Vulnerabilities

Cloudflare Users Exposed to Attacks Launched From Within Cloudflare: Researchers

Cloudflare Users Exposed to Attacks Launched From Within Cloudflare: Researchers 29/09/2023 at 14:31 By Ionut Arghire Gaps in Cloudflare’s security controls allow users to bypass protections and target others from the platform itself. The post Cloudflare Users Exposed to Attacks Launched From Within Cloudflare: Researchers appeared first on SecurityWeek. This article is an excerpt from […]

Cloudflare Users Exposed to Attacks Launched From Within Cloudflare: Researchers Read More »

Progress Software Patches Critical Pre-Auth Flaws in WS_FTP Server Product 

Progress Software Patches Critical Pre-Auth Flaws in WS_FTP Server Product  28/09/2023 at 22:48 By Ryan Naraine Progress Software ships patches for critical-severity flaws in its WS_FTP file transfer software and warns that a pre-authenticated attacker could wreak havoc on the underlying operating system. The post Progress Software Patches Critical Pre-Auth Flaws in WS_FTP Server Product 

Progress Software Patches Critical Pre-Auth Flaws in WS_FTP Server Product  Read More »

Cisco Warns of IOS Software Zero-Day Exploitation Attempts

Cisco Warns of IOS Software Zero-Day Exploitation Attempts 28/09/2023 at 15:32 By Ionut Arghire Cisco has released patches for vulnerability in the GET VPN feature of IOS and IOS XE software that has been exploited in attacks. The post Cisco Warns of IOS Software Zero-Day Exploitation Attempts appeared first on SecurityWeek. This article is an

Cisco Warns of IOS Software Zero-Day Exploitation Attempts Read More »

Google Rushes to Patch New Zero-Day Exploited by Spyware Vendor

Google Rushes to Patch New Zero-Day Exploited by Spyware Vendor 28/09/2023 at 13:16 By Eduard Kovacs Google has rushed to patch a new Chrome zero-day vulnerability, tracked as CVE-2023-5217 and exploited by a spyware vendor.  The post Google Rushes to Patch New Zero-Day Exploited by Spyware Vendor appeared first on SecurityWeek. This article is an

Google Rushes to Patch New Zero-Day Exploited by Spyware Vendor Read More »

Firefox 118 Patches High-Severity Vulnerabilities

Firefox 118 Patches High-Severity Vulnerabilities 27/09/2023 at 17:17 By Ionut Arghire Firefox 118 patches six high-severity vulnerabilities, including a memory leak potentially leading to sandbox escape. The post Firefox 118 Patches High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Firefox 118 Patches High-Severity Vulnerabilities Read More »

macOS 14 Sonoma Patches 60 Vulnerabilities

macOS 14 Sonoma Patches 60 Vulnerabilities 27/09/2023 at 15:30 By Eduard Kovacs macOS 14 Sonoma has been officially released by Apple and the latest version of the operating system patches over 60 vulnerabilities. The post macOS 14 Sonoma Patches 60 Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

macOS 14 Sonoma Patches 60 Vulnerabilities Read More »

In-the-Wild Exploitation Expected for Critical TeamCity Flaw Allowing Server Takeover

In-the-Wild Exploitation Expected for Critical TeamCity Flaw Allowing Server Takeover 25/09/2023 at 13:32 By Ionut Arghire A critical vulnerability in the TeamCity CI/CD server could allow unauthenticated attackers to execute code and take over vulnerable servers. The post In-the-Wild Exploitation Expected for Critical TeamCity Flaw Allowing Server Takeover appeared first on SecurityWeek. This article is

In-the-Wild Exploitation Expected for Critical TeamCity Flaw Allowing Server Takeover Read More »

Faster Patching Pace Validates CISA’s KEV Catalog Initiative

Faster Patching Pace Validates CISA’s KEV Catalog Initiative 22/09/2023 at 15:17 By Ionut Arghire CISA says Known Exploited Vulnerabilities Catalog has helped federal agencies significantly accelerate their vulnerability remediation pace. The post Faster Patching Pace Validates CISA’s KEV Catalog Initiative appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Faster Patching Pace Validates CISA’s KEV Catalog Initiative Read More »

BIND Updates Patch Two High-Severity DoS Vulnerabilities

BIND Updates Patch Two High-Severity DoS Vulnerabilities 22/09/2023 at 15:17 By Ionut Arghire The latest BIND security updates include patches for two high-severity DoS vulnerabilities that can be exploited remotely. The post BIND Updates Patch Two High-Severity DoS Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

BIND Updates Patch Two High-Severity DoS Vulnerabilities Read More »

Apple Patches 3 Zero-Days Likely Exploited by Spyware Vendor to Hack iPhones

Apple Patches 3 Zero-Days Likely Exploited by Spyware Vendor to Hack iPhones 22/09/2023 at 13:31 By Eduard Kovacs Apple has patched 3 zero-day vulnerabilities that have likely been exploited by a spyware vendor to hack iPhones. The post Apple Patches 3 Zero-Days Likely Exploited by Spyware Vendor to Hack iPhones appeared first on SecurityWeek. This

Apple Patches 3 Zero-Days Likely Exploited by Spyware Vendor to Hack iPhones Read More »

Car Cybersecurity Study Shows Drop in Critical Vulnerabilities Over Past Decade

Car Cybersecurity Study Shows Drop in Critical Vulnerabilities Over Past Decade 21/09/2023 at 15:31 By Eduard Kovacs An automotive cybersecurity study shows that critical-risk vulnerabilities have decreased in the past decade. The post Car Cybersecurity Study Shows Drop in Critical Vulnerabilities Over Past Decade appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Car Cybersecurity Study Shows Drop in Critical Vulnerabilities Over Past Decade Read More »

GitLab Patches Critical Pipeline Execution Vulnerability

GitLab Patches Critical Pipeline Execution Vulnerability 20/09/2023 at 15:31 By Ionut Arghire GitLab has released security updates to address a critical-severity vulnerability allowing an attacker to run pipelines as another user. The post GitLab Patches Critical Pipeline Execution Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

GitLab Patches Critical Pipeline Execution Vulnerability Read More »

Atos Unify Vulnerabilities Could Allow Hackers to Backdoor Systems

Atos Unify Vulnerabilities Could Allow Hackers to Backdoor Systems 20/09/2023 at 15:31 By Eduard Kovacs Atos Unify product vulnerabilities could be exploited to cause disruption and reconfigure or backdoor the targeted system.  The post Atos Unify Vulnerabilities Could Allow Hackers to Backdoor Systems appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Atos Unify Vulnerabilities Could Allow Hackers to Backdoor Systems Read More »

Trend Micro Patches Exploited Zero-Day Vulnerability in Endpoint Security Products

Trend Micro Patches Exploited Zero-Day Vulnerability in Endpoint Security Products 19/09/2023 at 15:47 By Eduard Kovacs Trend Micro has patched CVE-2023-41179, an Apex One zero-day code execution vulnerability that has been exploited in attacks.  The post Trend Micro Patches Exploited Zero-Day Vulnerability in Endpoint Security Products appeared first on SecurityWeek. This article is an excerpt

Trend Micro Patches Exploited Zero-Day Vulnerability in Endpoint Security Products Read More »

Thousands of Juniper Appliances Vulnerable to New Exploit 

Thousands of Juniper Appliances Vulnerable to New Exploit  19/09/2023 at 15:47 By Ionut Arghire VulnCheck details a new fileless exploit targeting a recent Junos OS vulnerability that thousands of devices have not been patched against. The post Thousands of Juniper Appliances Vulnerable to New Exploit  appeared first on SecurityWeek. This article is an excerpt from

Thousands of Juniper Appliances Vulnerable to New Exploit  Read More »

Hacker Conversations: Casey Ellis, Hacker and Ringmaster at Bugcrowd

Hacker Conversations: Casey Ellis, Hacker and Ringmaster at Bugcrowd 19/09/2023 at 14:24 By Kevin Townsend SecurityWeek interviews Casey Ellis, founder, chairman and CTO at Bugcrowd, best known for operating bug bounty programs for organizations. The post Hacker Conversations: Casey Ellis, Hacker and Ringmaster at Bugcrowd appeared first on SecurityWeek. This article is an excerpt from

Hacker Conversations: Casey Ellis, Hacker and Ringmaster at Bugcrowd Read More »

Google Extends Chromebook Lifespan, Promises 10 Years of Automatic Updates

Google Extends Chromebook Lifespan, Promises 10 Years of Automatic Updates 18/09/2023 at 18:09 By Ionut Arghire Google Chromebooks released from 2021 and onwards will receive automatic updates, including security patches, for 10 years. The post Google Extends Chromebook Lifespan, Promises 10 Years of Automatic Updates appeared first on SecurityWeek. This article is an excerpt from

Google Extends Chromebook Lifespan, Promises 10 Years of Automatic Updates Read More »

Fortinet Patches High-Severity Vulnerabilities in FortiOS, FortiProxy, FortiWeb Products

Fortinet Patches High-Severity Vulnerabilities in FortiOS, FortiProxy, FortiWeb Products 18/09/2023 at 16:33 By Ionut Arghire Fortinet has released patches for a high-severity cross-site scripting vulnerability impacting its enterprise firewalls and switches. The post Fortinet Patches High-Severity Vulnerabilities in FortiOS, FortiProxy, FortiWeb Products appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

Fortinet Patches High-Severity Vulnerabilities in FortiOS, FortiProxy, FortiWeb Products Read More »

Kubernetes Vulnerability Leads to Remote Code Execution

Kubernetes Vulnerability Leads to Remote Code Execution 14/09/2023 at 16:50 By Ionut Arghire A high-severity vulnerability can be exploited to execute code remotely on any Windows endpoint within a Kubernetes cluster. The post Kubernetes Vulnerability Leads to Remote Code Execution appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Kubernetes Vulnerability Leads to Remote Code Execution Read More »

Azure HDInsight Flaws Allowed Data Access, Session Hijacking, Payload Delivery

Azure HDInsight Flaws Allowed Data Access, Session Hijacking, Payload Delivery 14/09/2023 at 16:18 By Ionut Arghire Orca Security details eight XSS vulnerabilities in Azure HDInsight that could lead to information leaks, session hijacking, and payload delivery. The post Azure HDInsight Flaws Allowed Data Access, Session Hijacking, Payload Delivery appeared first on SecurityWeek. This article is

Azure HDInsight Flaws Allowed Data Access, Session Hijacking, Payload Delivery Read More »

Scroll to Top