Category vulnerabilities

Cisco Releases Critical Update to Address Authentication Bypass Vulnerability in BroadWorks Platform

Cisco has issued critical security patches addressing several vulnerabilities, including one particularly severe flaw, potentially allowing threat actors to gain unauthorized control of affected systems or precipitate denial-of-service (DoS) conditions. The most critical vulnerability identified as CVE-2023-20238 has received a maximum CVSS severity rating of 10.0, relating to an authentication…

Read MoreCisco Releases Critical Update to Address Authentication Bypass Vulnerability in BroadWorks Platform

Apple Hurries to Fix Zero-Day Vulnerabilities Targeted by Pegasus Spyware on iPhones

Apple Issues Urgent Security Patches for Exploited Zero-Day Vulnerabilities On Thursday, Apple announced the immediate release of emergency security updates for iOS, iPadOS, macOS, and watchOS to rectify two critical zero-day vulnerabilities. These flaws had already been leveraged in attacks to deploy the notorious Pegasus spyware developed by the NSO…

Read MoreApple Hurries to Fix Zero-Day Vulnerabilities Targeted by Pegasus Spyware on iPhones

Critical GitHub Vulnerability Puts Over 4,000 Repositories at Risk of Repojacking Attack

New Vulnerability Exposes Thousands of GitHub Repositories to Repojacking Attacks A recently disclosed vulnerability in GitHub has raised concerns about the security of thousands of repositories, putting them at risk for repojacking attacks. According to findings from Checkmarx security researcher Elad Rapoport, this flaw allows attackers to exploit a race…

Read MoreCritical GitHub Vulnerability Puts Over 4,000 Repositories at Risk of Repojacking Attack

Mozilla Urgently Addresses Critical Zero-Day Vulnerability in WebP for Firefox and Thunderbird

On Tuesday, Mozilla released urgent security updates addressing a critical zero-day vulnerability affecting both Firefox and Thunderbird, identified as CVE-2023-4863. This flaw has been actively exploited in the wild, prompting the need for immediate remediation. The vulnerability pertains to a heap buffer overflow in the WebP image format, which could…

Read MoreMozilla Urgently Addresses Critical Zero-Day Vulnerability in WebP for Firefox and Thunderbird

Update Adobe Acrobat and Reader to Address Actively Exploited Vulnerability

Adobe has issued a critical security patch as part of its September 2023 Patch Tuesday update, addressing a severe vulnerability in Acrobat and Reader software. The flaw, identified as CVE-2023-26369, poses a substantial risk by allowing attackers to execute malicious code on vulnerable systems, specifically those running on Windows and…

Read MoreUpdate Adobe Acrobat and Reader to Address Actively Exploited Vulnerability

Microsoft Issues Patch for Two Actively Exploited Zero-Day Vulnerabilities

Microsoft has issued an update addressing 59 vulnerabilities across its suite of products, including two critical zero-day vulnerabilities that have already been exploited by malicious actors. This release highlights the ongoing threat landscape, with the tech giant emphasizing the risks posed by active exploitation of these flaws. Among the 59…

Read MoreMicrosoft Issues Patch for Two Actively Exploited Zero-Day Vulnerabilities

N-Able’s Take Control Agent Vulnerability Poses Privilege Escalation Risk for Windows Systems

In a significant cybersecurity concern, a high-severity vulnerability has been revealed in N-Able’s Take Control Agent, a product utilized for remote management. This flaw, identified as CVE-2023-27470 and assigned a CVSS score of 8.8, could be exploited by local unprivileged attackers to escalate privileges to SYSTEM level, potentially compromising system…

Read MoreN-Able’s Take Control Agent Vulnerability Poses Privilege Escalation Risk for Windows Systems

Microsoft Identifies Vulnerabilities in ncurses Library Impacting Linux and macOS Platforms

Recent investigations have uncovered a series of memory corruption vulnerabilities within the ncurses library, which is instrumental for managing terminal displays on Unix-like operating systems, including Linux and macOS. These vulnerabilities, if exploited, could allow malicious actors to execute harmful code on susceptible systems, heightening the risk for organizations utilizing…

Read MoreMicrosoft Identifies Vulnerabilities in ncurses Library Impacting Linux and macOS Platforms

Trend Micro Issues Emergency Patch for Actively Exploited Critical Security Flaw

Trend Micro Issues Critical Patches for Exploited Flaw in Apex One and Worry-Free Solutions Cybersecurity firm Trend Micro has issued urgent patches to rectify a serious security vulnerability affecting its Apex One and Worry-Free Business Security solutions for Windows. This vulnerability, identified as CVE-2023-41179, has been linked to a third-party…

Read MoreTrend Micro Issues Emergency Patch for Actively Exploited Critical Security Flaw