Vulnerabilities

Evidence Suggests Ransomware Group Knew About MOVEit Zero-Day Since 2021

Evidence Suggests Ransomware Group Knew About MOVEit Zero-Day Since 2021 09/06/2023 at 15:46 By Eduard Kovacs Evidence suggests that the Cl0p ransomware group has known about and conducted tests with the recently patched MOVEit zero-day since mid-2021. The post Evidence Suggests Ransomware Group Knew About MOVEit Zero-Day Since 2021 appeared first on SecurityWeek. This article […]

Evidence Suggests Ransomware Group Knew About MOVEit Zero-Day Since 2021 Read More »

Vulnerabilities in Honda eCommerce Platform Exposed Customer, Dealer Data

Vulnerabilities in Honda eCommerce Platform Exposed Customer, Dealer Data 08/06/2023 at 18:48 By Eduard Kovacs Vulnerabilities found by a researcher in a Honda ecommerce platform used for equipment sales exposed customer and dealer information. The post Vulnerabilities in Honda eCommerce Platform Exposed Customer, Dealer Data appeared first on SecurityWeek. This article is an excerpt from

Vulnerabilities in Honda eCommerce Platform Exposed Customer, Dealer Data Read More »

Cisco Patches Critical Vulnerability in Enterprise Collaboration Solutions

Cisco Patches Critical Vulnerability in Enterprise Collaboration Solutions 08/06/2023 at 14:17 By Ionut Arghire Cisco releases fixes for a critical-severity vulnerability in Expressway series and TelePresence Video Communication Server (VCS). The post Cisco Patches Critical Vulnerability in Enterprise Collaboration Solutions appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Cisco Patches Critical Vulnerability in Enterprise Collaboration Solutions Read More »

VMware Plugs Critical Flaws in Network Monitoring Product

VMware Plugs Critical Flaws in Network Monitoring Product 07/06/2023 at 19:02 By Ryan Naraine VMware ships urgent patches to cover security defects that expose businesses to remote code execution attacks. The post VMware Plugs Critical Flaws in Network Monitoring Product appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

VMware Plugs Critical Flaws in Network Monitoring Product Read More »

KeePass Update Patches Vulnerability Exposing Master Password

KeePass Update Patches Vulnerability Exposing Master Password 06/06/2023 at 17:17 By Ionut Arghire KeePass 2.54 patches a vulnerability allowing attackers to retrieve the cleartext master password from a memory dump. The post KeePass Update Patches Vulnerability Exposing Master Password appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

KeePass Update Patches Vulnerability Exposing Master Password Read More »

Google Patches Third Chrome Zero-Day of 2023

Google Patches Third Chrome Zero-Day of 2023 06/06/2023 at 12:03 By Eduard Kovacs Google has released a Chrome 114 security update that patches CVE-2023-3079, the third zero-day vulnerability patched in the browser in 2023. The post Google Patches Third Chrome Zero-Day of 2023 appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Google Patches Third Chrome Zero-Day of 2023 Read More »

Zyxel Urges Customers to Patch Firewalls Against Exploited Vulnerabilities

Zyxel Urges Customers to Patch Firewalls Against Exploited Vulnerabilities 05/06/2023 at 16:47 By Ionut Arghire Zyxel urges customers to update ATP, USG Flex, VPN, and ZyWALL/USG firewalls to prevent exploitation of recent vulnerabilities. The post Zyxel Urges Customers to Patch Firewalls Against Exploited Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Zyxel Urges Customers to Patch Firewalls Against Exploited Vulnerabilities Read More »

SBOMs – Software Supply Chain Security’s Future or Fantasy?

SBOMs – Software Supply Chain Security’s Future or Fantasy? 05/06/2023 at 14:39 By Kevin Townsend If after eighteen months, meaningful use of SBOMs is unachievable, we need to ask what needs to be done to fulfill Biden’s executive order. The post SBOMs – Software Supply Chain Security’s Future or Fantasy? appeared first on SecurityWeek. This

SBOMs – Software Supply Chain Security’s Future or Fantasy? Read More »

Gigabyte Rolls Out BIOS Updates to Remove Backdoor From Motherboards

Gigabyte Rolls Out BIOS Updates to Remove Backdoor From Motherboards 05/06/2023 at 14:39 By Ionut Arghire Gigabyte has announced BIOS updates that remove a recently identified backdoor feature in hundreds of its motherboards. The post Gigabyte Rolls Out BIOS Updates to Remove Backdoor From Motherboards appeared first on SecurityWeek. This article is an excerpt from

Gigabyte Rolls Out BIOS Updates to Remove Backdoor From Motherboards Read More »

In Other News: Government Use of Spyware, New Industrial Security Tools, Japan Router Hack 

In Other News: Government Use of Spyware, New Industrial Security Tools, Japan Router Hack  03/06/2023 at 14:33 By Eduard Kovacs Cybersecurity news that you may have missed this week: the spyware used by various governments, new vulnerabilities, industrial security products, and Linux router attacks. The post In Other News: Government Use of Spyware, New Industrial

In Other News: Government Use of Spyware, New Industrial Security Tools, Japan Router Hack  Read More »

High-Severity Vulnerabilities Patched in Splunk Enterprise

High-Severity Vulnerabilities Patched in Splunk Enterprise 02/06/2023 at 16:54 By Ionut Arghire Splunk has resolved multiple high-severity vulnerabilities in Splunk Enterprise, including bugs in third-party packages used by the product. The post High-Severity Vulnerabilities Patched in Splunk Enterprise appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

High-Severity Vulnerabilities Patched in Splunk Enterprise Read More »

Zero-Day in MOVEit File Transfer Software Exploited to Steal Data From Organizations

Zero-Day in MOVEit File Transfer Software Exploited to Steal Data From Organizations 02/06/2023 at 12:41 By Eduard Kovacs A zero-day vulnerability in Progress Software’s MOVEit Transfer product has been exploited to hack organizations and steal their data. The post Zero-Day in MOVEit File Transfer Software Exploited to Steal Data From Organizations appeared first on SecurityWeek.

Zero-Day in MOVEit File Transfer Software Exploited to Steal Data From Organizations Read More »

Google Temporarily Offering $180,000 for Full Chain Chrome Exploit

Google Temporarily Offering $180,000 for Full Chain Chrome Exploit 02/06/2023 at 07:42 By Ionut Arghire Google is offering a bug bounty reward of up to $180,000 for a full chain exploit leading to a sandbox escape in the Chrome browser. The post Google Temporarily Offering $180,000 for Full Chain Chrome Exploit appeared first on SecurityWeek.

Google Temporarily Offering $180,000 for Full Chain Chrome Exploit Read More »

Moxa Patches MXsecurity Vulnerabilities That Could Be Exploited in OT Attacks

Moxa Patches MXsecurity Vulnerabilities That Could Be Exploited in OT Attacks 01/06/2023 at 15:19 By Eduard Kovacs Critical authentication bypass and high-severity command injection vulnerabilities have been patched in Moxa’s MXsecurity product. The post Moxa Patches MXsecurity Vulnerabilities That Could Be Exploited in OT Attacks appeared first on SecurityWeek. This article is an excerpt from

Moxa Patches MXsecurity Vulnerabilities That Could Be Exploited in OT Attacks Read More »

Adobe Inviting Researchers to Private Bug Bounty Program

Adobe Inviting Researchers to Private Bug Bounty Program 01/06/2023 at 13:47 By Ionut Arghire Adobe is inviting security researchers to join its private bug bounty program on the HackerOne platform. The post Adobe Inviting Researchers to Private Bug Bounty Program appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Adobe Inviting Researchers to Private Bug Bounty Program Read More »

Critical Vulnerabilities Found in Faronics Education Software

Critical Vulnerabilities Found in Faronics Education Software 01/06/2023 at 12:35 By Ionut Arghire Faronics patches critical-severity remote code execution (RCE) vulnerabilities in the Insight education software. The post Critical Vulnerabilities Found in Faronics Education Software appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Critical Vulnerabilities Found in Faronics Education Software Read More »

SharpPanda APT Campaign Expands its Arsenal Targeting G20 Nations

SharpPanda APT Campaign Expands its Arsenal Targeting G20 Nations 01/06/2023 at 08:36 By cybleinc Cyble analyzes SharpPanda, a highly sophisticated APT group utilizing spear-phishing tactics to launch cyberattacks on G20 Nation officials. The post SharpPanda APT Campaign Expands its Arsenal Targeting G20 Nations appeared first on Cyble. This article is an excerpt from Cyble View

SharpPanda APT Campaign Expands its Arsenal Targeting G20 Nations Read More »

Barracuda Zero-Day Exploited to Deliver Malware for Months Before Discovery

Barracuda Zero-Day Exploited to Deliver Malware for Months Before Discovery 31/05/2023 at 12:49 By Eduard Kovacs The recently discovered Barracuda zero-day vulnerability CVE-2023-2868 has been exploited to deliver malware and steal data since at least October 2022. The post Barracuda Zero-Day Exploited to Deliver Malware for Months Before Discovery appeared first on SecurityWeek. This article

Barracuda Zero-Day Exploited to Deliver Malware for Months Before Discovery Read More »

Millions of WordPress Sites Patched Against Critical Jetpack Vulnerability

Millions of WordPress Sites Patched Against Critical Jetpack Vulnerability 31/05/2023 at 12:49 By Ionut Arghire A decade-old critical vulnerability in Jetpack was force-patched on five million WordPress sites over the past few days. The post Millions of WordPress Sites Patched Against Critical Jetpack Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Millions of WordPress Sites Patched Against Critical Jetpack Vulnerability Read More »

Scroll to Top