Security News

New Windows Server 2012 zero-day gets free, unofficial patches
2024-11-29 17:00

Free unofficial security patches have been released through the 0patch platform to address a zero-day vulnerability introduced over two years ago in the Windows Mark of the Web (MotW) security...

Hackers exploit ProjectSend flaw to backdoor exposed servers
2024-11-27 21:00

Threat actors are using public exploits for a critical authentication bypass flaw in ProjectSend to upload webshells and gain remote access to servers. [...]

Critical Flaw in ProjectSend Under Active Exploitation Against Public-Facing Servers
2024-11-27 16:05

A critical security flaw impacting the ProjectSend open-source file-sharing application has likely come under active exploitation in the wild, according to findings from VulnCheck. The...

New NachoVPN attack uses rogue VPN servers to install malicious updates
2024-11-26 22:30

A set of vulnerabilities dubbed "NachoVPN" allows rogue VPN servers to install malicious updates when unpatched Palo Alto and SonicWall SSL-VPN clients connect to them. [...]

'Alarming' bugs lay low in Ubuntu Server utility for 10 years
2024-11-21 15:03

Update now: Qualys says vulnerabilities give root and are 'easily exploitable' Researchers at Qualys refuse to release exploit code for five bugs in Ubuntu Server's needrestart utility that allow...

Critical RCE bug in VMware vCenter Server now exploited in attacks
2024-11-18 18:54

​Broadcom warned today that attackers are now exploiting two VMware vCenter Server vulnerabilities, one of which is a critical remote code execution flaw. [...]

Microsoft fixes bugs causing Windows Server 2025 blue screens, install issues
2024-11-12 23:35

​Microsoft has fixed several bugs that cause install, upgrade, and Blue Screen of Death (BSOD) issues on Windows Server 2025 devices with a high core count. [...]

Microsoft blames Windows Server 2025 automatic upgrades on 3rd-party tools
2024-11-11 16:36

Microsoft has finally confirmed that some Windows Server 2019 and 2022 systems were "unexpectedly" upgraded to Windows Server 2025 on devices if updates were managed using third-party patch...

Security Flaws in Popular ML Toolkits Enable Server Hijacks, Privilege Escalation
2024-11-11 10:11

Cybersecurity researchers have uncovered nearly two dozen security flaws spanning 15 different machine learning (ML) related open-source projects. These comprise vulnerabilities discovered both on...

November 2024 Patch Tuesday forecast: New servers arrive early
2024-11-11 06:00

Microsoft followed their October precedent set with Windows 11 24H2 and announced Microsoft Server 2025 on the first of November. We were expecting the official announcement at Microsoft Ignite...