Category vulnerabilities

Numerous Campaigns Target VMware Vulnerability to Distribute Crypto Miners and Ransomware

A recently patched vulnerability in VMware Workspace ONE Access has been leveraged to distribute both cryptocurrency mining malware and ransomware across affected systems. This information comes from Fortinet’s FortiGuard Labs, where researcher Cara Lin highlighted that the attackers aim to exploit victims’ resources extensively. The goal appears to involve not…

Read MoreNumerous Campaigns Target VMware Vulnerability to Distribute Crypto Miners and Ransomware

Apple Issues Patch for Actively Exploited Zero-Day Vulnerability in iOS and iPadOS

Apple Inc. has recently released critical updates addressing a zero-day vulnerability identified in iOS and iPadOS that has reportedly been exploited in active cyberattacks. The flaw, tracked as CVE-2022-42827, pertains to an out-of-bounds write issue within the Kernel. This type of vulnerability can empower malicious applications to execute arbitrary code…

Read MoreApple Issues Patch for Actively Exploited Zero-Day Vulnerability in iOS and iPadOS

22-Year-Old Vulnerability Discovered in Popular SQLite Database Library

A recently disclosed vulnerability in the SQLite database library raises significant concerns within the cybersecurity community. This high-severity flaw, tracked under the identifier CVE-2022-35737, dates back over two decades to a code update from October 2000, and it poses a risk that could allow attackers to crash or gain control…

Read More22-Year-Old Vulnerability Discovered in Popular SQLite Database Library

VMware Issues Patch for Critical RCE Vulnerability in Cloud Foundation Platform

On Tuesday, VMware announced the release of security updates aimed at addressing a critical vulnerability within its VMware Cloud Foundation product, a platform utilized for cloud infrastructure management. The vulnerability, identified as CVE-2021-39144, has been assigned a CVSS score of 9.8, indicating its severity. This flaw is related to a…

Read MoreVMware Issues Patch for Critical RCE Vulnerability in Cloud Foundation Platform

Hackers Actively Exploiting Vulnerabilities in Cisco AnyConnect and GIGABYTE Drivers

Cisco has issued a warning regarding active exploitation attempts of two persistent vulnerabilities in the Cisco AnyConnect Secure Mobility Client for Windows, which have been present for two years. The vulnerabilities, identified as CVE-2020-3153 (with a CVSS score of 6.5) and CVE-2020-3433 (CVSS score: 7.8), could potentially allow authenticated local…

Read MoreHackers Actively Exploiting Vulnerabilities in Cisco AnyConnect and GIGABYTE Drivers

Researchers Reveal Key Details About Critical ‘CosMiss’ RCE Vulnerability in Azure Cosmos DB

On Tuesday, Microsoft disclosed that it had rectified an authentication bypass vulnerability in Jupyter Notebooks associated with Azure Cosmos DB, which had the potential to grant unauthorized full read and write access. This issue was identified on August 12, 2022, and was effectively resolved worldwide by October 6, 2022, shortly…

Read MoreResearchers Reveal Key Details About Critical ‘CosMiss’ RCE Vulnerability in Azure Cosmos DB

OpenSSL Issues Patch for Two Critical Vulnerabilities

OpenSSL has announced critical updates addressing two high-severity vulnerabilities within its cryptographic library. These flaws, identified as CVE-2022-3602 and CVE-2022-3786, pose risks of denial-of-service (DoS) attacks and potential remote code execution (RCE). The vulnerabilities stem from buffer overrun issues that can be exploited during the verification of X.509 certificates, typically…

Read MoreOpenSSL Issues Patch for Two Critical Vulnerabilities

Multiple Vulnerabilities Discovered in Checkmk IT Infrastructure Monitoring Software

Recent research has uncovered multiple critical vulnerabilities within Checkmk, an IT infrastructure monitoring software, which may allow an unauthenticated remote attacker to seize full control of affected systems. These vulnerabilities could potentially be mishandled collectively, posing significant risks to users, especially those utilizing Checkmk version 2.1.0p10 or older. Stefan Schiller,…

Read MoreMultiple Vulnerabilities Discovered in Checkmk IT Infrastructure Monitoring Software