Vulnerabilities

Atlassian Patches Critical Remote Code Execution Vulnerabilities

Atlassian Patches Critical Remote Code Execution Vulnerabilities 07/12/2023 at 13:32 By Ionut Arghire Atlassian has released patches for critical-severity remote code execution flaws in Confluence and other products. The post Atlassian Patches Critical Remote Code Execution Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Atlassian Patches Critical Remote Code Execution Vulnerabilities Read More »

Exploitation of Recent Cisco IOS XE Vulnerabilities Spikes

Exploitation of Recent Cisco IOS XE Vulnerabilities Spikes 06/12/2023 at 19:03 By Ionut Arghire The Shadowserver Foundation warns of an increase in the number of devices hacked via recent Cisco IOS XE vulnerabilities. The post Exploitation of Recent Cisco IOS XE Vulnerabilities Spikes appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS […]

Exploitation of Recent Cisco IOS XE Vulnerabilities Spikes Read More »

Enterprise, Consumer Devices Exposed to Attacks via Malicious UEFI Logo Images

Enterprise, Consumer Devices Exposed to Attacks via Malicious UEFI Logo Images 06/12/2023 at 19:03 By Eduard Kovacs LogoFAIL is an UEFI image parser attack allowing hackers to compromise consumer and enterprise devices using malicious logo images. The post Enterprise, Consumer Devices Exposed to Attacks via Malicious UEFI Logo Images appeared first on SecurityWeek. This article […]

Enterprise, Consumer Devices Exposed to Attacks via Malicious UEFI Logo Images Read More »

CISA Urges Federal Agencies to Patch Exploited Qualcomm Vulnerabilities

CISA Urges Federal Agencies to Patch Exploited Qualcomm Vulnerabilities 06/12/2023 at 16:01 By Ionut Arghire CISA has added to its Known Exploited Vulnerabilities Catalog four Qualcomm bugs, including three exploited as zero-days. The post CISA Urges Federal Agencies to Patch Exploited Qualcomm Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS […]

CISA Urges Federal Agencies to Patch Exploited Qualcomm Vulnerabilities Read More »

Apple Patches WebKit Flaws Exploited on Older iPhones

Apple Patches WebKit Flaws Exploited on Older iPhones 30/11/2023 at 23:02 By Ryan Naraine Apple’s security response team warns that flaws CVE-2023-42916 and CVE-2023-42917 were already exploited against versions of iOS before iOS 16.7.1. The post Apple Patches WebKit Flaws Exploited on Older iPhones appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Apple Patches WebKit Flaws Exploited on Older iPhones Read More »

Major Security Flaws in Zyxel Firewalls, Access Points, NAS Devices

Major Security Flaws in Zyxel Firewalls, Access Points, NAS Devices 30/11/2023 at 20:18 By Ryan Naraine Zyxel patches at least 15 security flaws that expose users to authentication bypass, command injection and denial-of-service attacks. The post Major Security Flaws in Zyxel Firewalls, Access Points, NAS Devices appeared first on SecurityWeek. This article is an excerpt […]

Major Security Flaws in Zyxel Firewalls, Access Points, NAS Devices Read More »

Google Patches Seventh Chrome Zero-Day of 2023

Google Patches Seventh Chrome Zero-Day of 2023 29/11/2023 at 16:46 By Ionut Arghire The latest Chrome security update addresses the seventh exploited zero-day vulnerability documented in the browser in 2023. The post Google Patches Seventh Chrome Zero-Day of 2023 appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Google Patches Seventh Chrome Zero-Day of 2023 Read More »

Exploitation of Critical ownCloud Vulnerability Begins

Exploitation of Critical ownCloud Vulnerability Begins 28/11/2023 at 18:01 By Ionut Arghire Threat actors have started exploiting a critical ownCloud vulnerability leading to sensitive information disclosure. The post Exploitation of Critical ownCloud Vulnerability Begins appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Exploitation of Critical ownCloud Vulnerability Begins Read More »

Critical ownCloud Flaws Lead to Sensitive Information Disclosure, Authentication Bypass

Critical ownCloud Flaws Lead to Sensitive Information Disclosure, Authentication Bypass 27/11/2023 at 19:46 By Ionut Arghire Three critical vulnerabilities in ownCloud could lead to sensitive information disclosure and authentication and validation bypass. The post Critical ownCloud Flaws Lead to Sensitive Information Disclosure, Authentication Bypass appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Critical ownCloud Flaws Lead to Sensitive Information Disclosure, Authentication Bypass Read More »

Microsoft Offers Up to $20,000 for Vulnerabilities in Defender Products

Microsoft Offers Up to $20,000 for Vulnerabilities in Defender Products 22/11/2023 at 17:17 By Ionut Arghire Microsoft invites researchers to new bug bounty program focused on vulnerabilities in its Defender products. The post Microsoft Offers Up to $20,000 for Vulnerabilities in Defender Products appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS […]

Microsoft Offers Up to $20,000 for Vulnerabilities in Defender Products Read More »

Citrix, Gov Agencies Issue Fresh Warnings on CitrixBleed Vulnerability

Citrix, Gov Agencies Issue Fresh Warnings on CitrixBleed Vulnerability 22/11/2023 at 15:17 By Ionut Arghire Administrators are urged to patch the recent CitrixBleed NetScaler vulnerability as LockBit starts exploiting it. The post Citrix, Gov Agencies Issue Fresh Warnings on CitrixBleed Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View […]

Citrix, Gov Agencies Issue Fresh Warnings on CitrixBleed Vulnerability Read More »

Microsoft announces Defender bug bounty program

Microsoft announces Defender bug bounty program 22/11/2023 at 14:47 By Helga Labus Microsoft has announced a new bug bounty program aimed at unearthing vulnerabilities in Defender-related products and services, and is offering participants the possibility to earn up to $20,000 for the most critical bugs. The Microsoft Defender bug bounty program Microsoft Defender includes various […]

Microsoft announces Defender bug bounty program Read More »

Microsoft Paid Out $63 Million Since Launch of First Bug Bounty Program 10 Years Ago

Microsoft Paid Out $63 Million Since Launch of First Bug Bounty Program 10 Years Ago 21/11/2023 at 15:16 By Ionut Arghire Over the past ten years, Microsoft has handed out $63 million in rewards as part of its bug bounty programs. The post Microsoft Paid Out $63 Million Since Launch of First Bug Bounty Program […]

Microsoft Paid Out $63 Million Since Launch of First Bug Bounty Program 10 Years Ago Read More »

Organizations’ serious commitment to software risk management pays off

Organizations’ serious commitment to software risk management pays off 21/11/2023 at 07:32 By Industry News There has been a significant decrease in vulnerabilities found in target applications – from 97% in 2020 to 83% in 2022 – an encouraging sign that code reviews, automated testing and continuous integration are helping to reduce common programming errors, […]

Organizations’ serious commitment to software risk management pays off Read More »

Over a Dozen Exploitable Vulnerabilities Found in AI/ML Tools

Over a Dozen Exploitable Vulnerabilities Found in AI/ML Tools 17/11/2023 at 17:45 By Ionut Arghire Bug hunters uncover over a dozen exploitable vulnerabilities in tools used to build chatbots and other types of AI/ML models. The post Over a Dozen Exploitable Vulnerabilities Found in AI/ML Tools appeared first on SecurityWeek. This article is an excerpt […]

Over a Dozen Exploitable Vulnerabilities Found in AI/ML Tools Read More »

Microsoft Patches Sensitive Information Disclosure Vulnerability in Azure CLI

Microsoft Patches Sensitive Information Disclosure Vulnerability in Azure CLI 15/11/2023 at 18:02 By Ionut Arghire Microsoft provided guidance on an Azure CLI bug leading to the exposure of sensitive information through GitHub Actions logs. The post Microsoft Patches Sensitive Information Disclosure Vulnerability in Azure CLI appeared first on SecurityWeek. This article is an excerpt from […]

Microsoft Patches Sensitive Information Disclosure Vulnerability in Azure CLI Read More »

SAP Patches Critical Vulnerability in Business One Product

SAP Patches Critical Vulnerability in Business One Product 15/11/2023 at 17:01 By Ionut Arghire SAP released a hotfix for a critical-severity improper access control vulnerability in Business One product installation. The post SAP Patches Critical Vulnerability in Business One Product appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original […]

SAP Patches Critical Vulnerability in Business One Product Read More »

Chipmaker Patch Tuesday: Intel, AMD Address Over 130 Vulnerabilities

Chipmaker Patch Tuesday: Intel, AMD Address Over 130 Vulnerabilities 15/11/2023 at 13:17 By Eduard Kovacs Intel and AMD have informed their customers about a total of more than 130 vulnerabilities found in their products. The post Chipmaker Patch Tuesday: Intel, AMD Address Over 130 Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from […]

Chipmaker Patch Tuesday: Intel, AMD Address Over 130 Vulnerabilities Read More »

Critical Authentication Bypass Flaw in VMware Cloud Director Appliance

Critical Authentication Bypass Flaw in VMware Cloud Director Appliance 15/11/2023 at 00:32 By Ryan Naraine VMware flaw carries a CVSS severity-score of 9.8/10 and can be exploited to bypass login restrictions when authenticating on certain ports. The post Critical Authentication Bypass Flaw in VMware Cloud Director Appliance appeared first on SecurityWeek. This article is an […]

Critical Authentication Bypass Flaw in VMware Cloud Director Appliance Read More »

Scroll to Top