Security News > 2023 > October

Critical OAuth Flaws Uncovered in Grammarly, Vidio, and Bukalapak Platforms
2023-10-25 13:04

Critical security flaws have been disclosed in the Open Authorization (OAuth) implementation of popular online services such as Grammarly, Vidio, and Bukalapak, building upon previous shortcomings...

A fortified data vault to give you peace of mind
2023-10-25 12:53

Webinar It's a challenge to maintain the availability and security of mission critical data in today's environment. The traditional approach to meeting that challenge often involves complex multi-vendor solutions.

Roundcube webmail zero-day exploited to spy on government entities (CVE-2023-5631)
2023-10-25 11:44

The Winter Vivern APT group has been exploiting a zero-day vulnerability in Roundcube webmail servers to spy on email communications of European governmental entities and a think tank, according to ESET researchers. Roundcube is an open-source browser-based email client with application-like user interface.

The Rise of S3 Ransomware: How to Identify and Combat It
2023-10-25 11:36

In today's digital landscape, around 60% of corporate data now resides in the cloud, with Amazon S3 standing as the backbone of data storage for many major corporations. Despite S3 being a secure...

Microsoft is Soft-Launching Security Copilot
2023-10-25 11:07

About Bruce Schneier I am a public-interest technologist, working at the intersection of security, technology, and people. I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

European govt email servers hacked using Roundcube zero-day
2023-10-25 11:00

Their phishing messages impersonated the Outlook Team and tried to trick potential victims into opening malicious emails, automatically triggering a first-stage payload that exploited the Roundcube email server vulnerability. "The final JavaScript payload [.] is able to list folders and emails in the current Roundcube account, and to exfiltrate email messages to the C&C server."

VMware patches critical vulnerability in vCenter Server (CVE-2023-34048)
2023-10-25 10:40

VMware has fixed a critical out-of-bounds write vulnerability and a moderate-severity information disclosure flaw in vCenter Server, its popular server management software.CVE-2023-34048 allows an attacker with network access to a vulnerable vCenter Server virtual appliance to trigger an out-of-bounds write that can lead to remote code execution.

Act Now: VMware Releases Patch for Critical vCenter Server RCE Vulnerability
2023-10-25 10:11

VMware has released security updates to address a critical flaw in the vCenter Server that could result in remote code execution on affected systems. The issue, tracked as CVE-2023-34048 (CVSS...

Malvertising Campaign Targets Brazil's PIX Payment System with GoPIX Malware
2023-10-25 09:13

The popularity of Brazil's PIX instant payment system has made it a lucrative target for threat actors looking to generate illicit profits using a new malware called GoPIX. Kaspersky, which has...

VMware fixes critical code execution flaw in vCenter Server
2023-10-25 09:00

VMware issued security updates to fix a critical vCenter Server vulnerability that can be exploited to gain remote code execution attacks on vulnerable servers. vCenter Server is the central management hub for VMware's vSphere suite, and it helps administrators manage and monitor virtualized infrastructure.