Vulnerabilities

New NTLM Hash Leak Attacks Target Outlook, Windows Programs

New NTLM Hash Leak Attacks Target Outlook, Windows Programs 2024-01-22 at 17:16 By Eduard Kovacs Varonis finds one vulnerability and three attack methods that can be used to obtain NTLM hashes via Outlook and two Windows programs. The post New NTLM Hash Leak Attacks Target Outlook, Windows Programs appeared first on SecurityWeek. This article is […]

New NTLM Hash Leak Attacks Target Outlook, Windows Programs Read More »

Chinese Spies Exploited VMware vCenter Server Vulnerability Since 2021

Chinese Spies Exploited VMware vCenter Server Vulnerability Since 2021 2024-01-22 at 13:16 By Ionut Arghire CVE-2023-34048, a vCenter Server vulnerability patched in October 2023, had been exploited as zero-day for a year and a half. The post Chinese Spies Exploited VMware vCenter Server Vulnerability Since 2021 appeared first on SecurityWeek. This article is an excerpt

Chinese Spies Exploited VMware vCenter Server Vulnerability Since 2021 Read More »

CISA Issues Emergency Directive on Ivanti Zero-Days

CISA Issues Emergency Directive on Ivanti Zero-Days 2024-01-19 at 23:31 By Ryan Naraine The US government’s cybersecurity agency CISA ramps up the pressure on organizations to mitigate two exploited Ivanti VPN vulnerabilities. The post CISA Issues Emergency Directive on Ivanti Zero-Days appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

CISA Issues Emergency Directive on Ivanti Zero-Days Read More »

VMware vCenter Server Vulnerability Exploited in Wild 

VMware vCenter Server Vulnerability Exploited in Wild  2024-01-19 at 13:16 By Eduard Kovacs VMware warns customers that CVE-2023-34048, a vCenter Server vulnerability patched in October 2023, is being exploited in the wild.  The post VMware vCenter Server Vulnerability Exploited in Wild  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

VMware vCenter Server Vulnerability Exploited in Wild  Read More »

Ivanti EPMM Vulnerability Targeted in Attacks as Exploitation of VPN Flaws Increases

Ivanti EPMM Vulnerability Targeted in Attacks as Exploitation of VPN Flaws Increases 2024-01-19 at 13:16 By Eduard Kovacs The number of Ivanti VPN appliances compromised through exploitation of recent flaws increases and another vulnerability is added to exploited list. The post Ivanti EPMM Vulnerability Targeted in Attacks as Exploitation of VPN Flaws Increases appeared first

Ivanti EPMM Vulnerability Targeted in Attacks as Exploitation of VPN Flaws Increases Read More »

Unpatched Rapid SCADA Vulnerabilities Expose Industrial Organizations to Attacks

Unpatched Rapid SCADA Vulnerabilities Expose Industrial Organizations to Attacks 2024-01-18 at 18:16 By Eduard Kovacs Seven vulnerabilities found in Rapid SCADA could be exploited to gain access to sensitive industrial systems, but they remain unpatched. The post Unpatched Rapid SCADA Vulnerabilities Expose Industrial Organizations to Attacks appeared first on SecurityWeek. This article is an excerpt

Unpatched Rapid SCADA Vulnerabilities Expose Industrial Organizations to Attacks Read More »

Atlassian Warns of Critical RCE Vulnerability in Outdated Confluence Instances

Atlassian Warns of Critical RCE Vulnerability in Outdated Confluence Instances 2024-01-17 at 17:31 By Ionut Arghire Out-of-date Confluence Data Center and Server instances are haunted by a critical vulnerability leading to remote code execution. The post Atlassian Warns of Critical RCE Vulnerability in Outdated Confluence Instances appeared first on SecurityWeek. This article is an excerpt

Atlassian Warns of Critical RCE Vulnerability in Outdated Confluence Instances Read More »

AI Data Exposed to ‘LeftoverLocals’ Attack via Vulnerable AMD, Apple, Qualcomm GPUs

AI Data Exposed to ‘LeftoverLocals’ Attack via Vulnerable AMD, Apple, Qualcomm GPUs 2024-01-17 at 15:31 By Eduard Kovacs Researchers show how a new attack named LeftoverLocals, which impacts GPUs from AMD, Apple and Qualcomm, can be used to obtain AI data. The post AI Data Exposed to ‘LeftoverLocals’ Attack via Vulnerable AMD, Apple, Qualcomm GPUs

AI Data Exposed to ‘LeftoverLocals’ Attack via Vulnerable AMD, Apple, Qualcomm GPUs Read More »

GitHub Rotates Credentials in Response to Vulnerability

GitHub Rotates Credentials in Response to Vulnerability 2024-01-17 at 15:31 By Ionut Arghire GitHub rotates credentials and releases patches after being alerted of a vulnerability affecting GitHub.com and GitHub Enterprise Server. The post GitHub Rotates Credentials in Response to Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

GitHub Rotates Credentials in Response to Vulnerability Read More »

Oracle Patches 200 Vulnerabilities With January 2024 CPU

Oracle Patches 200 Vulnerabilities With January 2024 CPU 2024-01-17 at 13:31 By Ionut Arghire Oracle releases 389 new security patches to address 200 vulnerabilities as part of the first Critical Patch Update of 2024. The post Oracle Patches 200 Vulnerabilities With January 2024 CPU appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Oracle Patches 200 Vulnerabilities With January 2024 CPU Read More »

Citrix Warns NetScaler ADC Customers of New Zero-Day Exploitation

Citrix Warns NetScaler ADC Customers of New Zero-Day Exploitation 2024-01-17 at 12:16 By Eduard Kovacs Citrix is aware of attacks exploiting two new NetScaler ADC and Gateway zero-day vulnerabilities tracked as CVE-2023-6548 and CVE-2023-6549. The post Citrix Warns NetScaler ADC Customers of New Zero-Day Exploitation appeared first on SecurityWeek. This article is an excerpt from

Citrix Warns NetScaler ADC Customers of New Zero-Day Exploitation Read More »

Google Warns of Chrome Browser Zero-Day Being Exploited

Google Warns of Chrome Browser Zero-Day Being Exploited 2024-01-16 at 23:31 By Ryan Naraine The exploited zero-day, tagged as CVE-2024-0519, is described as an out-of-bounds memory access issue in the V8 JavaScript engine. The post Google Warns of Chrome Browser Zero-Day Being Exploited appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Google Warns of Chrome Browser Zero-Day Being Exploited Read More »

Vulnerabilities Expose PAX Payment Terminals to Hacking

Vulnerabilities Expose PAX Payment Terminals to Hacking 2024-01-16 at 18:16 By Ionut Arghire Vulnerabilities in Android-based PoS terminals from PAX can be exploited to downgrade bootloaders, execute arbitrary code. The post Vulnerabilities Expose PAX Payment Terminals to Hacking appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Vulnerabilities Expose PAX Payment Terminals to Hacking Read More »

Remotely Exploitable ‘PixieFail’ Flaws Found in Tianocore EDK II PXE Implementation

Remotely Exploitable ‘PixieFail’ Flaws Found in Tianocore EDK II PXE Implementation 2024-01-16 at 16:16 By Ryan Naraine Quarkslab finds serious, remotely exploitable vulnerabilities in EDK II, the de-facto open source reference implementation of the UEFI spec. The post Remotely Exploitable ‘PixieFail’ Flaws Found in Tianocore EDK II PXE Implementation appeared first on SecurityWeek. This article

Remotely Exploitable ‘PixieFail’ Flaws Found in Tianocore EDK II PXE Implementation Read More »

VMware Urges Customers to Patch Critical Aria Automation Vulnerability 

VMware Urges Customers to Patch Critical Aria Automation Vulnerability  2024-01-16 at 16:16 By Eduard Kovacs Aria Automation is affected by a critical vulnerability that could be exploited to gain access to remote organizations and workflows. The post VMware Urges Customers to Patch Critical Aria Automation Vulnerability  appeared first on SecurityWeek. This article is an excerpt

VMware Urges Customers to Patch Critical Aria Automation Vulnerability  Read More »

180k Internet-Exposed SonicWall Firewalls Vulnerable to DoS Attacks, Possibly RCE

180k Internet-Exposed SonicWall Firewalls Vulnerable to DoS Attacks, Possibly RCE 2024-01-16 at 16:16 By Ionut Arghire Two DoS vulnerabilities patched in 2022 and 2023 haunt nearly 180,000 internet-exposed SonicWall firewalls. The post 180k Internet-Exposed SonicWall Firewalls Vulnerable to DoS Attacks, Possibly RCE appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

180k Internet-Exposed SonicWall Firewalls Vulnerable to DoS Attacks, Possibly RCE Read More »

Remote Code Execution Vulnerability Found in Opera File Sharing Feature

Remote Code Execution Vulnerability Found in Opera File Sharing Feature 2024-01-16 at 16:16 By Ionut Arghire A vulnerability in Opera browser’s file sharing feature My Flow could be exploited for remote code execution. The post Remote Code Execution Vulnerability Found in Opera File Sharing Feature appeared first on SecurityWeek. This article is an excerpt from

Remote Code Execution Vulnerability Found in Opera File Sharing Feature Read More »

GitLab Patches Critical Password Reset Vulnerability

GitLab Patches Critical Password Reset Vulnerability 2024-01-15 at 13:46 By Ionut Arghire GitLab has resolved a critical authentication vulnerability allowing attackers to hijack password reset emails. The post GitLab Patches Critical Password Reset Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

GitLab Patches Critical Password Reset Vulnerability Read More »

Juniper Networks Patches Critical Remote Code Execution Flaw in Firewalls, Switches

Juniper Networks Patches Critical Remote Code Execution Flaw in Firewalls, Switches 2024-01-15 at 13:18 By Eduard Kovacs Juniper Networks patches over 100 vulnerabilities, including a critical flaw that can be exploited for remote code execution against firewalls and switches. The post Juniper Networks Patches Critical Remote Code Execution Flaw in Firewalls, Switches appeared first on

Juniper Networks Patches Critical Remote Code Execution Flaw in Firewalls, Switches Read More »

Apple Patches Keystroke Injection Vulnerability in Magic Keyboard

Apple Patches Keystroke Injection Vulnerability in Magic Keyboard 2024-01-12 at 13:16 By Ionut Arghire Apple’s latest Magic Keyboard firmware addresses a recently disclosed Bluetooth keyboard injection vulnerability. The post Apple Patches Keystroke Injection Vulnerability in Magic Keyboard appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Apple Patches Keystroke Injection Vulnerability in Magic Keyboard Read More »

Scroll to Top