Security News

BeyondTrust fixes critical vulnerability in remote access, support solutions (CVE-2024-12356)
2024-12-18 09:39

BeyondTrust has fixed an unauthenticated command injection vulnerability (CVE-2024-12356) in its Privileged Remote Access (PRA) and Remote Support (RS) products that may allow remote code...

BeyondTrust Issues Urgent Patch for Critical Vulnerability in PRA and RS Products
2024-12-18 09:15

BeyondTrust has disclosed details of a critical security flaw in Privileged Remote Access (PRA) and Remote Support (RS) products that could potentially lead to the execution of arbitrary commands....

Critical OpenWrt Vulnerability Exposes Devices to Malicious Firmware Injection
2024-12-13 16:48

A security flaw has been disclosed in OpenWrt's Attended Sysupgrade (ASU) feature that, if successfully exploited, could have been abused to distribute malicious firmware packages. The...

Patch Tuesday: Microsoft Patches One Actively Exploited Vulnerability, Among Others
2024-12-11 20:57

December marked a quiet month with 70 vulnerabilities patched, plus updates from outside of Microsoft.

Microsoft Fixes 72 Flaws, Including Patch for Actively Exploited CLFS Vulnerability
2024-12-11 07:16

Microsoft closed out its Patch Tuesday updates for 2024 with fixes for a total of 72 security flaws spanning its software portfolio, including one that it said has been exploited in the wild. Of...

Ivanti warns of maximum severity CSA auth bypass vulnerability
2024-12-10 19:40

Ivanti warned customers on Tuesday about a new maximum-severity authentication bypass vulnerability in its Cloud Services Appliance (CSA) solution. [...]

Cleo File Transfer Vulnerability Under Exploitation – Patch Pending, Mitigation Urged
2024-12-10 15:57

Users of Cleo-managed file transfer software are being urged to ensure that their instances are not exposed to the internet following reports of mass exploitation of a vulnerability affecting...

Want to Grow Vulnerability Management into Exposure Management? Start Here!
2024-12-05 12:46

Vulnerability Management (VM) has long been a cornerstone of organizational cybersecurity. Nearly as old as the discipline of cybersecurity itself, it aims to help organizations identify and...

PoC exploit for critical WhatsUp Gold RCE vulnerability released (CVE-2024-8785)
2024-12-04 11:16

Researchers have published a proof-of-concept (PoC) exploit for CVE-2024-8785, a critical remote code execution vulnerability affecting Progress WhatsUp Gold, a popular network monitoring solution...

Veeam Issues Patch for Critical RCE Vulnerability in Service Provider Console
2024-12-04 05:34

Veeam has released security updates to address a critical flaw impacting Service Provider Console (VSPC) that could pave the way for remote code execution on susceptible instances. The...