Security News

D-Link urges users to retire VPN routers impacted by unfixed RCE flaw
2024-11-19 17:58

D-Link is warning customers to replace end-of-life VPN router models after a critical unauthenticated, remote code execution vulnerability was discovered that will not be fixed on these devices. [...]

Critical 9.8-rated VMware vCenter RCE bug exploited after patch fumble
2024-11-18 22:29

If you didn't fix this a month ago, your to-do list probably needs a reshuffle Two VMware vCenter server bugs, including a critical heap-overflow vulnerability that leads to remote code execution...

Critical RCE bug in VMware vCenter Server now exploited in attacks
2024-11-18 18:54

​Broadcom warned today that attackers are now exploiting two VMware vCenter Server vulnerabilities, one of which is a critical remote code execution flaw. [...]

Palo Alto Networks warns of critical RCE zero-day exploited in attacks
2024-11-15 14:44

Palo Alto Networks is warning that a critical zero-day vulnerability on Next-Generation Firewalls (NGFW) management interfaces, currently tracked as 'PAN-SA-2024-0015,' is actively being exploited...

CISA Flags Two Actively Exploited Palo Alto Flaws; New RCE Attack Confirmed
2024-11-15 05:04

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday warned that two more flaws impacting the Palo Alto Networks Expedition have come under active exploitation in the wild....

New Flaws in Citrix Virtual Apps Enable RCE Attacks via MSMQ Misconfiguration
2024-11-12 14:01

Cybersecurity researchers have disclosed new security flaws impacting Citrix Virtual Apps and Desktop that could be exploited to achieve unauthenticated remote code execution (RCE) The issue, per...

Palo Alto Advises Securing PAN-OS Interface Amid Potential RCE Threat Concerns
2024-11-09 06:12

Palo Alto Networks on Friday issued an informational advisory urging customers to ensure that access to the PAN-OS management interface is secured because of a potential remote code execution...

Critical Veeam RCE bug now used in Frag ransomware attacks
2024-11-08 20:23

After being used in Akira and Fog ransomware attacks, a critical Veeam Backup & Replication (VBR) security flaw was also recently exploited to deploy Frag ransomware. [...]

Palo Alto Networks warns of potential PAN-OS RCE vulnerability
2024-11-08 17:42

Palo Alto Networks warned customers to restrict access to their next-generation firewalls because of a potential remote code execution vulnerability in the PAN-OS management interface. [...]

HPE warns of critical RCE flaws in Aruba Networking access points
2024-11-07 15:47

Hewlett Packard Enterprise (HPE) released updates for Instant AOS-8 and AOS-10 software to address two critical vulnerabilities in Aruba Networking Access Points. [...]