Security News

BeyondTrust fixes critical vulnerability in remote access, support solutions (CVE-2024-12356)
2024-12-18 09:39

BeyondTrust has fixed an unauthenticated command injection vulnerability (CVE-2024-12356) in its Privileged Remote Access (PRA) and Remote Support (RS) products that may allow remote code...

Microsoft fixes exploited zero-day (CVE-2024-49138)
2024-12-10 20:59

On December 2024 Patch Tuesday, Microsoft resolved 71 vulnerabilities in a variety of its products, including a zero-day (CVE-2024-49138) that’s been exploited by attackers in the wild to execute...

Attackers actively exploiting flaw(s) in Cleo file transfer software (CVE-2024-50623)
2024-12-10 13:24

Attackers are exploiting a vulnerability (CVE-2024-50623) in file transfer software by Cleo – LexiCo, VLTransfer, and Harmony – to gain access to organizations’ systems, Huntress researchers...

PoC exploit for critical WhatsUp Gold RCE vulnerability released (CVE-2024-8785)
2024-12-04 11:16

Researchers have published a proof-of-concept (PoC) exploit for CVE-2024-8785, a critical remote code execution vulnerability affecting Progress WhatsUp Gold, a popular network monitoring solution...

Veeam plugs serious holes in Service Provider Console (CVE-2024-42448, CVE-2024-42449)
2024-12-03 17:33

Veeam has fixed two vulnerabilities in Veeam Service Provider Console (VSPC), one of which (CVE-2024-42448) may allow remote attackers to achieve code exection on the VSPC server machine. The...

Apple fixes 2 zero-days exploited to breach macOS systems (CVE-2024-44309, CVE-2024-44308)
2024-11-20 10:48

Apple has released emergency security updates for macOS Sequoia that fix two zero-day vulnerabilities (CVE-2024-44309, CVE-2024-44308) that “may have been actively exploited on Intel-based Mac...

Oracle patches exploited Agile PLM vulnerability (CVE-2024-21287)
2024-11-19 10:43

Oracle has released a security patch for CVE-2024-21287, a remotely exploitable vulnerability in the Oracle Agile PLM Framework that is, according to Tenable researchers, being actively exploited...

Attackers are exploiting 2 zero-days in Palo Alto Networks firewalls (CVE-2024-0012, CVE-2024-9474)
2024-11-18 15:28

Palo Alto Networks has released fixes for two vulnerabilities (CVE-2024-0012 and CVE-2024-9474) in its next-generation firewalls that have been exploited by attackers as zero-days. About the...

Palo Alto Networks firewalls, Expedition under attack (CVE-2024-9463, CVE-2024-9465)
2024-11-15 11:09

Attackers have been spotted exploiting two additional vulnerabilities (CVE-2024-9463, CVE-2024-9465) in Palo Alto Networks’ Expedition firewall configuration migration tool, CISA has confirmed on...

How a Windows zero-day was exploited in the wild for months (CVE-2024-43451)
2024-11-14 09:57

CVE-2024-43451, a Windows zero-day vulnerability for which Microsoft released a fix on November 2024 Patch Tuesday, has been exploited since at least April 2024, ClearSky researchers have...