Security News

Critical RCE Vulnerability Found in Apache OFBiz ERP Software—Patch Now
2021-03-22 01:34

The Apache Software Foundation on Friday addressed a high severity vulnerability in Apache OFBiz that could have allowed an unauthenticated adversary to remotely seize control of the open-source enterprise resource planning system. Tracked as CVE-2021-26295, the flaw affects all versions of the software prior to 17.12.06 and employs an "Unsafe deserialization" as an attack vector to permit unauthorized remote attackers to execute arbitrary code on a server directly.

Critical F5 BIG-IP vulnerability now targeted in ongoing attacks
2021-03-19 17:09

On Thursday, cybersecurity firm NCC Group said that it detected successful in the wild exploitation of a recently patched critical vulnerability in F5 BIG-IP and BIG-IQ networking devices. The security vulnerability these attackers attempt to exploit is an unauthenticated remote command execution tracked as CVE-2021-22986, and it affects most F5 BIG-IP and BIG-IQ software versions.

Vulnerability Management Firm Vulcan Cyber Raises $21 Million
2021-03-17 14:40

Vulnerability remediation orchestration provider Vulcan Cyber today announced that it has raised $21 million in Series B funding. The new funding, Vulcan Cyber says, will help it expand its platform with new vulnerability remediation solutions for both cloud and applications, as well as meet demand for its SaaS solution.

Vulnerability That Allows Complete WordPress Site Takeover Exploited in the Wild
2021-03-09 15:31

A critical vulnerability identified in The Plus Addons for Elementor WordPress plugin could be exploited to gain administrative privileges to a website. With more than 30,000 installations to date, The Plus Addons for Elementor is a premium plugin that has been designed to add several widgets to be used with the popular WordPress website builder Elementor.

Tufin releases Vulnerability-Based Change Automation App
2021-03-08 01:00

The new app expands Tufin's vulnerability management capabilities with automated vulnerability checks prior to approving network access changes. When combined with the Vulnerability Mitigation App, Tufin delivers a vulnerability management solution that allows customers to maintain additional control over their attack surface when making network changes.

VMware releases fix for severe View Planner RCE vulnerability
2021-03-04 17:09

VMware has addressed a high severity unauthenticated RCE vulnerability in VMware View Planner, allowing attackers to abuse servers running unpatched software for remote code execution. The vulnerability was discovered and reported to VMware by Positive Technologies web application security expert Mikhail Klyuchnikov.

Several Cisco Products Exposed to DoS Attacks Due to Snort Vulnerability
2021-03-04 13:46

Cisco informed customers on Wednesday that several of its products are exposed to denial-of-service attacks due to a vulnerability in the Snort detection engine. Cisco says the vulnerability is in the Ethernet Frame Decoder component of Snort.

Microsoft Pays $50,000 Bounty for Account Takeover Vulnerability
2021-03-04 04:45

A security researcher says Microsoft has awarded him a $50,000 bounty reward for reporting a vulnerability that could have potentially allowed for the takeover of any Microsoft account. The attack, the researcher explains, targets the password recovery process that Microsoft has in place, which typically requires the user to enter their email or phone number to receive a security code, and then enter that code.

VMware Patches Remote Code Execution Vulnerability in View Planner
2021-03-03 15:23

VMware this week announced the availability of a security patch for VMware View Planner, to address a vulnerability leading to remote code execution. With the release of View Planner 4.6 Security Patch 1 on March 2, VMware fixes CVE-2021-21978, an issue that could allow an attacker to execute code remotely.

Chrome 89 Patches Actively Exploited Vulnerability
2021-03-03 13:22

Google this week announced the availability of Chrome 89 in the stable channel, with patches for a total of 47 vulnerabilities, including one that has been exploited in the wild. Tracked as CVE-2021-21166, the zero-day security hole is described as a high-severity "Object lifecycle issue in audio." The bug was reported by Alison Huffman of Microsoft Browser Vulnerability Research, and is the second of this type addressed in Chrome 89, alongside CVE-2021-21165, also rated high risk.