposed Jenkins Instances Found Amid Reports of In-the-Wild Exploitation appeared first on SecurityWeek. This article is an excerpt from

45,000 Exposed Jenkins Instances Found Amid Reports of In-the-Wild Exploitation Read More »

Juniper Networks Patches Vulnerabilities in Switches, Firewalls

Juniper Networks Patches Vulnerabilities in Switches, Firewalls 2024-01-30 at 16:46 By Ionut Arghire A high-severity flaw in the J-Web interface of Juniper’s Junos OS could lead to arbitrary command execution, remotely. The post Juniper Networks Patches Vulnerabilities in Switches, Firewalls appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Juniper Networks Patches Vulnerabilities in Switches, Firewalls Read More »

Ivanti Struggling to Hit Zero-Day Patch Release Schedule

Ivanti Struggling to Hit Zero-Day Patch Release Schedule 2024-01-29 at 22:15 By Ryan Naraine Ivanti is struggling to hit its own timeline for the delivery of patches for critical — and already exploited — flaws in its flagship VPN appliances. The post Ivanti Struggling to Hit Zero-Day Patch Release Schedule appeared first on SecurityWeek. This

Ivanti Struggling to Hit Zero-Day Patch Release Schedule Read More »

Vulnerabilities in WatchGuard, Panda Security Products Lead to Code Execution

Vulnerabilities in WatchGuard, Panda Security Products Lead to Code Execution 2024-01-29 at 18:21 By Ionut Arghire Two memory safety vulnerabilities in WatchGuard and Panda Security products could lead to code execution with System privileges. The post Vulnerabilities in WatchGuard, Panda Security Products Lead to Code Execution appeared first on SecurityWeek. This article is an excerpt

Vulnerabilities in WatchGuard, Panda Security Products Lead to Code Execution Read More »

PoC Exploit Published for Critical Jenkins Vulnerability

PoC Exploit Published for Critical Jenkins Vulnerability 2024-01-29 at 18:21 By Ionut Arghire PoC exploit code targeting a critical Jenkins vulnerability patched last week is already publicly available. The post PoC Exploit Published for Critical Jenkins Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

PoC Exploit Published for Critical Jenkins Vulnerability Read More »

Critical Jenkins Vulnerability Leads to Remote Code Execution

Critical Jenkins Vulnerability Leads to Remote Code Execution 2024-01-26 at 14:02 By Ionut Arghire A critical vulnerability in Jenkins’ built-in CLI allows remote attackers to obtain cryptographic keys and execute arbitrary code. The post Critical Jenkins Vulnerability Leads to Remote Code Execution appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

Critical Jenkins Vulnerability Leads to Remote Code Execution Read More »

Hackers Earn $1.3M for Tesla, EV Charger, Infotainment Exploits at Pwn2Own Automotive

Hackers Earn $1.3M for Tesla, EV Charger, Infotainment Exploits at Pwn2Own Automotive 2024-01-26 at 11:05 By Eduard Kovacs Participants have earned more than $1.3 million for hacking Teslas, EV chargers and infotainment systems at Pwn2Own Automotive. The post Hackers Earn $1.3M for Tesla, EV Charger, Infotainment Exploits at Pwn2Own Automotive appeared first on SecurityWeek. This

Hackers Earn $1.3M for Tesla, EV Charger, Infotainment Exploits at Pwn2Own Automotive Read More »

New Offerings From Protect AI, Venafi Tackle Software Supply Chain Security

New Offerings From Protect AI, Venafi Tackle Software Supply Chain Security 2024-01-25 at 16:46 By Kevin Townsend Two new products aim to secure the traditional OSS supply chain, and the new AI model software supply chain. The post New Offerings From Protect AI, Venafi Tackle Software Supply Chain Security appeared first on SecurityWeek. This article

New Offerings From Protect AI, Venafi Tackle Software Supply Chain Security Read More »

Cisco Patches Critical Vulnerability in Enterprise Collaboration Products

Cisco Patches Critical Vulnerability in Enterprise Collaboration Products 2024-01-25 at 15:46 By Ionut Arghire A critical flaw in Cisco Unified Communications and Contact Center Solutions products could lead to remote code execution. The post Cisco Patches Critical Vulnerability in Enterprise Collaboration Products appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

Cisco Patches Critical Vulnerability in Enterprise Collaboration Products Read More »

Thousands of GitLab Instances Unpatched Against Critical Password Reset Bug

Thousands of GitLab Instances Unpatched Against Critical Password Reset Bug 2024-01-25 at 15:46 By Ionut Arghire Over 5,000 GitLab servers have yet to be patched against CVE-2023-7028, a critical password reset vulnerability. The post Thousands of GitLab Instances Unpatched Against Critical Password Reset Bug appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Thousands of GitLab Instances Unpatched Against Critical Password Reset Bug Read More »

Tesla Hack Earns Researchers $100,000 at Pwn2Own Automotive

Tesla Hack Earns Researchers $100,000 at Pwn2Own Automotive 2024-01-25 at 15:46 By Eduard Kovacs Over $1 million paid out in the first two days of Pwn2Own Automotive for Tesla, infotainment and EV charger hacks. The post Tesla Hack Earns Researchers $100,000 at Pwn2Own Automotive appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Tesla Hack Earns Researchers $100,000 at Pwn2Own Automotive Read More »

Pwn2Own Automotive: Hackers Earn Over $700k for Tesla, EV Charger, Infotainment Exploits

Pwn2Own Automotive: Hackers Earn Over $700k for Tesla, EV Charger, Infotainment Exploits 2024-01-24 at 17:48 By Eduard Kovacs On the first day of Pwn2Own Automotive participants earned over $700,000 for hacking Tesla, EV chargers and infotainment systems. The post Pwn2Own Automotive: Hackers Earn Over $700k for Tesla, EV Charger, Infotainment Exploits appeared first on SecurityWeek.

Pwn2Own Automotive: Hackers Earn Over $700k for Tesla, EV Charger, Infotainment Exploits Read More »

Orca Flags Dangerous Google Kubernetes Engine Misconfiguration

Orca Flags Dangerous Google Kubernetes Engine Misconfiguration 2024-01-24 at 17:48 By Ionut Arghire Attackers could take over a Kubernetes cluster if access privileges are granted to all authenticated users in Google Kubernetes Engine. The post Orca Flags Dangerous Google Kubernetes Engine Misconfiguration appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

Orca Flags Dangerous Google Kubernetes Engine Misconfiguration Read More »

PoC Code Published for Just-Disclosed Fortra GoAnywhere Vulnerability

PoC Code Published for Just-Disclosed Fortra GoAnywhere Vulnerability 2024-01-24 at 16:31 By Ionut Arghire PoC code exploiting a critical Fortra GoAnywhere MFT vulnerability gets published one day after public disclosure. The post PoC Code Published for Just-Disclosed Fortra GoAnywhere Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

PoC Code Published for Just-Disclosed Fortra GoAnywhere Vulnerability Read More »

Scroll to Top