Security News

Week in review: The data skills gap,  new Kali Linux release, Apache Solr RCEs with public PoCs
2019-12-01 16:30

Here’s an overview of some of last week’s most interesting news and articles: The overlooked part of an infosec strategy: Cyber insurance underwriting When a data breach or cyber attack hits the...

Apache Solr RCEs with public PoCs could soon be exploited
2019-11-25 10:33

Two remote code execution (RCE) vulnerabilities in Apache Solr could be exploited by attackers to compromise the underlying server. One – CVE-2019-12409 – has already been patched, while the other...

Apache Solr Bug Gets Bumped Up to High Severity
2019-11-20 19:41

Linux users running the enterprise-search platform Solr are potentially vulnerable to remote code execution attack.

DataStax unveils Change Data Capture Connector for Apache Kafka
2019-10-02 02:00

DataStax, the company behind the leading database built on Apache Cassandra, announced early access to the DataStax Change Data Capture (CDC) Connector for Apache Kafka. The DataStax CDC Connector...

61 impacted versions of Apache Struts left off security advisories
2019-08-19 10:23

Researchers found that 24 security advisories inaccurately listed affected versions for the open-source development framework.

Many Apache Struts Security Advisories Updated Following Review
2019-08-16 05:41

Two dozen security advisories for the Apache Struts open source development framework have been updated after researchers determined that they contained incorrect information regarding which...

Apache Security Advisories Red Flag Wrong Versions in Patching Gaffe
2019-08-15 18:41

Up to 24 Apache Struts Security Advisories listed the wrong versions that were impacted by vulnerabilities, researchers warn.

PoC exploit for Carpe Diem Apache bug released
2019-04-09 09:25

Charles Fol, the security engineer that unearthed the Carpe Diem Apache HTTP Server bug (CVE-2019-0211), has released an exploit for it. “This is between a POC and a proper exploit. I added tons...

Apache needs a patchy! Carpe Diem, update now
2019-04-04 11:06

A flaw in the world’s most popular web server could give an attacker a way to gain full control of Unix-based systems.

A patchy Apache a-patchin: HTTP server gets fix for worrying root access hole
2019-04-03 19:52

Rogue 'worker' processes can sneak in with elevated privileges at startup Apache HTTP Server has been given a patch to address a potentially serious elevation of privilege vulnerability.…