Tag Cisco

More than 70,000 Memcached Servers Remain Exposed to Remote Hacking Threats

Last year, Cisco’s Talos intelligence unit identified three critical remote code execution (RCE) vulnerabilities within Memcached, a widely-used open-source distributed caching system. This discovery raised significant alarm as it impacted major platforms, including Facebook, Twitter, YouTube, and Reddit, putting them at risk of unauthorized access. Memcached is instrumental for dynamic…

Read MoreMore than 70,000 Memcached Servers Remain Exposed to Remote Hacking Threats

Vulnerability Allows Remote Exploitation, Endangering Millions of Internet-Connected Devices

A significant vulnerability has been identified in a widely used open-source software library, posing a substantial risk to millions of Internet of Things (IoT) devices. Known as CVE-2017-9765, this flaw was uncovered by security experts at the IoT-focused firm Senrio and affects the gSOAP toolkit, which is instrumental in developing…

Read MoreVulnerability Allows Remote Exploitation, Endangering Millions of Internet-Connected Devices

MS Office Built-in Feature Enables Malware Execution Without the Need for Macros

With the rapid evolution of cybercrime, traditional defenses are increasingly being overwhelmed by attacks that exploit commonly used system tools and protocols. A recent investigation by Cisco’s Talos threat research group uncovered a campaign utilizing malware-laden Microsoft Word documents capable of executing code without requiring Macro permissions or corrupting memory.…

Read MoreMS Office Built-in Feature Enables Malware Execution Without the Need for Macros

ROBOT Attack: The Reemergence of the 19-Year-Old Bleichenbacher Attack on Encrypted Websites

A recently re-emerged vulnerability, known as the ROBOT (Return of Bleichenbacher’s Oracle Attack), has affected the RSA implementations from at least eight vendors, including prominent names like F5, Citrix, and Cisco. This weakness, which has remained present for nearly two decades, enables man-in-the-middle attackers to gain unauthorized access to encrypted…

Read MoreROBOT Attack: The Reemergence of the 19-Year-Old Bleichenbacher Attack on Encrypted Websites

Update Your Firefox Browser to Address a Critical Remote Exploit Vulnerability

In a significant security update, Mozilla has announced a critical patch for its Firefox web browser to address a serious vulnerability. This flaw could allow remote attackers to execute code on machines running affected versions of the browser, potentially compromising user data and system integrity. This update follows closely on…

Read MoreUpdate Your Firefox Browser to Address a Critical Remote Exploit Vulnerability

Cisco Releases Security Updates to Address 32 Vulnerabilities in Its Products

Cisco Addresses 32 Security Vulnerabilities in Latest Patch Release Cisco has announced the release of thirty security patch advisories aimed at addressing a total of 32 vulnerabilities across its product line. Among these, three vulnerabilities have been classified as critical, one of which pertains to a recently disclosed remote code…

Read MoreCisco Releases Security Updates to Address 32 Vulnerabilities in Its Products

Urgent: Recent Oracle WebLogic Vulnerability Exploited — Update Immediately

Oracle Deploys Critical WebLogic Server Update Amid Exploitation Threats Oracle has issued an urgent software update to address a newly identified critical vulnerability in its WebLogic Server, which is a Java-based multi-tier enterprise application server utilized by businesses to efficiently roll out products and services across both cloud and traditional…

Read MoreUrgent: Recent Oracle WebLogic Vulnerability Exploited — Update Immediately

Hackers Exploit CVE-2025-55182 to Compromise 766 Next.js Hosts and Steal Credentials

Large-Scale Credential Harvesting Operation Targets Vulnerable Next.js Applications A significant credential harvesting operation has been detected exploiting the React2Shell vulnerability, marking a serious threat to numerous organizations. This operation aims to steal sensitive information, including database credentials, SSH private keys, AWS secrets, shell command histories, Stripe API keys, and GitHub…

Read MoreHackers Exploit CVE-2025-55182 to Compromise 766 Next.js Hosts and Steal Credentials