Security News

Progress urges admins to patch critical WhatsUp Gold bugs ASAP
2024-09-27 12:01

Progress Software warned customers to patch multiple critical and high-severity vulnerabilities in its WhatsUp Gold network monitoring tool as soon as possible. [...]

Critical NVIDIA Container Toolkit Vulnerability Could Grant Full Host Access to Attackers
2024-09-27 05:54

A critical security flaw has been disclosed in the NVIDIA Container Toolkit that, if successfully exploited, could allow threat actors to break out of the confines of a container and gain full...

Patch now: Critical Nvidia bug allows container escape, complete host takeover
2024-09-26 21:42

33% of cloud environments using the toolkit impacted, we're told A critical bug in Nvidia's widely used Container Toolkit could allow a rogue user or software to escape their containers and...

HPE patches three critical security holes in Aruba PAPI
2024-09-26 19:30

More 9.8 bugs? Ay, papi! Aruba access points running AOS-8 and AOS-10 need to be patched urgently after HPE emitted fixes for three critical flaws in its networking subsidiary's networking access points.…

That doomsday critical Linux bug: It's CUPS. May lead to remote hijacking of devices
2024-09-26 17:34

No patches yet, can be mitigated, requires user interaction Final update After days of anticipation, what was billed as one or more critical unauthenticated remote-code execution vulnerabilities...

That doomsday critical Linux bug: It's CUPS. Could lead to remote hijacking of devices
2024-09-26 17:34

Quick fix: Remove cups-browsed, block UDP port 631 Updated After days of waiting and anticipation, what was billed as one or more critical unauthenticated remote-code execution vulnerabilities in...

HPE Aruba Networking fixes critical flaws impacting Access Points
2024-09-26 12:11

HPE Aruba Networking has fixed three critical vulnerabilities in the Command Line Interface (CLI) service of its Aruba Access Points, which could let unauthenticated attackers gain remote code...

PoC for critical SolarWinds Web Help Desk vulnerability released (CVE-2024-28987)
2024-09-25 14:07

Details about and proof-of-concept (PoC) exploit code for CVE-2024-28987, a recently patched SolarWinds Web Help Desk (WHD) vulnerability that could be exploited by unauthenticated attackers to...

CISA Flags Critical Ivanti vTM Vulnerability Amid Active Exploitation Concerns
2024-09-25 06:01

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a critical security flaw impacting Ivanti Virtual Traffic Manager (vTM) to its Known Exploited Vulnerabilities...

Critical Ivanti vTM auth bypass bug now exploited in attacks
2024-09-24 17:03

CISA has tagged another critical Ivanti security vulnerability, which can let threat actors create rogue admin users on vulnerable Virtual Traffic Manager (vTM) appliances, as actively exploited...