Security News

CISA Adds Five-Year-Old jQuery XSS Flaw to Exploited Vulnerabilities List
2025-01-24 05:39

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday placed a now-patched security flaw impacting the popular jQuery JavaScript library to its Known Exploited...

QNAP fixes six Rsync vulnerabilities in NAS backup, recovery app
2025-01-23 18:30

QNAP has fixed six rsync vulnerabilities that could let attackers gain remote code execution on unpatched Network Attached Storage (NAS) devices. [...]

Six vulnerabilities in ubiquitous rsync tool announced and fixed in a day
2025-01-17 15:49

Turns out tool does both file transfers and security fixes fast Don't panic. Yes, there were a bunch of CVEs affecting potentially hundreds of thousands of users found in rsync in early December –...

Critical SimpleHelp vulnerabilities fixed, update your server instances!
2025-01-16 14:50

If you’re an organization using SimpleHelp for your remote IT support/access needs, you should update or patch your server installation without delay, to fix security vulnerabilities that may be...

Critical vulnerabilities remain unresolved due to prioritization gaps
2025-01-16 04:00

Fragmented data from multiple scanners, siloed risk scoring and poor cross-team collaboration are leaving organizations increasingly exposed to breaches, compliance failures and costly penalties,...

SAP fixes critical vulnerabilities in NetWeaver application servers
2025-01-15 22:02

SAP has fixed two critical vulnerabilities affecting NetWeaver web application server that could be exploited to escalate privileges and access restricted information. [...]

Rsync vulnerabilities allow remote code execution on servers, patch quickly!
2025-01-15 14:24

Six vulnerabilities have been fixed in the newest versions of Rsync (v3.4.0), two of which could be exploited by a malicious client to achieve arbitrary code execution on a machine with a running...

Major Vulnerabilities Patched in SonicWall, Palo Alto Expedition, and Aviatrix Controllers
2025-01-09 17:29

Palo Alto Networks has released software patches to address several security flaws in its Expedition migration tool, including a high-severity bug that an authenticated attacker could exploit to...

Mitel MiCollab, Oracle WebLogic Server vulnerabilities exploited by attackers
2025-01-08 12:12

CISA has added Mitel MiCollab (CVE-2024-41713, CVE-2024-55550) and Oracle WebLogic Server (CVE-2020-2883) vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. The Mitel MiCollab...

Moxa Alerts Users to High-Severity Vulnerabilities in Cellular and Secure Routers
2025-01-07 07:44

Taiwan-based Moxa has warned of two security vulnerabilities impacting its cellular routers, secure routers, and network security appliances that could allow privilege escalation and command...