Security News

That critical VMware vuln allowed anyone on your network to create new admin users, no creds needed
2020-04-17 15:59

A critical vulnerability in VMware's vCenter management product allowed any old bod on the same network to remotely create an admin-level user, research by Guardicore Labs has revealed. The astonishing vuln, details of which were quite spare when VMWare issued a patch last week, was rated by VMware itself as CVSS v3 10.0, the highest level.

Cisco Patches Critical Flaws in IP Phones, UCS Director
2020-04-17 04:11

Cisco this week released security patches to address numerous vulnerabilities across its products, including critical severity flaws that impact IP Phones and UCS Director. The critical vulnerability patched in IP Phones impacts the web server and could allow a remote, unauthenticated attacker to execute code with root privileges.

KORE introduces Critical Asset Management solution providing condition-level visibility into critical goods
2020-04-17 02:30

KORE, the independent global IoT leader, announced the launch of a new comprehensive managed services solution for Critical Asset Management, utilizing the Visilion asset tracking platform from Sony Network Communications Europe. KORE's solution introduces a new level of condition management, allowing companies in the medical instrumentation, pharmaceutical, and food and beverage industries to maintain real-time condition visibility of critical and high-value goods.

Cisco IP Phone Harbors Critical RCE Flaw
2020-04-16 18:49

Cisco is warning of a critical flaw in the web server of its IP phones. Cisco issued patches in a Wednesday advisory for the flaw, which affects various versions of its Cisco IP phones for small- to medium-sized businesses.

Using Cisco IP phones? Fix these critical vulnerabilities
2020-04-16 10:10

Among the vulnerabilities fixed are critical flaws affecting a variety of Cisco IP phones and Cisco UCS Director and Cisco UCS Director Express for Big Data, its unified infrastructure management solutions for data center operations. Jacob Baines, a research engineer with Tenable, unearthed two critical flaws affecting the Cisco Wireless IP Phone 8821.

SAP's April 2020 Security Updates Patch Five Critical Vulnerabilities
2020-04-16 03:59

SAP this week released its latest set of security patches, which brings a total of 23 Security Notes, including five that address Hot News vulnerabilities. Another Hot News Security Note released as part of the April 2020 SAP Security Patch Day addresses a directory traversal vulnerability in SAP NetWeaver.

Oracle's April 2020 Critical Patch Update Brings 397 Security Fixes
2020-04-15 12:53

Oracle this week released its April 2020 collection of security patches, which includes a total of 397 fixes for vulnerabilities affecting two dozen products. Roughly 60 of the newly addressed vulnerabilities are considered critical severity, with more than 55 of them featuring a CVSS score of 9.8.

Hackers Targeting Critical Healthcare Facilities With Ransomware During Coronavirus Pandemic
2020-04-15 03:08

As hospitals around the world are struggling to respond to the coronavirus crisis, cybercriminals-with no conscience and empathy-are continuously targeting healthcare organizations, research facilities, and other governmental organizations with ransomware and malicious information stealers. While the security firm didn't name the latest victims, it said a Canadian government healthcare organization and a Canadian medical research university both suffered ransomware attacks, as criminal groups seek to exploit the crisis for financial gain.

Safe Remote Access to Critical Infrastructure Networks in a Time of Global Crisis
2020-04-14 13:00

The Wired article argued that it is essential to engineer a way to provide remote access to control system environments for critical infrastructure services such as water, electricity, and fuel refining during the coronavirus crisis. Through server replication, critical infrastructure sites enable 100% real-time visibility into protected networks, 100% protection from remote attacks, with a number of options for truly secure remote access in this time of crisis.

VMware plugs critical flaw in vCenter Server, patch ASAP!
2020-04-14 10:55

VMware has fixed a critical vulnerability affecting vCenter Server, which can be exploited to extract highly sensitive information that could be used to compromise vCenter Server or other services which depend on the VMware Directory Service for authentication. vCenter Server is server management software for controlling VMware vSphere environments.