Cybersecurity
Will this CVSS 10 Linux Kernel vuln ruin your holiday?
We're hopeful that Betteridge's law applies...
Cybersecurity
We're hopeful that Betteridge's law applies...
Cloud
A critical vulnerability in an Azure tool that lets users manage Kubernetes clusters can be exploited remotely without authentication to gain administrative control over Kubernetes clusters, as well as Azure edge devices. The vulnerability, allocated a maximum possible CVSS (severity rating) score of 10 has been allocated CVE-2022-37968. It is
Cybersecurity
Exploits have circulated since February.
Cybersecurity
Those 700,000 folks with RPC exposed to the internet should probably...
Cybersecurity
Don't put that stuff on the public internet, kids.
Cybersecurity
Just block iControl REST access through the management interface for starters...
Read This
Attackers continue to accelerate their weaponisation of newly-discovered flaws, the Five Eyes list of most-exploited vulnerabilities of 2021 shows. Contrary to some reports suggesting fears of mass-exploitation had been over-indexed, the flaw in Log4j joined the most widely-exploited vulnerabilities last year, despite only being discovered at the year's
Cybersecurity
It's back, it's big, and it's bad. April Patch Tuesday brings 145 vulnerability fixes from Microsoft -- the highest number in 19 months -- including a trio of remote code execution (RCE) vulnerabilities in Hyper-V and a brace of critical (CVSS 9.8) bugs
Cybersecurity
VMware Cloud Foundation, NSX-T, vRealize Suite, VMware Cloud suites, vRealize Automation, vRealize Log Insight all...
Cybersecurity
Pre-auth RCE has been exploited in the wild...
Read This
New state actors, labelled Wolf and Ocelot, identified in threat report
Cybersecurity
AWS, Red Hat, VMware, more affected with pre-auth RCE exploits circulating