vulnerabilities
This critical vulnerability is an “open door into your network” and being exploited. Why didn’t RUCKUS Networks register a CVE?
CVE-2023-25717 is being exploited and affected products have been pulled into a new botnet...
vulnerabilities
CVE-2023-25717 is being exploited and affected products have been pulled into a new botnet...
MOVEit
Hackers "often breach the Department’s defensive perimeter and roam freely within our information systems"
Fortinet
"It is a pre-auth RCE [and] has been proven to be exploitable in a consistent manner; we found it during a Red Team engagement and have exploited it remotely..."
News
Admins should urgently modify firewall rules to deny HTTP and HTTPs traffic to MOVEit Transfer on ports 80 and 443. (Also, can we start fuzzing for SQL Injection properly, please?)
Cybersecurity
... and probably shot to high heaven with malware.
Cybersecurity
Security experts are warning that a critical Microsoft Outlook exploit is trivial to deploy and “will likely be leveraged imminently by actors for espionage purposes or financial gain” – after Ukrainian cybersecurity authorities disclosed CVE-2023-23397, a critical vulnerability that requires no user interaction to exploit. As The Stack reported, the critical
Cybersecurity
Get domain admin by... just emailing the domain admin?
Cybersecurity
This may generate a lot of Black Hat interest...
Cybersecurity
Open source bug leads to server backup bug leads to... crime.
Cybersecurity
VMware denies zero day being used
Cybersecurity
Heroic effort by Trellix but risks abound still...
Featured
Can you guess the product with the most CVEs in 2022?