Security News

Critical Zimbra RCE flaw exploited to backdoor servers using emails
2024-10-02 14:15

Hackers are actively exploiting a recently disclosed RCE vulnerability in Zimbra email servers that can be triggered simply by sending specially crafted emails to the SMTP server. [...]

Critical Zimbra RCE vulnerability under mass exploitation (CVE-2024-45519)
2024-10-02 11:05

Attackers are actively exploiting CVE-2024-45519, a critical Zimbra vulnerability that allows them to execute arbitrary commands on vulnerable installations. Proofpoint’s threat researchers say...

'Patch yesterday': Zimbra mail servers under siege through RCE vuln
2024-10-02 10:50

Attacks began the day after public disclosure "Patch yesterday" is the advice from infosec researchers as the latest critical vulnerability affecting Zimbra mail servers is now being mass-exploited.…

Arc browser launches bug bounty program after fixing RCE bug
2024-10-01 22:33

The Browser Company has introduced an Arc Bug Bounty Program to encourage security researchers to report vulnerabilities to the project and receive rewards. [...]

CUPS vulnerabilities affecting Linux, Unix systems can lead to RCE
2024-09-27 10:17

After much hyping and following prematurely leaked information by a third party, security researcher Simone Margaritelli has released details about four zero-day vulnerabilities in the Common UNIX...

Broadcom fixes critical RCE bug in VMware vCenter Server
2024-09-17 19:57

Broadcom has fixed a critical VMware vCenter Server vulnerability that attackers can exploit to gain remote code execution on unpatched servers via a network packet. [...]

SolarWinds Issues Patch for Critical ARM Vulnerability Enabling RCE Attacks
2024-09-17 04:34

SolarWinds has released fixes to address two security flaws in its Access Rights Manager (ARM) software, including a critical vulnerability that could result in remote code execution. The...

Exploit code released for critical Ivanti RCE flaw, patch now
2024-09-16 19:08

A proof-of-concept (PoC) exploit for CVE-2024-29847, a critical remote code execution (RCE) vulnerability in Ivanti Endpoint Manager, is now publicly released, making it crucial to update devices. [...]

D-Link fixes critical RCE, hardcoded password flaws in WiFi 6 routers
2024-09-16 14:24

D-Link has fixed critical vulnerabilities in three popular wireless router models that allow remote attackers to execute arbitrary code or access the devices using hardcoded credentials. [...]

Week in review: Veeam Backup & Replication RCE could soon be exploited, Microsoft fixes 4 0-days
2024-09-15 08:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Veeam Backup & Replication RCE flaw may soon be leveraged by ransomware gangs (CVE-2024-40711)...