Content Paint

CVEs

Critical pre-auth RCE Fortinet vulnerability is a breeze to exploit

A vulnerability in multiple Fortinet products gives an unauthenticated remote attackers root access to its core product’s administrative interface – and the vulnerability has been exploited in the wild the company warned. Given exploitation the company has warned customers to check for Indicators of Compromise. https://twitter.com/Horizon3Attack/status/

Two unpatched Microsoft Exchange Server zero days are under attack.

Exploited for a month. No detection in Sentinel, no patch yet. Mitigate urgently.

Second critical Sophos Firewall bug exploited in wild

CVSS 9.8 vulnerability added to CISA "known exploited" catalogue

Siemens' CVSS 9.8 advisory features exploited Apache HTTP vulnerability

Nasty Apache HTTP Server bug continues to cause issues...

"Dirty Pipe" Linux vulnerability now being exploited

Well a Metasploit module has been available for a while...

Five Cisco products vulnerable to a CVSS 10 auth bypass

Should customers start demanding more?

A record number of software vulnerabilities was reported in 2021

Mean-time-to-Patch, meanwhile? 205 days...

With #HiveNightmare, Windows 10 and 11 give up all user passwords

Zero, to SYSTEM and creating new admin accounts, in a heartbeat.

Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Great! You've successfully signed up.
Great! You've successfully signed up.
Welcome back! You've successfully signed in.
Success! You now have access to additional content.