Security News

Zyxel fixes critical command injection flaw in EOL NAS devices (CVE-2024-6342)
2024-09-10 09:01

Users of Zyxel network-attached storage (NAS) devices are urged to implement hotfixes addressing a critical and easily exploited command injection vulnerability (CVE-2024-6342). About...

Veeam Backup & Replication RCE flaw may soon be leveraged by ransomware gangs (CVE-2024-40711)
2024-09-09 11:45

CVE-2024-40711, a critical vulnerability affecting Veeam Backup & Replication (VBR), could soon be exploited by attackers to steal enterprise data. Discovered and reported by Code WHite researcher...

Apache OFBiz team patches critical RCE vulnerability (CVE-2024-45195)
2024-09-06 10:01

For the fourth time in the last five months, Apache OFBiz users have been advised to upgrade their installations to fix a critical flaw (CVE-2024-45195) that could lead to unauthenticated remote...

Critical flaw in Zyxel’s secure routers allows OS command execution via cookie (CVE-2024-7261)
2024-09-03 12:47

Zyxel has patched a myriad of vulnerabilities in its various networking devices, including a critical one (CVE-2024-7261) that may allow unauthenticated attackers to execute OS commands on many...

APT group exploits WPS Office for Windows RCE vulnerability (CVE-2024-7262)
2024-08-28 09:00

ESET researchers discovered a remote code execution vulnerability in WPS Office for Windows (CVE-2024-7262). APT-C-60, a South Korea-aligned cyberespionage group, was exploiting it to target East...

Critical Fortra FileCatalyst Workflow vulnerability patched (CVE-2024-6633)
2024-08-28 08:46

Organizations using Fortra’s FileCatalyst Workflow are urged to upgrade their instances, so that attackers can’t access an internal HSQL database by exploiting known static credentials...

Versa Director zero-day exploited to compromise ISPs, MSPs (CVE-2024-39717)
2024-08-27 15:47

Advanced, persistent attackers have exploited a zero-day vulnerability (CVE-2024-39717) in Versa Director to compromise US-based managed service providers with a custom-made web shell dubbed...

Google Warns of CVE-2024-7965 Chrome Security Flaw Under Active Exploitation
2024-08-27 04:45

Google has revealed that a security flaw that was patched as part of a security update rolled out last week to its Chrome browser has come under active exploitation in the wild. Tracked as...

SonicWall patches critical flaw affecting its firewalls (CVE-2024-40766)
2024-08-26 18:28

SonicWall has patched a critical vulnerability (CVE-2024-40766) in its next-gen firewalls that could allow remote attackers unauthorized access to resources and, in specific conditions, to crash...

Another critical SolarWinds Web Help Desk bug fixed (CVE-2024-28987)
2024-08-23 10:26

A week after SolarWinds released a fix for a critical code-injection-to-RCE vulnerability (CVE-2024-28986) in Web Help Desk (WHD), another patch for another critical flaw (CVE-2024-28987) in the...