Category vulnerabilities

Exploit PoC Unveiled for Critical SSH Authentication Bypass in VMware Aria

VMware Faces Critical Vulnerability as PoC Exploit Code Emerges A newly disclosed vulnerability in VMware Aria Operations for Networks (formerly known as vRealize Network Insight) has raised serious security concerns, particularly as proof-of-concept (PoC) exploit code has become available. The critical flaw, tracked as CVE-2023-34039, has been assigned a severe…

Read MoreExploit PoC Unveiled for Critical SSH Authentication Bypass in VMware Aria

Hackers Exploit Vulnerabilities in MinIO Storage System to Compromise Servers

A concerning cybersecurity incident has emerged involving a previously unidentified threat actor exploiting critical vulnerabilities in the MinIO object storage platform. This series of attacks enables unauthorized code execution on affected servers, prompting alarm among cybersecurity professionals. According to Security Joes, a cybersecurity and incident response firm, the attackers utilized…

Read MoreHackers Exploit Vulnerabilities in MinIO Storage System to Compromise Servers

Zero-Day Alert: Recent Android Patch Addresses Actively Exploited Vulnerability

In its latest round of security updates, Google has addressed critical vulnerabilities within the Android operating system, including a serious zero-day flaw that may have been leveraged in active attacks. The company released monthly patches aimed at rectifying issues that could potentially put user devices at risk. The vulnerability, designated…

Read MoreZero-Day Alert: Recent Android Patch Addresses Actively Exploited Vulnerability

North Korean Hackers Leverage Zero-Day Vulnerability to Attack Cybersecurity Researchers

Recent investigations by Google’s Threat Analysis Group (TAG) have revealed that North Korean hackers are persistently targeting the cybersecurity community through the exploitation of a zero-day vulnerability in an unspecified software application. This campaign has gained momentum over the past several weeks, highlighting sophisticated tactics employed to infiltrate the systems…

Read MoreNorth Korean Hackers Leverage Zero-Day Vulnerability to Attack Cybersecurity Researchers

Cisco Releases Critical Update to Address Authentication Bypass Vulnerability in BroadWorks Platform

Cisco has issued critical security patches addressing several vulnerabilities, including one particularly severe flaw, potentially allowing threat actors to gain unauthorized control of affected systems or precipitate denial-of-service (DoS) conditions. The most critical vulnerability identified as CVE-2023-20238 has received a maximum CVSS severity rating of 10.0, relating to an authentication…

Read MoreCisco Releases Critical Update to Address Authentication Bypass Vulnerability in BroadWorks Platform

Apple Hurries to Fix Zero-Day Vulnerabilities Targeted by Pegasus Spyware on iPhones

Apple Issues Urgent Security Patches for Exploited Zero-Day Vulnerabilities On Thursday, Apple announced the immediate release of emergency security updates for iOS, iPadOS, macOS, and watchOS to rectify two critical zero-day vulnerabilities. These flaws had already been leveraged in attacks to deploy the notorious Pegasus spyware developed by the NSO…

Read MoreApple Hurries to Fix Zero-Day Vulnerabilities Targeted by Pegasus Spyware on iPhones

Critical GitHub Vulnerability Puts Over 4,000 Repositories at Risk of Repojacking Attack

New Vulnerability Exposes Thousands of GitHub Repositories to Repojacking Attacks A recently disclosed vulnerability in GitHub has raised concerns about the security of thousands of repositories, putting them at risk for repojacking attacks. According to findings from Checkmarx security researcher Elad Rapoport, this flaw allows attackers to exploit a race…

Read MoreCritical GitHub Vulnerability Puts Over 4,000 Repositories at Risk of Repojacking Attack

Mozilla Urgently Addresses Critical Zero-Day Vulnerability in WebP for Firefox and Thunderbird

On Tuesday, Mozilla released urgent security updates addressing a critical zero-day vulnerability affecting both Firefox and Thunderbird, identified as CVE-2023-4863. This flaw has been actively exploited in the wild, prompting the need for immediate remediation. The vulnerability pertains to a heap buffer overflow in the WebP image format, which could…

Read MoreMozilla Urgently Addresses Critical Zero-Day Vulnerability in WebP for Firefox and Thunderbird

Update Adobe Acrobat and Reader to Address Actively Exploited Vulnerability

Adobe has issued a critical security patch as part of its September 2023 Patch Tuesday update, addressing a severe vulnerability in Acrobat and Reader software. The flaw, identified as CVE-2023-26369, poses a substantial risk by allowing attackers to execute malicious code on vulnerable systems, specifically those running on Windows and…

Read MoreUpdate Adobe Acrobat and Reader to Address Actively Exploited Vulnerability