Vulnerabilities

SysAid Zero-Day Vulnerability Exploited by Ransomware Group

SysAid Zero-Day Vulnerability Exploited by Ransomware Group 09/11/2023 at 13:32 By Eduard Kovacs CVE-2023-47246 zero-day vulnerability in SysAid IT service management software has been exploited by Cl0p ransomware affiliates. The post SysAid Zero-Day Vulnerability Exploited by Ransomware Group appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

SysAid Zero-Day Vulnerability Exploited by Ransomware Group Read More »

Critical Vulnerabilities Expose Veeam ONE Software to Code Execution

Critical Vulnerabilities Expose Veeam ONE Software to Code Execution 07/11/2023 at 19:46 By Ionut Arghire Veeam Software has rolled out patches to cover code execution vulnerabilities in its Veeam ONE IT monitoring product. The post Critical Vulnerabilities Expose Veeam ONE Software to Code Execution appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Critical Vulnerabilities Expose Veeam ONE Software to Code Execution Read More »

Exploitation of Critical Confluence Vulnerability Begins

Exploitation of Critical Confluence Vulnerability Begins 06/11/2023 at 15:47 By Ionut Arghire Threat actors have started exploiting a recent critical vulnerability in Confluence Data Center and Confluence Server. The post Exploitation of Critical Confluence Vulnerability Begins appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Exploitation of Critical Confluence Vulnerability Begins Read More »

Microsoft Says Exchange ‘Zero Days’ Disclosed by ZDI Already Patched or Not Urgent

Microsoft Says Exchange ‘Zero Days’ Disclosed by ZDI Already Patched or Not Urgent 06/11/2023 at 13:30 By Eduard Kovacs Microsoft says four Exchange ‘zero-days’ disclosed by ZDI have either already been patched or they don’t require immediate attention. The post Microsoft Says Exchange ‘Zero Days’ Disclosed by ZDI Already Patched or Not Urgent appeared first

Microsoft Says Exchange ‘Zero Days’ Disclosed by ZDI Already Patched or Not Urgent Read More »

Mass Exploitation of ‘Citrix Bleed’ Vulnerability Underway

Mass Exploitation of ‘Citrix Bleed’ Vulnerability Underway 01/11/2023 at 17:31 By Ionut Arghire Multiple threat actors are exploiting CVE-2023-4966, aka Citrix Bleed, a critical vulnerability in NetScaler ADC and Gateway. The post Mass Exploitation of ‘Citrix Bleed’ Vulnerability Underway appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Mass Exploitation of ‘Citrix Bleed’ Vulnerability Underway Read More »

Atlassian CISO Urges Quick Action to Protect Confluence Instances From Critical Vulnerability

Atlassian CISO Urges Quick Action to Protect Confluence Instances From Critical Vulnerability 31/10/2023 at 21:30 By Ionut Arghire Atlassian warns that a critical vulnerability in Confluence Data Center and Server could lead to significant data loss if exploited. The post Atlassian CISO Urges Quick Action to Protect Confluence Instances From Critical Vulnerability appeared first on

Atlassian CISO Urges Quick Action to Protect Confluence Instances From Critical Vulnerability Read More »

Hackers Earn Over $1 Million at Pwn2Own Toronto 2023

Hackers Earn Over $1 Million at Pwn2Own Toronto 2023 30/10/2023 at 16:46 By Ionut Arghire Hackers have demonstrated 58 zero-days and earned more than $1 million in rewards at Pwn2Own Toronto 2023. The post Hackers Earn Over $1 Million at Pwn2Own Toronto 2023 appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Hackers Earn Over $1 Million at Pwn2Own Toronto 2023 Read More »

F5 Warns of Critical Remote Code Execution Vulnerability in BIG-IP

F5 Warns of Critical Remote Code Execution Vulnerability in BIG-IP 27/10/2023 at 17:47 By Ionut Arghire A critical-severity vulnerability in F5 BIG-IP CVE-2023-46747 allows unauthenticated attackers to execute code remotely. The post F5 Warns of Critical Remote Code Execution Vulnerability in BIG-IP appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

F5 Warns of Critical Remote Code Execution Vulnerability in BIG-IP Read More »

Critical Mirth Connect Vulnerability Could Expose Sensitive Healthcare Data

Critical Mirth Connect Vulnerability Could Expose Sensitive Healthcare Data 26/10/2023 at 22:03 By Ionut Arghire Mirth Connect versions prior to 4.4.1 are vulnerable to CVE-2023-43208, a bypass for an RCE vulnerability. The post Critical Mirth Connect Vulnerability Could Expose Sensitive Healthcare Data appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

Critical Mirth Connect Vulnerability Could Expose Sensitive Healthcare Data Read More »

Hackers Earn $350k on Second Day at Pwn2Own Toronto 2023

Hackers Earn $350k on Second Day at Pwn2Own Toronto 2023 26/10/2023 at 20:02 By Ionut Arghire Smart speakers, printers, routers, NAS devices, and mobile phones were hacked on the second day at Pwn2Own Toronto 2023. The post Hackers Earn $350k on Second Day at Pwn2Own Toronto 2023 appeared first on SecurityWeek. This article is an

Hackers Earn $350k on Second Day at Pwn2Own Toronto 2023 Read More »

iLeakage Attack Exploits Safari to Steal Sensitive Data From Macs, iPhones

iLeakage Attack Exploits Safari to Steal Sensitive Data From Macs, iPhones 26/10/2023 at 19:32 By Eduard Kovacs New iLeakage side-channel speculative execution attack exploits Safari to steal sensitive information from Macs and iPhones. The post iLeakage Attack Exploits Safari to Steal Sensitive Data From Macs, iPhones appeared first on SecurityWeek. This article is an excerpt

iLeakage Attack Exploits Safari to Steal Sensitive Data From Macs, iPhones Read More »

Apple Ships Major iOS, macOS Security Updates

Apple Ships Major iOS, macOS Security Updates 25/10/2023 at 23:01 By Ryan Naraine Apple patches dozens of serious security flaws in its macOS and iOS platforms, warning that hackers could launch code execution exploits. The post Apple Ships Major iOS, macOS Security Updates appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Apple Ships Major iOS, macOS Security Updates Read More »

Firefox, Chrome Updates Patch High-Severity Vulnerabilities

Firefox, Chrome Updates Patch High-Severity Vulnerabilities 25/10/2023 at 23:01 By Ionut Arghire Firefox and Chrome updates released this week resolve multiple high-severity memory safety vulnerabilities. The post Firefox, Chrome Updates Patch High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Firefox, Chrome Updates Patch High-Severity Vulnerabilities Read More »

Hackers Earn $400k on First Day at Pwn2Own Toronto 2023

Hackers Earn $400k on First Day at Pwn2Own Toronto 2023 25/10/2023 at 19:17 By Ionut Arghire NAS devices, printers, IP cameras, speakers, and mobile phones were hacked on the first day at Pwn2Own Toronto 2023. The post Hackers Earn $400k on First Day at Pwn2Own Toronto 2023 appeared first on SecurityWeek. This article is an

Hackers Earn $400k on First Day at Pwn2Own Toronto 2023 Read More »

Censys Banks $75M for Attack Surface Management Technology

Censys Banks $75M for Attack Surface Management Technology 25/10/2023 at 18:17 By Ryan Naraine Michigan startup raises $75 million in new funding as venture capital investors bet big on attack surface management technologies. The post Censys Banks $75M for Attack Surface Management Technology appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Censys Banks $75M for Attack Surface Management Technology Read More »

VMware vCenter Flaw So Critical, Patches Released for End-of-Life Products

VMware vCenter Flaw So Critical, Patches Released for End-of-Life Products 25/10/2023 at 16:31 By Ryan Naraine VMware described the bug as an out-of-bounds write issue in its implementation of the DCE/RPC protocol. CVSS severity score of 9.8/10. The post VMware vCenter Flaw So Critical, Patches Released for End-of-Life Products appeared first on SecurityWeek. This article

VMware vCenter Flaw So Critical, Patches Released for End-of-Life Products Read More »

Number of Cisco Devices Hacked via Zero-Day Remains High as Attackers Update Implant

Number of Cisco Devices Hacked via Zero-Day Remains High as Attackers Update Implant 24/10/2023 at 20:02 By Eduard Kovacs The number of Cisco devices hacked via recent zero-days remains high, but the attackers have updated their implant. The post Number of Cisco Devices Hacked via Zero-Day Remains High as Attackers Update Implant appeared first on

Number of Cisco Devices Hacked via Zero-Day Remains High as Attackers Update Implant Read More »

SolarWinds Patches High-Severity Flaws in Access Rights Manager

SolarWinds Patches High-Severity Flaws in Access Rights Manager 23/10/2023 at 21:49 By Ionut Arghire SolarWinds patches high-severity flaws in its Access Rights Manager product, including three unauthenticated remote code execution issues. The post SolarWinds Patches High-Severity Flaws in Access Rights Manager appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

SolarWinds Patches High-Severity Flaws in Access Rights Manager Read More »

Cisco Finds Second Zero-Day as Number of Hacked Devices Apparently Drops

Cisco Finds Second Zero-Day as Number of Hacked Devices Apparently Drops 23/10/2023 at 21:49 By Eduard Kovacs Cisco has found a second zero-day vulnerability that has been exploited in recent attacks as the number of hacked devices has started dropping. The post Cisco Finds Second Zero-Day as Number of Hacked Devices Apparently Drops appeared first

Cisco Finds Second Zero-Day as Number of Hacked Devices Apparently Drops Read More »

Scroll to Top