Security News

IoT Botnets Target Apache Struts, SonicWall GMS
2018-09-10 11:58

The infamous Mirai and Gafgyt Internet of Things (IoT) botnets are targeting vulnerabilities in Apache Struts and the SonicWall Global Management System (GMS), Palo Alto Networks has discovered. read more

Cisco fixes a host of security holes, including latest Apache Struts flaw
2018-09-06 20:21

Cisco has plugged a heap of security holes – three of which are critical – in a variety of its products. The critical flaws The flaws deemed critical are: A DoS and RCE vulnerability...

Active Campaign Exploits Critical Apache Struts 2 Flaw in the Wild
2018-09-05 17:48

A Monero cryptomining script is spreading in an ongoing campaign using the recently disclosed critical remote command-execution flaw.

CVE-2018-11776 — The Latest Apache Struts Vulnerability
2018-09-04 10:49

A Critical security flaw (CVE-2018-11776) impacts Apache Struts 2.3 through 2.3.34, Struts 2.5 through 2.5.16, and possibly unsupported versions of the popular Java framework.

Oracle Products Affected by Exploited Apache Struts Flaw
2018-09-04 10:22

Oracle informed customers over the weekend that some of the company’s products are affected by a critical Apache Struts 2 vulnerability that has been exploited in the wild. read more

Hackers latch onto new Apache Struts megavuln to mine cryptocurrency
2018-08-30 15:05

Underground forums alight with Struts chat, we hear A recently uncovered critical vulnerability in Apache Struts is already being exploited in the wild.…

Critical Apache Struts Vulnerability Exploited in Live Attacks
2018-08-28 14:07

A Critical remote code execution vulnerability in Apache Struts 2 that was patched last week is already being abused in malicious attacks, threat intelligence firm Volexity warns. read more

PoC exploit for critical Apache Struts flaw found online
2018-08-27 15:26

The Apache Software Foundation revealed last week the existence of a critical Apache Struts flaw (CVE-2018-11776) similar to the one exploited in the Equifax breach and urged organizations and...

Week in review: DNS interception, critical Apache Struts flaw, cybersecurity career pathing
2018-08-26 19:21

Here’s an overview of some of last week’s most interesting news and articles: The importance of career pathing in the cybersecurity industry A major issue facing our industry right now is a...