Security News

Man charged with stealing $65 million by exploting DeFI protocols vulnerabilities
2025-02-04 10:13

A Canadian man has been indicted in federal court in New York for exploiting vulnerabilities in two decentralized finance (DeFi) protocols to fraudulently obtain about $65 million from the...

SimpleHelp RMM vulnerabilities may have been exploited to breach healthcare orgs
2025-01-30 15:13

Attackers may have leveraged vulnerabilities in the SimpleHelp remote monitoring and management solution to gain initial access to healthcare organizations. About the vulnerabilities On January...

CISA Adds Five-Year-Old jQuery XSS Flaw to Exploited Vulnerabilities List
2025-01-24 05:39

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday placed a now-patched security flaw impacting the popular jQuery JavaScript library to its Known Exploited...

QNAP fixes six Rsync vulnerabilities in NAS backup, recovery app
2025-01-23 18:30

QNAP has fixed six rsync vulnerabilities that could let attackers gain remote code execution on unpatched Network Attached Storage (NAS) devices. [...]

Six vulnerabilities in ubiquitous rsync tool announced and fixed in a day
2025-01-17 15:49

Turns out tool does both file transfers and security fixes fast Don't panic. Yes, there were a bunch of CVEs affecting potentially hundreds of thousands of users found in rsync in early December –...

Critical SimpleHelp vulnerabilities fixed, update your server instances!
2025-01-16 14:50

If you’re an organization using SimpleHelp for your remote IT support/access needs, you should update or patch your server installation without delay, to fix security vulnerabilities that may be...

Critical vulnerabilities remain unresolved due to prioritization gaps
2025-01-16 04:00

Fragmented data from multiple scanners, siloed risk scoring and poor cross-team collaboration are leaving organizations increasingly exposed to breaches, compliance failures and costly penalties,...

SAP fixes critical vulnerabilities in NetWeaver application servers
2025-01-15 22:02

SAP has fixed two critical vulnerabilities affecting NetWeaver web application server that could be exploited to escalate privileges and access restricted information. [...]

Rsync vulnerabilities allow remote code execution on servers, patch quickly!
2025-01-15 14:24

Six vulnerabilities have been fixed in the newest versions of Rsync (v3.4.0), two of which could be exploited by a malicious client to achieve arbitrary code execution on a machine with a running...

Major Vulnerabilities Patched in SonicWall, Palo Alto Expedition, and Aviatrix Controllers
2025-01-09 17:29

Palo Alto Networks has released software patches to address several security flaws in its Expedition migration tool, including a high-severity bug that an authenticated attacker could exploit to...