Vulnerabilities

Number of Cisco Devices Hacked via Unpatched Vulnerability Increases to 40,000

Number of Cisco Devices Hacked via Unpatched Vulnerability Increases to 40,000 19/10/2023 at 14:01 By Eduard Kovacs The number of Cisco devices hacked via the CVE-2023-20198 zero-day has reached 40,000, including many in the US. The post Number of Cisco Devices Hacked via Unpatched Vulnerability Increases to 40,000 appeared first on SecurityWeek. This article is […]

Number of Cisco Devices Hacked via Unpatched Vulnerability Increases to 40,000 Read More »

Three Months After Patch, Gov-Backed Actors Exploiting WinRAR Flaw

Three Months After Patch, Gov-Backed Actors Exploiting WinRAR Flaw 18/10/2023 at 20:55 By Ryan Naraine Google says it is still catching government-backed groups linked to China and Russia launching WinRAR exploits in targeted attacks. The post Three Months After Patch, Gov-Backed Actors Exploiting WinRAR Flaw appeared first on SecurityWeek. This article is an excerpt from

Three Months After Patch, Gov-Backed Actors Exploiting WinRAR Flaw Read More »

Oracle Patches 185 Vulnerabilities With October 2023 CPU

Oracle Patches 185 Vulnerabilities With October 2023 CPU 18/10/2023 at 15:49 By Ionut Arghire Oracle on Tuesday released 387 new security patches that address 185 vulnerabilities in its code and third-party components. The post Oracle Patches 185 Vulnerabilities With October 2023 CPU appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

Oracle Patches 185 Vulnerabilities With October 2023 CPU Read More »

Recent NetScaler Vulnerability Exploited as Zero-Day Since August

Recent NetScaler Vulnerability Exploited as Zero-Day Since August 18/10/2023 at 14:01 By Ionut Arghire Mandiant says the recently patched Citrix NetScaler vulnerability CVE-2023-4966 had been exploited as zero-day since August. The post Recent NetScaler Vulnerability Exploited as Zero-Day Since August appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Recent NetScaler Vulnerability Exploited as Zero-Day Since August Read More »

US Gov Expects Widespread Exploitation of Atlassian Confluence Vulnerability

US Gov Expects Widespread Exploitation of Atlassian Confluence Vulnerability 17/10/2023 at 14:16 By Ionut Arghire CISA, FBI, and MS-ISAC warn of potential widespread exploitation of CVE-2023-22515, a critical vulnerability in Atlassian Confluence. The post US Gov Expects Widespread Exploitation of Atlassian Confluence Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

US Gov Expects Widespread Exploitation of Atlassian Confluence Vulnerability Read More »

Cisco Devices Hacked via IOS XE Zero-Day Vulnerability

Cisco Devices Hacked via IOS XE Zero-Day Vulnerability 17/10/2023 at 14:16 By Eduard Kovacs Cisco is warning customers that a new IOS XE zero-day vulnerability tracked as CVE-2023-20198 is being exploited to hack devices.  The post Cisco Devices Hacked via IOS XE Zero-Day Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Cisco Devices Hacked via IOS XE Zero-Day Vulnerability Read More »

WordPress Websites Hacked via Royal Elementor Plugin Zero-Day

WordPress Websites Hacked via Royal Elementor Plugin Zero-Day 17/10/2023 at 13:01 By Ionut Arghire A critical vulnerability in the Royal Elementor WordPress plugin has been exploited as a zero-day since August 30. The post WordPress Websites Hacked via Royal Elementor Plugin Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

WordPress Websites Hacked via Royal Elementor Plugin Zero-Day Read More »

Signal Pours Cold Water on Zero-Day Exploit Rumors

Signal Pours Cold Water on Zero-Day Exploit Rumors 16/10/2023 at 17:47 By Ryan Naraine Privacy-focused messaging firm Signal is pouring cold water on widespread rumors of a zero-day exploit in its popular encrypted chat app. The post Signal Pours Cold Water on Zero-Day Exploit Rumors appeared first on SecurityWeek. This article is an excerpt from

Signal Pours Cold Water on Zero-Day Exploit Rumors Read More »

CISA Now Flagging Vulnerabilities, Misconfigurations Exploited by Ransomware

CISA Now Flagging Vulnerabilities, Misconfigurations Exploited by Ransomware 13/10/2023 at 17:16 By Ionut Arghire CISA is now flagging vulnerabilities and misconfigurations that are known to be exploited in ransomware attacks. The post CISA Now Flagging Vulnerabilities, Misconfigurations Exploited by Ransomware appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

CISA Now Flagging Vulnerabilities, Misconfigurations Exploited by Ransomware Read More »

Juniper Networks Patches Over 30 Vulnerabilities in Junos OS

Juniper Networks Patches Over 30 Vulnerabilities in Junos OS 13/10/2023 at 16:16 By Ionut Arghire Juniper Networks patches over 30 vulnerabilities in Junos OS and Junos OS Evolved, including nine high-severity bugs. The post Juniper Networks Patches Over 30 Vulnerabilities in Junos OS appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Juniper Networks Patches Over 30 Vulnerabilities in Junos OS Read More »

Dozens of Squid Proxy Vulnerabilities Remain Unpatched 2 Years After Disclosure

Dozens of Squid Proxy Vulnerabilities Remain Unpatched 2 Years After Disclosure 13/10/2023 at 13:32 By Eduard Kovacs Dozens of Squid caching proxy vulnerabilities remain unpatched two years after a researcher reported them to developers. The post Dozens of Squid Proxy Vulnerabilities Remain Unpatched 2 Years After Disclosure appeared first on SecurityWeek. This article is an

Dozens of Squid Proxy Vulnerabilities Remain Unpatched 2 Years After Disclosure Read More »

SEC Investigating Progress Software Over MOVEit Hack

SEC Investigating Progress Software Over MOVEit Hack 12/10/2023 at 20:16 By Ionut Arghire Progress Software confirms the SEC has launched its own investigation into costly ransomware zero-days in the MOVEit file transfer software. The post SEC Investigating Progress Software Over MOVEit Hack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

SEC Investigating Progress Software Over MOVEit Hack Read More »

Unpatched Vulnerabilities Expose Yifan Industrial Routers to Attacks

Unpatched Vulnerabilities Expose Yifan Industrial Routers to Attacks 12/10/2023 at 14:46 By Eduard Kovacs Industrial routers made by Chinese company Yifan are affected by several critical vulnerabilities that can expose organizations to attacks.  The post Unpatched Vulnerabilities Expose Yifan Industrial Routers to Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Unpatched Vulnerabilities Expose Yifan Industrial Routers to Attacks Read More »

Critical SOCKS5 Vulnerability in cURL Puts Enterprise Systems at Risk

Critical SOCKS5 Vulnerability in cURL Puts Enterprise Systems at Risk 11/10/2023 at 19:01 By Ryan Naraine Flaw poses a direct threat to the SOCKS5 proxy handshake process in cURL and can be exploited remotely in some non-standard configurations. The post Critical SOCKS5 Vulnerability in cURL Puts Enterprise Systems at Risk appeared first on SecurityWeek. This

Critical SOCKS5 Vulnerability in cURL Puts Enterprise Systems at Risk Read More »

Citrix Patches Critical NetScaler ADC, Gateway Vulnerability

Citrix Patches Critical NetScaler ADC, Gateway Vulnerability 11/10/2023 at 17:02 By Ionut Arghire Citrix has released patches for a critical information disclosure vulnerability in NetScaler ADC and NetScaler Gateway. The post Citrix Patches Critical NetScaler ADC, Gateway Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Citrix Patches Critical NetScaler ADC, Gateway Vulnerability Read More »

Organizations Respond to HTTP/2 Zero-Day Exploited for DDoS Attacks

Organizations Respond to HTTP/2 Zero-Day Exploited for DDoS Attacks 11/10/2023 at 15:33 By Eduard Kovacs Organizations respond to HTTP/2 Rapid Reset zero-day vulnerability exploited to launch the largest DDoS attacks seen to date.  The post Organizations Respond to HTTP/2 Zero-Day Exploited for DDoS Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Organizations Respond to HTTP/2 Zero-Day Exploited for DDoS Attacks Read More »

CISA Warns of Attacks Exploiting Adobe Acrobat Vulnerability 

CISA Warns of Attacks Exploiting Adobe Acrobat Vulnerability  11/10/2023 at 13:48 By Ionut Arghire CISA has added five bugs to its Known Exploited Vulnerabilities catalog, including the recent WordPad, Skype, and HTTP/2 zero-days. The post CISA Warns of Attacks Exploiting Adobe Acrobat Vulnerability  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

CISA Warns of Attacks Exploiting Adobe Acrobat Vulnerability  Read More »

Microsoft Blames Nation-State Threat Actor for Confluence Zero-Day Attacks

Microsoft Blames Nation-State Threat Actor for Confluence Zero-Day Attacks 11/10/2023 at 03:01 By Ryan Naraine Microsoft says an APT group tracked as Storm-0062 has been hacking Confluence installations since mid-September, three weeks before Atlassian’s disclosure. The post Microsoft Blames Nation-State Threat Actor for Confluence Zero-Day Attacks appeared first on SecurityWeek. This article is an excerpt

Microsoft Blames Nation-State Threat Actor for Confluence Zero-Day Attacks Read More »

Microsoft Fixes Exploited Zero-Days in WordPad, Skype for Business

Microsoft Fixes Exploited Zero-Days in WordPad, Skype for Business 10/10/2023 at 21:32 By Ryan Naraine Microsoft patches more than 100 vulnerabilities across the Windows ecosystem and warned that three are already being exploited in the wild. The post Microsoft Fixes Exploited Zero-Days in WordPad, Skype for Business appeared first on SecurityWeek. This article is an

Microsoft Fixes Exploited Zero-Days in WordPad, Skype for Business Read More »

Scroll to Top