Vulnerabilities

SquareX Launches Bug Bounty Program for Browser Security Product

SquareX Launches Bug Bounty Program for Browser Security Product 15/06/2023 at 18:28 By Ionut Arghire Cybersecurity startup SquareX launches a temporary bug bounty program for its cloud-based browser security solution. The post SquareX Launches Bug Bounty Program for Browser Security Product appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View […]

SquareX Launches Bug Bounty Program for Browser Security Product Read More »

Hundreds of Thousands of eCommerce Sites Impacted by Critical Plugin Vulnerability

Hundreds of Thousands of eCommerce Sites Impacted by Critical Plugin Vulnerability 14/06/2023 at 16:35 By Ionut Arghire Hundreds of thousands of ecommerce sites are impacted by a critical vulnerability in the WooCommerce Stripe Payment Gateway plugin. The post Hundreds of Thousands of eCommerce Sites Impacted by Critical Plugin Vulnerability appeared first on SecurityWeek. This article

Hundreds of Thousands of eCommerce Sites Impacted by Critical Plugin Vulnerability Read More »

Chrome 114 Update Patches Critical Vulnerability

Chrome 114 Update Patches Critical Vulnerability 14/06/2023 at 15:31 By Ionut Arghire Google has released a Chrome 114 security update to address five vulnerabilities, including a critical-severity bug in Autofill payments. The post Chrome 114 Update Patches Critical Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Chrome 114 Update Patches Critical Vulnerability Read More »

SAP Patches High-Severity Vulnerabilities With June 2023 Security Updates

SAP Patches High-Severity Vulnerabilities With June 2023 Security Updates 14/06/2023 at 14:34 By Ionut Arghire SAP has released eight new security notes on June 2023 Security Patch Day, including two that address high-severity vulnerabilities. The post SAP Patches High-Severity Vulnerabilities With June 2023 Security Updates appeared first on SecurityWeek. This article is an excerpt from

SAP Patches High-Severity Vulnerabilities With June 2023 Security Updates Read More »

Chinese Cyberspies Caught Exploiting VMware ESXi Zero-Day

Chinese Cyberspies Caught Exploiting VMware ESXi Zero-Day 13/06/2023 at 21:19 By Ionut Arghire Mandiant has observed a Chinese cyberespionage group exploiting a VMware ESXi zero-day vulnerability for privilege escalation. The post Chinese Cyberspies Caught Exploiting VMware ESXi Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Chinese Cyberspies Caught Exploiting VMware ESXi Zero-Day Read More »

Microsoft Patches Critical Windows Vulns, Warn of Code Execution Risks

Microsoft Patches Critical Windows Vulns, Warn of Code Execution Risks 13/06/2023 at 21:19 By Ryan Naraine Patch Tuesday: Microsoft ships updates to over at least 70 documented vulnerabilities affecting the Windows ecosystem. The post Microsoft Patches Critical Windows Vulns, Warn of Code Execution Risks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Microsoft Patches Critical Windows Vulns, Warn of Code Execution Risks Read More »

Patch Tuesday: Critical Flaws in Adobe Commerce Software

Patch Tuesday: Critical Flaws in Adobe Commerce Software 13/06/2023 at 19:21 By Ryan Naraine Adobe ships urgent fixes for at least a dozen flaws that expose Adobe Commerce users to code execution attacks. The post Patch Tuesday: Critical Flaws in Adobe Commerce Software appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Patch Tuesday: Critical Flaws in Adobe Commerce Software Read More »

Fortinet Warns Customers of Possible Zero-Day Exploited in Limited Attacks

Fortinet Warns Customers of Possible Zero-Day Exploited in Limited Attacks 13/06/2023 at 11:50 By Eduard Kovacs Fortinet has warned customers that the critical CVE-2023-27997 vulnerability that was patched recently could be a zero-day exploited in limited attacks. The post Fortinet Warns Customers of Possible Zero-Day Exploited in Limited Attacks appeared first on SecurityWeek. This article

Fortinet Warns Customers of Possible Zero-Day Exploited in Limited Attacks Read More »

Software Supply Chain: The Golden Container Ship

Software Supply Chain: The Golden Container Ship 12/06/2023 at 15:18 By Matt Honea By having a golden image you will put a process in place that allows you to quickly take action when a vulnerability is found within your organization. The post Software Supply Chain: The Golden Container Ship appeared first on SecurityWeek. This article

Software Supply Chain: The Golden Container Ship Read More »

New MOVEit Vulnerabilities Found as More Zero-Day Attack Victims Come Forward

New MOVEit Vulnerabilities Found as More Zero-Day Attack Victims Come Forward 12/06/2023 at 13:34 By Eduard Kovacs Researchers discover new MOVEit vulnerabilities related to the zero-day, just as more organizations hit by the attack are coming forward. The post New MOVEit Vulnerabilities Found as More Zero-Day Attack Victims Come Forward appeared first on SecurityWeek. This

New MOVEit Vulnerabilities Found as More Zero-Day Attack Victims Come Forward Read More »

Fortinet Patches Critical FortiGate SSL VPN Vulnerability

Fortinet Patches Critical FortiGate SSL VPN Vulnerability 12/06/2023 at 12:40 By Eduard Kovacs Fortinet has patched CVE-2023-27997, a critical FortiGate SSL VPN vulnerability that can be exploited for unauthenticated remote code execution. The post Fortinet Patches Critical FortiGate SSL VPN Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

Fortinet Patches Critical FortiGate SSL VPN Vulnerability Read More »

Evidence Suggests Ransomware Group Knew About MOVEit Zero-Day Since 2021

Evidence Suggests Ransomware Group Knew About MOVEit Zero-Day Since 2021 09/06/2023 at 15:46 By Eduard Kovacs Evidence suggests that the Cl0p ransomware group has known about and conducted tests with the recently patched MOVEit zero-day since mid-2021. The post Evidence Suggests Ransomware Group Knew About MOVEit Zero-Day Since 2021 appeared first on SecurityWeek. This article

Evidence Suggests Ransomware Group Knew About MOVEit Zero-Day Since 2021 Read More »

Vulnerabilities in Honda eCommerce Platform Exposed Customer, Dealer Data

Vulnerabilities in Honda eCommerce Platform Exposed Customer, Dealer Data 08/06/2023 at 18:48 By Eduard Kovacs Vulnerabilities found by a researcher in a Honda ecommerce platform used for equipment sales exposed customer and dealer information. The post Vulnerabilities in Honda eCommerce Platform Exposed Customer, Dealer Data appeared first on SecurityWeek. This article is an excerpt from

Vulnerabilities in Honda eCommerce Platform Exposed Customer, Dealer Data Read More »

Cisco Patches Critical Vulnerability in Enterprise Collaboration Solutions

Cisco Patches Critical Vulnerability in Enterprise Collaboration Solutions 08/06/2023 at 14:17 By Ionut Arghire Cisco releases fixes for a critical-severity vulnerability in Expressway series and TelePresence Video Communication Server (VCS). The post Cisco Patches Critical Vulnerability in Enterprise Collaboration Solutions appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Cisco Patches Critical Vulnerability in Enterprise Collaboration Solutions Read More »

VMware Plugs Critical Flaws in Network Monitoring Product

VMware Plugs Critical Flaws in Network Monitoring Product 07/06/2023 at 19:02 By Ryan Naraine VMware ships urgent patches to cover security defects that expose businesses to remote code execution attacks. The post VMware Plugs Critical Flaws in Network Monitoring Product appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

VMware Plugs Critical Flaws in Network Monitoring Product Read More »

KeePass Update Patches Vulnerability Exposing Master Password

KeePass Update Patches Vulnerability Exposing Master Password 06/06/2023 at 17:17 By Ionut Arghire KeePass 2.54 patches a vulnerability allowing attackers to retrieve the cleartext master password from a memory dump. The post KeePass Update Patches Vulnerability Exposing Master Password appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

KeePass Update Patches Vulnerability Exposing Master Password Read More »

Google Patches Third Chrome Zero-Day of 2023

Google Patches Third Chrome Zero-Day of 2023 06/06/2023 at 12:03 By Eduard Kovacs Google has released a Chrome 114 security update that patches CVE-2023-3079, the third zero-day vulnerability patched in the browser in 2023. The post Google Patches Third Chrome Zero-Day of 2023 appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Google Patches Third Chrome Zero-Day of 2023 Read More »

Zyxel Urges Customers to Patch Firewalls Against Exploited Vulnerabilities

Zyxel Urges Customers to Patch Firewalls Against Exploited Vulnerabilities 05/06/2023 at 16:47 By Ionut Arghire Zyxel urges customers to update ATP, USG Flex, VPN, and ZyWALL/USG firewalls to prevent exploitation of recent vulnerabilities. The post Zyxel Urges Customers to Patch Firewalls Against Exploited Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Zyxel Urges Customers to Patch Firewalls Against Exploited Vulnerabilities Read More »

SBOMs – Software Supply Chain Security’s Future or Fantasy?

SBOMs – Software Supply Chain Security’s Future or Fantasy? 05/06/2023 at 14:39 By Kevin Townsend If after eighteen months, meaningful use of SBOMs is unachievable, we need to ask what needs to be done to fulfill Biden’s executive order. The post SBOMs – Software Supply Chain Security’s Future or Fantasy? appeared first on SecurityWeek. This

SBOMs – Software Supply Chain Security’s Future or Fantasy? Read More »

Gigabyte Rolls Out BIOS Updates to Remove Backdoor From Motherboards

Gigabyte Rolls Out BIOS Updates to Remove Backdoor From Motherboards 05/06/2023 at 14:39 By Ionut Arghire Gigabyte has announced BIOS updates that remove a recently identified backdoor feature in hundreds of its motherboards. The post Gigabyte Rolls Out BIOS Updates to Remove Backdoor From Motherboards appeared first on SecurityWeek. This article is an excerpt from

Gigabyte Rolls Out BIOS Updates to Remove Backdoor From Motherboards Read More »

Scroll to Top