Security News

Cisco Patches Critical Vulnerability in Jabber for Windows
2020-09-07 14:22

Cisco last week released patches to address a critical remote code execution vulnerability in Jabber for Windows. "Cisco Jabber uses XHTML-IM by default for all messages. A malicious message can therefore easily be created by intercepting an XMPP message sent by the application and modifying it. Attackers can do this manually on their own machine or it can be automated to create a worm that spreads automatically," the company continues.

Attackers Can Exploit Critical Cisco Jabber Flaw With One Message
2020-09-03 17:30

Researchers are warning of a critical remote code-execution flaw in the Windows version of Cisco Jabber, the networking company's video-conferencing and instant-messaging application. The flaw has a CVSS score of 9.9 out of 10, making it critical in severity, Cisco said in a Wednesday advisory.

WordPress 'File Manager' Plugin Patches Critical Zero-Day Exploited in Attacks
2020-09-03 13:25

The highly popular WordPress plugin File Manager this week received a patch to address an actively exploited zero-day vulnerability. Designed to provide WordPress site admins with copy/paste, edit, delete, download/upload, and archive functionality for both files and folders, File Manager has over 700,000 active installs.

Cisco patches critical, wormable RCE flaw in Cisco Jabber
2020-09-03 09:49

Cisco has patched four vulnerabilities in its Jabber client for Windows, the most critical of which could allow attackers to achieve remote code execution by sending specially crafted chat messages. Cisco Jabber is a video conferencing and instant messaging application that's often used within enterprises for internal communication and collaboration.

Iranian Hackers Target Critical Vulnerability in F5's BIG-IP
2020-09-01 10:43

A hacking group believed to be linked to the Iranian government was observed targeting a critical vulnerability that F5 Networks addressed in its BIG-IP application delivery controller in early July. Tracked as CVE-2020-5902 and featuring a CVSS score of 10, the vulnerability allows remote attackers to take complete control of a targeted system.

Critical vuln that lets miscreants hijack computers via Slack? *Sucks in air* We'll give you $1,750 for it
2020-08-31 21:28

A critical remote-code-execution vulnerability affecting past versions of the Slack desktop app was disclosed on Friday after the software maker fixed its app. Back in January, Oskars Vegeris, a security engineer at Evolution Gaming, privately reported to Slack a remote code execution vulnerability affecting version 4.2 and 4.32 of its desktop apps for Linux, macOS, and Windows via bug bounty program HackerOne.

Slack Pays Bounty for Critical Vulnerability in Desktop App
2020-08-31 18:34

A security researcher was awarded a $1,750 bug bounty reward for discovering a remote code execution vulnerability in the Slack desktop applications. An attacker could exploit the vulnerability to execute arbitrary code within Slack's desktop apps for macOS, Linux, and Windows.

Critical Slack Bug Allows Access to Private Channels, Conversations
2020-08-31 15:36

A critical vulnerability in the popular Slack collaboration app would allow remote code-execution. Attackers could gain full remote control over the Slack desktop app with a successful exploit - and thus access to private channels, conversations, passwords, tokens and keys, and various functions.

Five critical cloud security challenges and how to overcome them
2020-08-31 05:00

You need to recognize the most critical cloud security challenges and develop a strategy for minimizing these risks. With that in mind, let's dive into the five most pressing cloud security challenges faced by modern organizations.

BT Security announces critical security partners for global portfolio
2020-08-31 00:30

BT Security has announced the key partners that it will work with going forward to provide industry-leading managed security services to customers. "Kevin Brown, Managing Director of BT Security, said:"Our new security partner ecosystem showcases the benefits of BT Security as a Managed Security Services Provider.