Security News

Patch Alert: Critical Apache Struts Flaw Found, Exploitation Attempts Detected
2024-12-18 13:36

Threat actors are attempting to exploit a recently disclosed security flaw impacting Apache Struts that could pave the way for remote code execution. The issue, tracked as CVE-2024-53677, carries...

BeyondTrust Issues Urgent Patch for Critical Vulnerability in PRA and RS Products
2024-12-18 09:15

BeyondTrust has disclosed details of a critical security flaw in Privileged Remote Access (PRA) and Remote Support (RS) products that could potentially lead to the execution of arbitrary commands....

Vanir: Open-source security patch validation for Android
2024-12-18 04:30

Google’s open-source tool Vanir enables Android developers to quickly scan custom platform code for missing or applicable security patches. By automating patch validation, Vanir helps OEMs deliver...

Patch Tuesday: Microsoft Patches One Actively Exploited Vulnerability, Among Others
2024-12-11 20:57

December marked a quiet month with 70 vulnerabilities patched, plus updates from outside of Microsoft.

Microsoft Fixes 72 Flaws, Including Patch for Actively Exploited CLFS Vulnerability
2024-12-11 07:16

Microsoft closed out its Patch Tuesday updates for 2024 with fixes for a total of 72 security flaws spanning its software portfolio, including one that it said has been exploited in the wild. Of...

Microsoft holds last Patch Tuesday of the year with 72 gifts for admins
2024-12-10 20:48

Twas the night before Christmas, and all through the house, patching was done with the click of a mouse Microsoft hasn't added too much coal to the stocking this Patch Tuesday, with just 72 fixes,...

Microsoft December 2024 Patch Tuesday fixes 1 exploited zero-day, 71 flaws
2024-12-10 18:33

Today is Microsoft's December 2024 Patch Tuesday, which includes security updates for 71 flaws, including one actively exploited zero-day vulnerability. [...]

Cleo File Transfer Vulnerability Under Exploitation – Patch Pending, Mitigation Urged
2024-12-10 15:57

Users of Cleo-managed file transfer software are being urged to ensure that their instances are not exposed to the internet following reports of mass exploitation of a vulnerability affecting...

Week in review: Veeam Service Provider Console flaws fixed, Patch Tuesday forecast
2024-12-08 09:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Veeam plugs serious holes in Service Provider Console (CVE-2024-42448, CVE-2024-42449) Veeam has...

New Windows zero-day exposes NTLM credentials, gets unofficial patch
2024-12-06 16:32

A new zero-day vulnerability has been discovered that allows attackers to capture NTLM credentials by simply tricking the target into viewing a malicious file in Windows Explorer. [...]