Security News

Zyxel won’t patch newly exploited flaws in end-of-life routers
2025-02-04 21:22

Zyxel has issued a security advisory about actively exploited flaws in CPE Series devices, warning that it has no plans to issue fixing patches and urging users to move to actively supported models. [...]

Netgear warns users to patch critical WiFi router vulnerabilities
2025-02-04 16:33

Netgear has fixed two critical remote code execution and authentication bypass vulnerabilities affecting multiple WiFi routers and warned customers to update their devices to the latest firmware...

Zyxel CPE devices under attack via critical vulnerability without a patch (CVE-2024-40891)
2025-01-29 16:23

CVE-2024-40891, a command injection vulnerability in Zyxel CPE Series telecommunications devices that has yet to be fixed by the manufacturer, is being targeted by attackers, cybersecurity company...

Don't want your Kubernetes Windows nodes hijacked? Patch this hole now
2025-01-24 15:00

SYSTEM-level command injection via API parameter *chef's kiss* A now-fixed command-injection bug in Kubernetes can be exploited by a remote attacker to gain code execution with SYSTEM privileges...

Patch now: Cisco fixes critical 9.9-rated, make-me-admin bug in Meeting Management
2025-01-23 21:00

No in-the-wild exploits … yet Cisco has pushed a patch for a critical, 9.9-rated vulnerability in its Meeting Management tool that could allow a remote, authenticated attacker with low privileges...

SonicWall Urges Immediate Patch for Critical CVE-2025-23006 Flaw Amid Likely Exploitation
2025-01-23 10:24

SonicWall is alerting customers of a critical security flaw impacting its Secure Mobile Access (SMA) 1000 Series appliances that it said has been likely exploited in the wild as a zero-day. The...

Asus lets processor security fix slip out early, AMD confirms patch in progress
2025-01-23 07:19

Answers on a postcard to what 'Microcode Signature Verification Vulnerability' might mean AMD has confirmed at least some of its microprocessors suffer a microcode-related security vulnerability,...

Oracle Releases January 2025 Patch to Address 318 Flaws Across Major Products
2025-01-22 07:25

Oracle is urging customers to apply its January 2025 Critical Patch Update (CPU) to address 318 new security vulnerabilities spanning its products and services. The most severe of the flaws is a...

Patch procrastination leaves 50,000 Fortinet firewalls vulnerable to zero-day
2025-01-21 18:45

Seven days after disclosure and little action taken, data shows Fortinet customers need to get with the program and apply the latest updates as nearly 50,000 management interfaces are still...

7-Zip fixes bug that bypasses Windows MoTW security warnings, patch now
2025-01-21 16:05

​A high-severity vulnerability in the 7-Zip file archiver allows attackers to bypass the Mark of the Web (MotW) Windows security feature and execute code on users' computers when extracting...