Vulnerabilities

High-Severity Memory Corruption Vulnerabilities Patched in Firefox, Chrome

High-Severity Memory Corruption Vulnerabilities Patched in Firefox, Chrome 30/08/2023 at 14:17 By Ionut Arghire Mozilla and Google have released stable updates for the Firefox and Chrome browsers to address several memory corruption vulnerabilities. The post High-Severity Memory Corruption Vulnerabilities Patched in Firefox, Chrome appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS […]

High-Severity Memory Corruption Vulnerabilities Patched in Firefox, Chrome Read More »

VMware Patches Major Security Flaws in Network Monitoring Product

VMware Patches Major Security Flaws in Network Monitoring Product 29/08/2023 at 23:02 By Ryan Naraine VWware patches critical flaws that allow hackers to bypass SSH authentication and gain access to the Aria Operations for Networks command line interface. The post VMware Patches Major Security Flaws in Network Monitoring Product appeared first on SecurityWeek. This article

VMware Patches Major Security Flaws in Network Monitoring Product Read More »

Cisco Patches Vulnerabilities Exposing Switches, Firewalls to DoS Attacks

Cisco Patches Vulnerabilities Exposing Switches, Firewalls to DoS Attacks 24/08/2023 at 18:31 By Ionut Arghire Cisco has released patches for three high-severity vulnerabilities in NX-OS and FXOS software that could lead to denial-of-service (DoS) conditions. The post Cisco Patches Vulnerabilities Exposing Switches, Firewalls to DoS Attacks appeared first on SecurityWeek. This article is an excerpt

Cisco Patches Vulnerabilities Exposing Switches, Firewalls to DoS Attacks Read More »

3,000 Openfire Servers Exposed to Attacks Targeting Recent Vulnerability

3,000 Openfire Servers Exposed to Attacks Targeting Recent Vulnerability 23/08/2023 at 17:19 By Ionut Arghire More than 3,000 Openfire servers are not patched against a recent vulnerability and are exposed to attacks employing a new exploit. The post 3,000 Openfire Servers Exposed to Attacks Targeting Recent Vulnerability appeared first on SecurityWeek. This article is an

3,000 Openfire Servers Exposed to Attacks Targeting Recent Vulnerability Read More »

First Weekly Chrome Security Update Patches High-Severity Vulnerabilities

First Weekly Chrome Security Update Patches High-Severity Vulnerabilities 23/08/2023 at 15:17 By Ionut Arghire Google has released the first weekly Chrome security update, which patches five memory safety vulnerabilities, including four rated ‘high severity’. The post First Weekly Chrome Security Update Patches High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

First Weekly Chrome Security Update Patches High-Severity Vulnerabilities Read More »

Exploitation of Ivanti Sentry Zero-Day Confirmed

Exploitation of Ivanti Sentry Zero-Day Confirmed 23/08/2023 at 12:17 By Eduard Kovacs While initially it was unclear if the Ivanti Sentry vulnerability CVE-2023-38035 has been exploited, the vendor and CISA have now confirmed it. The post Exploitation of Ivanti Sentry Zero-Day Confirmed appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

Exploitation of Ivanti Sentry Zero-Day Confirmed Read More »

CISA Warns of Another Exploited Adobe ColdFusion Vulnerability

CISA Warns of Another Exploited Adobe ColdFusion Vulnerability 22/08/2023 at 13:47 By Eduard Kovacs CISA warns that CVE-2023-26359, an Adobe ColdFusion vulnerability patched in March, has been exploited in the wild. The post CISA Warns of Another Exploited Adobe ColdFusion Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

CISA Warns of Another Exploited Adobe ColdFusion Vulnerability Read More »

Ivanti Ships Urgent Patch for API Authentication Bypass Vulnerability

Ivanti Ships Urgent Patch for API Authentication Bypass Vulnerability 21/08/2023 at 22:31 By Ryan Naraine A critical-severity vulnerability in the Ivanti Sentry (formerly MobileIron Sentry) product exposes sensitive API data and configurations. The post Ivanti Ships Urgent Patch for API Authentication Bypass Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Ivanti Ships Urgent Patch for API Authentication Bypass Vulnerability Read More »

Flaws in Juniper Switches and Firewalls Can Be Chained for Remote Code Execution

Flaws in Juniper Switches and Firewalls Can Be Chained for Remote Code Execution 21/08/2023 at 14:01 By Ionut Arghire Juniper Networks has released Junos OS updates to address J-Web vulnerabilities that can be combined to achieve unauthenticated, remote code execution. The post Flaws in Juniper Switches and Firewalls Can Be Chained for Remote Code Execution

Flaws in Juniper Switches and Firewalls Can Be Chained for Remote Code Execution Read More »

In Other News: US Hacking China, Unfixed PowerShell Gallery Flaws, Free Train Tickets

In Other News: US Hacking China, Unfixed PowerShell Gallery Flaws, Free Train Tickets 18/08/2023 at 18:17 By SecurityWeek News Weekly cybersecurity news roundup that provides a summary of noteworthy stories that might have slipped under the radar for the week of August 14, 2023. The post In Other News: US Hacking China, Unfixed PowerShell Gallery

In Other News: US Hacking China, Unfixed PowerShell Gallery Flaws, Free Train Tickets Read More »

Jenkins Patches High-Severity Vulnerabilities in Multiple Plugins

Jenkins Patches High-Severity Vulnerabilities in Multiple Plugins 18/08/2023 at 16:46 By Ionut Arghire Jenkins has announced patches for high and medium-severity vulnerabilities impacting several of the open source automation tool’s plugins. The post Jenkins Patches High-Severity Vulnerabilities in Multiple Plugins appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Jenkins Patches High-Severity Vulnerabilities in Multiple Plugins Read More »

Companies Respond to ‘Downfall’ Intel CPU Vulnerability 

Companies Respond to ‘Downfall’ Intel CPU Vulnerability  18/08/2023 at 15:49 By Eduard Kovacs Several major companies have published advisories in response to the Downfall vulnerability affecting Intel CPUs. The post Companies Respond to ‘Downfall’ Intel CPU Vulnerability  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Companies Respond to ‘Downfall’ Intel CPU Vulnerability  Read More »

Google Brings AI Magic to Fuzz Testing With Eye-Opening Results

Google Brings AI Magic to Fuzz Testing With Eye-Opening Results 17/08/2023 at 20:46 By Ryan Naraine Google sprinkles magic of generative-AI into its open source fuzz testing infrastructure and finds immediate success with code coverage. The post Google Brings AI Magic to Fuzz Testing With Eye-Opening Results appeared first on SecurityWeek. This article is an

Google Brings AI Magic to Fuzz Testing With Eye-Opening Results Read More »

Cisco Patches High-Severity Vulnerabilities in Enterprise Applications

Cisco Patches High-Severity Vulnerabilities in Enterprise Applications 17/08/2023 at 19:02 By Ionut Arghire Cisco has patched high-severity vulnerabilities in enterprise applications that could lead to privilege escalation, SQL injection, and denial-of-service. The post Cisco Patches High-Severity Vulnerabilities in Enterprise Applications appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Cisco Patches High-Severity Vulnerabilities in Enterprise Applications Read More »

Exploitation of Citrix ShareFile Vulnerability Spikes as CISA Issues Warning 

Exploitation of Citrix ShareFile Vulnerability Spikes as CISA Issues Warning  17/08/2023 at 12:18 By Eduard Kovacs Exploitation of a Citrix ShareFile vulnerability tracked as CVE-2023-24489 has spiked as CISA added it to its ‘must patch’ catalog. The post Exploitation of Citrix ShareFile Vulnerability Spikes as CISA Issues Warning  appeared first on SecurityWeek. This article is

Exploitation of Citrix ShareFile Vulnerability Spikes as CISA Issues Warning  Read More »

Ivanti Patches Critical Vulnerability in Avalanche Enterprise MDM Solution

Ivanti Patches Critical Vulnerability in Avalanche Enterprise MDM Solution 16/08/2023 at 16:45 By Ionut Arghire Ivanti has patched critical- and high-severity vulnerabilities with the latest release of Avalanche, its enterprise mobile device management solution. The post Ivanti Patches Critical Vulnerability in Avalanche Enterprise MDM Solution appeared first on SecurityWeek. This article is an excerpt from

Ivanti Patches Critical Vulnerability in Avalanche Enterprise MDM Solution Read More »

2,000 Citrix NetScaler Instances Backdoored via Recent Vulnerability

2,000 Citrix NetScaler Instances Backdoored via Recent Vulnerability 15/08/2023 at 19:47 By Ionut Arghire A threat actor has exploited a recent Citrix vulnerability (CVE-2023-3519) to infect roughly 2,000 NetScaler instances with a backdoor. The post 2,000 Citrix NetScaler Instances Backdoored via Recent Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

2,000 Citrix NetScaler Instances Backdoored via Recent Vulnerability Read More »

Power Management Product Flaws Can Expose Data Centers to Damaging Attacks, Spying

Power Management Product Flaws Can Expose Data Centers to Damaging Attacks, Spying 14/08/2023 at 16:16 By Eduard Kovacs Vulnerabilities in CyberPower and Dataprobe power management products could be exploited in data center attacks, including to cause damage and for spying. The post Power Management Product Flaws Can Expose Data Centers to Damaging Attacks, Spying appeared

Power Management Product Flaws Can Expose Data Centers to Damaging Attacks, Spying Read More »

Scroll to Top