Security News

Critical default credential in Kubernetes Image Builder allows SSH root access
2024-10-16 21:58

It's called leaving the door wide open – especially in Proxmox A critical bug in Kubernetes Image Builder could allow unauthorized SSH access to virtual machines (VMs) thanks to default...

Critical hardcoded SolarWinds credential now exploited in the wild
2024-10-16 20:00

Another blow for IT software house and its customers A critical, hardcoded login credential in SolarWinds' Web Help Desk line has been exploited in the wild by criminals, according to the US...

Critical Kubernetes Image Builder flaw gives SSH root access to VMs
2024-10-16 16:58

A critical vulnerability in Kubernetes could allow unauthorized SSH access to a virtual machine running an image created with the Kubernetes Image Builder project. [...]

GitHub Patches Critical Flaw in Enterprise Server Allowing Unauthorized Instance Access
2024-10-16 05:06

GitHub has released security updates for Enterprise Server (GHES) to address multiple issues, including a critical bug that could allow unauthorized access to an instance. The vulnerability,...

Jetpack fixes critical information disclosure flaw existing since 2016
2024-10-14 19:30

WordPress plugin Jetpack released a critical security update earlier today, addressing a vulnerability that allowed a logged-in user to access forms submitted by other visitors to the site. [...]

Critical Veeam Vulnerability Exploited to Spread Akira and Fog Ransomware
2024-10-14 08:55

Threat actors are actively attempting to exploit a now-patched security flaw in Veeam Backup & Replication to deploy Akira and Fog ransomware. Cybersecurity vendor Sophos said it has been tracking...

New Critical GitLab Vulnerability Could Allow Arbitrary CI/CD Pipeline Execution
2024-10-11 06:29

GitLab has released security updates for Community Edition (CE) and Enterprise Edition (EE) to address eight security flaws, including a critical bug that could allow running Continuous...

Akira and Fog ransomware now exploit critical Veeam RCE flaw
2024-10-10 22:07

Ransomware gangs now exploit a critical security vulnerability that lets attackers gain remote code execution (RCE) on vulnerable Veeam Backup & Replication (VBR) servers. [...]

GitLab warns of critical arbitrary branch pipeline execution flaw
2024-10-10 15:12

GitLab has released security updates to address multiple flaws in Community Edition (CE) and Enterprise Edition (EE), including a critical arbitrary branch pipeline execution flaw. [...]

CISA adds fresh Ivanti vuln, critical Fortinet bug to hall of shame
2024-10-10 13:34

Usual three-week window to address significant risks to federal agencies applies The US Cybersecurity and Infrastructure Security Agency (CISA) says vulnerabilities in Fortinet and Ivanti products...