Vulnerabilities

Intel, AMD, Zoom, Splunk Release Patch Tuesday Security Advisories

Intel, AMD, Zoom, Splunk Release Patch Tuesday Security Advisories 2024-01-11 at 16:32 By Eduard Kovacs Intel, AMD, Zoom and Splunk released security advisories on Patch Tuesday to inform customers about vulnerabilities found in their products. The post Intel, AMD, Zoom, Splunk Release Patch Tuesday Security Advisories appeared first on SecurityWeek. This article is an excerpt […]

Intel, AMD, Zoom, Splunk Release Patch Tuesday Security Advisories Read More »

Cisco Patches Critical Vulnerability in Unity Connection Product

Cisco Patches Critical Vulnerability in Unity Connection Product 2024-01-11 at 14:32 By Ionut Arghire Cisco Unity Connection flaw could allow remote, unauthenticated attackers to upload arbitrary files and execute commands on the system. The post Cisco Patches Critical Vulnerability in Unity Connection Product appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Cisco Patches Critical Vulnerability in Unity Connection Product Read More »

Volexity Catches Chinese Hackers Exploiting Ivanti VPN Zero-Days

Volexity Catches Chinese Hackers Exploiting Ivanti VPN Zero-Days 2024-01-11 at 00:01 By Ryan Naraine Ivanti confirms active zero-day exploits, ships pre-patch mitigations, but says comprehensive fixes won’t be available until January 22. The post Volexity Catches Chinese Hackers Exploiting Ivanti VPN Zero-Days appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

Volexity Catches Chinese Hackers Exploiting Ivanti VPN Zero-Days Read More »

Kyocera Device Manager Vulnerability Exposes Enterprise Credentials

Kyocera Device Manager Vulnerability Exposes Enterprise Credentials 2024-01-10 at 15:32 By Ionut Arghire An improper input validation flaw in Kyocera Device Manager allows attackers to capture credentials, compromise accounts. The post Kyocera Device Manager Vulnerability Exposes Enterprise Credentials appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Kyocera Device Manager Vulnerability Exposes Enterprise Credentials Read More »

SAP’s First Patches of 2024 Resolve Critical Vulnerabilities

SAP’s First Patches of 2024 Resolve Critical Vulnerabilities 2024-01-10 at 15:32 By Ionut Arghire SAP has released patches for critical vulnerabilities in Business Application Studio, Web IDE, and Edge Integration Cell. The post SAP’s First Patches of 2024 Resolve Critical Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

SAP’s First Patches of 2024 Resolve Critical Vulnerabilities Read More »

Microsoft Ships Urgent Fixes for Critical Flaws in Windows Kerberos, Hyper-V

Microsoft Ships Urgent Fixes for Critical Flaws in Windows Kerberos, Hyper-V 2024-01-09 at 21:02 By Ryan Naraine Patch Tuesday: Redmond patches critical, remote code execution vulnerabilities haunting Windows Kerberos and Windows Hyper-V. The post Microsoft Ships Urgent Fixes for Critical Flaws in Windows Kerberos, Hyper-V appeared first on SecurityWeek. This article is an excerpt from

Microsoft Ships Urgent Fixes for Critical Flaws in Windows Kerberos, Hyper-V Read More »

Adobe Patches Code Execution Flaws in Substance 3D Stager

Adobe Patches Code Execution Flaws in Substance 3D Stager 2024-01-09 at 20:02 By Ryan Naraine Patch Tuesday: Adobe patches six security flaws in the Substance 3D Stager product and warned of code execution risks on Windows and macOS. The post Adobe Patches Code Execution Flaws in Substance 3D Stager appeared first on SecurityWeek. This article

Adobe Patches Code Execution Flaws in Substance 3D Stager Read More »

CISA Warns of Apache Superset Vulnerability Exploitation

CISA Warns of Apache Superset Vulnerability Exploitation 2024-01-09 at 20:02 By Ionut Arghire CISA has added a critical-severity Apache Superset flaw (CVE-2023-27524) to its Known Exploited Vulnerabilities catalog. The post CISA Warns of Apache Superset Vulnerability Exploitation appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

CISA Warns of Apache Superset Vulnerability Exploitation Read More »

QNAP Patches High-Severity Flaws in QTS, Video Station, QuMagie, Netatalk Products

QNAP Patches High-Severity Flaws in QTS, Video Station, QuMagie, Netatalk Products 2024-01-08 at 17:01 By Ionut Arghire QNAP has released patches for a dozen vulnerabilities in its products, including several high-severity flaws. The post QNAP Patches High-Severity Flaws in QTS, Video Station, QuMagie, Netatalk Products appeared first on SecurityWeek. This article is an excerpt from

QNAP Patches High-Severity Flaws in QTS, Video Station, QuMagie, Netatalk Products Read More »

Vulnerability Handling in 2023: 28,000 New CVEs, 84 New CNAs

Vulnerability Handling in 2023: 28,000 New CVEs, 84 New CNAs 2024-01-08 at 13:31 By Eduard Kovacs A total of more than 28,000 CVE IDs were assigned in 2023 and 84 new CVE Numbering Authorities (CNAs) were named.  The post Vulnerability Handling in 2023: 28,000 New CVEs, 84 New CNAs appeared first on SecurityWeek. This article

Vulnerability Handling in 2023: 28,000 New CVEs, 84 New CNAs Read More »

Ivanti Patches Critical Vulnerability in Endpoint Manager

Ivanti Patches Critical Vulnerability in Endpoint Manager 2024-01-05 at 14:17 By Ionut Arghire CVE-2023-39336, a critical vulnerability in Ivanti EPM, may lead to device takeover and code execution on the server. The post Ivanti Patches Critical Vulnerability in Endpoint Manager appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Ivanti Patches Critical Vulnerability in Endpoint Manager Read More »

Google Patches Six Vulnerabilities With First Chrome Update of 2024

Google Patches Six Vulnerabilities With First Chrome Update of 2024 2024-01-04 at 17:20 By Ionut Arghire Google has released a Chrome 120 update to resolve six vulnerabilities, including four reported by external researchers. The post Google Patches Six Vulnerabilities With First Chrome Update of 2024 appeared first on SecurityWeek. This article is an excerpt from

Google Patches Six Vulnerabilities With First Chrome Update of 2024 Read More »

New DLL Search Order Hijacking Technique Targets WinSxS folder

New DLL Search Order Hijacking Technique Targets WinSxS folder 2024-01-02 at 17:31 By Ionut Arghire Attackers can abuse a new DLL search order hijacking technique to execute code in applications within the WinSxS folder. The post New DLL Search Order Hijacking Technique Targets WinSxS folder appeared first on SecurityWeek. This article is an excerpt from

New DLL Search Order Hijacking Technique Targets WinSxS folder Read More »

Vulnerabilities in Google Kubernetes Engine Could Allow Cluster Takeover

Vulnerabilities in Google Kubernetes Engine Could Allow Cluster Takeover 2023-12-29 at 14:02 By Ionut Arghire Two flaws in Google Kubernetes Engine could be exploited to escalate privileges and take over the Kubernetes cluster. The post Vulnerabilities in Google Kubernetes Engine Could Allow Cluster Takeover appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Vulnerabilities in Google Kubernetes Engine Could Allow Cluster Takeover Read More »

Critical Apache OFBiz Vulnerability in Attacker Crosshairs

Critical Apache OFBiz Vulnerability in Attacker Crosshairs 2023-12-29 at 13:17 By Eduard Kovacs Shadowserver sees possible in-the-wild exploitation of a critical Apache OFBiz vulnerability tracked as CVE-2023-49070. The post Critical Apache OFBiz Vulnerability in Attacker Crosshairs appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Critical Apache OFBiz Vulnerability in Attacker Crosshairs Read More »

In Other News: Crypto Exchange Hack Guilty Plea, Rating AI Vulnerabilities, Intellexa Spyware 

In Other News: Crypto Exchange Hack Guilty Plea, Rating AI Vulnerabilities, Intellexa Spyware  2023-12-22 at 16:32 By SecurityWeek News Noteworthy stories that might have slipped under the radar: Cryptocurrency exchange hacker pleads guilty, rating LLM vulnerabilities, Intellexa spyware analysis. The post In Other News: Crypto Exchange Hack Guilty Plea, Rating AI Vulnerabilities, Intellexa Spyware  appeared

In Other News: Crypto Exchange Hack Guilty Plea, Rating AI Vulnerabilities, Intellexa Spyware  Read More »

Ivanti Patches Dozen Critical Vulnerabilities in Avalanche MDM Product

Ivanti Patches Dozen Critical Vulnerabilities in Avalanche MDM Product 21/12/2023 at 15:32 By Eduard Kovacs Ivanti has patched 20 vulnerabilities in its Avalanche MDM product, including a dozen remote code execution flaws rated critical. The post Ivanti Patches Dozen Critical Vulnerabilities in Avalanche MDM Product appeared first on SecurityWeek. This article is an excerpt from

Ivanti Patches Dozen Critical Vulnerabilities in Avalanche MDM Product Read More »

Google Rushes to Patch Eighth Chrome Zero-Day This Year

Google Rushes to Patch Eighth Chrome Zero-Day This Year 21/12/2023 at 13:48 By Ionut Arghire Google warns of in-the-wild exploitation of CVE-2023-7024, a new Chrome vulnerability, the eighth documented this year. The post Google Rushes to Patch Eighth Chrome Zero-Day This Year appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

Google Rushes to Patch Eighth Chrome Zero-Day This Year Read More »

Mozilla Patches Firefox Vulnerability Allowing Remote Code Execution, Sandbox Escape

Mozilla Patches Firefox Vulnerability Allowing Remote Code Execution, Sandbox Escape 20/12/2023 at 18:32 By Ionut Arghire Firefox and Thunderbird security updates released this week address multiple memory safety bugs in both products. The post Mozilla Patches Firefox Vulnerability Allowing Remote Code Execution, Sandbox Escape appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Mozilla Patches Firefox Vulnerability Allowing Remote Code Execution, Sandbox Escape Read More »

Outlook Plays Attacker Tunes: Vulnerability Chain Leading to Zero-Click RCE

Outlook Plays Attacker Tunes: Vulnerability Chain Leading to Zero-Click RCE 19/12/2023 at 23:55 By Ionut Arghire Akamai researchers document more vulnerabilities and patch bypasses leading to zero-click remote code execution in Microsoft Outlook. The post Outlook Plays Attacker Tunes: Vulnerability Chain Leading to Zero-Click RCE appeared first on SecurityWeek. This article is an excerpt from

Outlook Plays Attacker Tunes: Vulnerability Chain Leading to Zero-Click RCE Read More »

Scroll to Top