Security News

Samsung MagicINFO 9 Server RCE flaw now exploited in attacks
2025-05-06 17:10

Hackers are exploiting an unauthenticated remote code execution (RCE) vulnerability in the Samsung MagicINFO 9 Server to hijack devices and deploy malware. [...]

Critical Langflow RCE flaw exploited to hack AI app servers
2025-05-06 16:05

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has tagged a Langflow remote code execution vulnerability as actively exploited, urging organizations to apply security updates and...

Microsoft: Windows Server hotpatching to require subscription
2025-04-29 19:47

Microsoft has announced that it will soon introduce paid subscriptions for Windows Server 2025 hotpatching, a service that enables admins to install security updates without restarting. [...]

Hitachi Vantara takes servers offline after Akira ransomware attack
2025-04-28 19:39

Hitachi Vantara, a subsidiary of Japanese multinational conglomerate Hitachi, was forced to take servers offline over the weekend to contain an Akira ransomware attack. [...]

Over 1,200 SAP NetWeaver servers vulnerable to actively exploited flaw
2025-04-28 16:46

Over 1,200 internet-exposed SAP NetWeaver instances are vulnerable to an actively exploited maximum severity unauthenticated file upload vulnerability that allows attackers to hijack servers. [...]

Hackers Exploit Critical Craft CMS Flaws; Hundreds of Servers Likely Compromised
2025-04-28 07:13

Threat actors have been observed exploiting two newly disclosed critical security flaws in Craft CMS in zero-day attacks to breach servers and gain unauthorized access. The attacks, first observed...

Microsoft pitches pay-to-patch reboot reduction subscription for Windows Server 2025
2025-04-28 06:37

Redmond reckons $1.50/core/month hotpatch service is worth it to avoid eight Patch Tuesday scrambles each year Microsoft has announced that its preview of hotpatching for on-prem Windows Server...

Oh, cool. Microsoft melts bug that froze Server 2025 Remote Desktop sessions
2025-04-25 18:00

Where have we heard this before? Feb security update needs its own fix More than one month after complaints starting flying, Microsoft has fixed a Windows bug that caused some Remote Desktop...

Researchers Identify Rack::Static Vulnerability Enabling Data Breaches in Ruby Servers
2025-04-25 08:57

Cybersecurity researchers have disclosed three security flaws in the Rack Ruby web server interface that, if successfully exploited, could enable attackers to gain unauthorized access to files,...

ASUS releases fix for AMI bug that lets hackers brick servers
2025-04-23 14:50

ASUS has released security updates to address CVE-2024-54085, a maximum severity flaw that could allow attackers to hijack and potentially brick servers. [...]