Category vulnerabilities

Microsoft Issues October 2023 Updates Addressing 103 Vulnerabilities, Including 2 Currently Exploited Threats

In its October 2023 Patch Tuesday update, Microsoft has addressed a total of 103 vulnerabilities across its software platforms, including two critical zero-day vulnerabilities actively exploited in the wild. This update highlights the ongoing importance of patch management in maintaining cybersecurity defenses. Among the identified vulnerabilities, 13 are categorized as…

Read MoreMicrosoft Issues October 2023 Updates Addressing 103 Vulnerabilities, Including 2 Currently Exploited Threats

Critical Security Vulnerabilities Found in Curl Library – Latest Patches Available

Image Source: JFrog Security Research Recent patches have been issued to address two significant vulnerabilities in the Curl data transfer library. These flaws pose a considerable risk, especially one that could potentially lead to remote code execution, drawing the attention of cybersecurity professionals and business owners alike. The vulnerabilities include…

Read MoreCritical Security Vulnerabilities Found in Curl Library – Latest Patches Available

Signal Disproves Zero-Day Vulnerability Claims, Reveals No Supporting Evidence

Encrypted messaging platform Signal has responded to widespread claims concerning a potential zero-day vulnerability, asserting that no evidence corroborates the reports. Following thorough internal investigation, the company stated it has found no indications that such a flaw exists. Signal emphasized that additional information has not been communicated through official channels,…

Read MoreSignal Disproves Zero-Day Vulnerability Claims, Reveals No Supporting Evidence

Pro-Russian Hackers Target Recent WinRAR Vulnerability in Latest Attack Campaign

Recent reports indicate that pro-Russian hacking groups are exploiting a security vulnerability in WinRAR, a widely used archiving software. This vulnerability has been employed in a phishing campaign aimed at credential theft from compromised systems, raising significant security concerns among business owners. The vulnerability in question, known as CVE-2023-38831, affects…

Read MorePro-Russian Hackers Target Recent WinRAR Vulnerability in Latest Attack Campaign

Alert: Cisco Zero-Day Vulnerability Being Actively Exploited in the Wild

Cisco Systems has recently disclosed a severe, unpatched vulnerability affecting its IOS XE software, which is currently under active exploitation by threat actors. The zero-day flaw, identified as CVE-2023-20198, holds a critical severity rating of 10.0 on the Common Vulnerability Scoring System (CVSS). This vulnerability specifically impacts enterprise networking hardware…

Read MoreAlert: Cisco Zero-Day Vulnerability Being Actively Exploited in the Wild

Critical Vulnerabilities Discovered in Open Source CasaOS Cloud Software

Recently identified vulnerabilities within the open-source CasaOS personal cloud software could pose significant risks to users. Attackers can exploit these flaws to execute arbitrary code, compromising vulnerable systems entirely. Tracked as CVE-2023-37265 and CVE-2023-37266, these issues have been rated with a CVSS score of 9.8, suggesting a high level of…

Read MoreCritical Vulnerabilities Discovered in Open Source CasaOS Cloud Software

New Vulnerability Discovered: Admin Takeover in Synology’s DiskStation Manager

A medium-severity vulnerability has emerged within Synology’s DiskStation Manager (DSM), posing significant risks to administrative account security. This flaw enables potential attackers to reverse-engineer an administrator’s password, potentially leading to a complete account takeover. According to Sharon Brizinov from Claroty, under specific circumstances, an assailant could leverage the flaw to…

Read MoreNew Vulnerability Discovered: Admin Takeover in Synology’s DiskStation Manager

Google TAG Identifies State-Sponsored Threat Actors Exploiting WinRAR Vulnerability

Recent investigations have unveiled that state-sponsored threat actors from Russia and China are exploiting a known security vulnerability in the WinRAR archiver software for Windows, as part of their cyber operations. These attacks indicate a pronounced shift towards utilizing established vulnerabilities to bolster operational success. The vulnerability, referenced as CVE-2023-38831,…

Read MoreGoogle TAG Identifies State-Sponsored Threat Actors Exploiting WinRAR Vulnerability

Microsoft Alerts on North Korean Cyberattacks Targeting JetBrains TeamCity Vulnerability

Cybersecurity experts have reported that North Korean threat actors are leveraging a critical vulnerability in JetBrains TeamCity, specifically CVE-2023-42793, which carries a severe CVSS score of 9.8. This exploitation allows attackers to breach unprotected servers, with campaigns attributed to two distinct groups: Diamond Sleet, also known as Labyrinth Chollima, and…

Read MoreMicrosoft Alerts on North Korean Cyberattacks Targeting JetBrains TeamCity Vulnerability