Category: Uncategorized
-
Citrix Warns NetScaler ADC Customers of New Zero-Day Exploitation Eduard Kovacs
Citrix is aware of attacks exploiting two new NetScaler ADC and Gateway zero-day vulnerabilities tracked as CVE-2023-6548 and CVE-2023-6549. The post Citrix Warns NetScaler ADC Customers of New Zero-Day Exploitation appeared first on SecurityWeek. Read More
-

GitHub Rotates Keys After High-Severity Vulnerability Exposes Credentials [email protected] (The Hacker News)
GitHub has revealed that it has rotated some keys in response to a security vulnerability that could be potentially exploited to gain access to credentials within a production container. The Microsoft-owned subsidiary said it was made aware of the problem on December 26, 2023, and that it addressed the issue the same day, in addition…
-

Citrix, VMware, and Atlassian Hit with Critical Flaws — Patch ASAP! [email protected] (The Hacker News)
Citrix is warning of two zero-day security vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that are being actively exploited in the wild. The flaws are listed below – CVE-2023-6548 (CVSS score: 5.5) – Authenticated (low privileged) remote code execution on Management Interface (requires access to NSIP, CLIP, or SNIP…
-

Zero-Day Alert: Update Chrome Now to Fix New Actively Exploited Vulnerability [email protected] (The Hacker News)
Google on Tuesday released updates to fix four security issues in its Chrome browser, including an actively exploited zero-day flaw. The issue, tracked as CVE-2024-0519, concerns an out-of-bounds memory access in the V8 JavaScript and WebAssembly engine, which can be weaponized by threat actors to trigger a crash. “By reading out-of-bounds memory, an attacker might…
-
How to create a CSIRT: 10 best practices
Post ContentRead More
-
Google Warns of Chrome Browser Zero-Day Being Exploited Ryan Naraine
The exploited zero-day, tagged as CVE-2024-0519, is described as an out-of-bounds memory access issue in the V8 JavaScript engine. The post Google Warns of Chrome Browser Zero-Day Being Exploited appeared first on SecurityWeek. Read More
-
Adobe ColdFusion Access Control Bypass Attack
FortiGuards labs observed critical level of exploitation attempts relating to security bypass vulnerabilities in Adobe ColdFusion. Successful exploitation could result in access of the ColdFusion Administrator endpoints.Read More
-
Ho, Ho, Hoooold on a Minute: A New Year Resolution That IoT Isn’t a Gift That Keeps on Taking Tom Eston
Some IoT products may make your life easier, but they also may be somewhat of a Trojan Horse. The post Ho, Ho, Hoooold on a Minute: A New Year Resolution That IoT Isn’t a Gift That Keeps on Taking appeared first on SecurityWeek. Read More
-
Vulnerabilities Expose PAX Payment Terminals to Hacking Ionut Arghire
Vulnerabilities in Android-based PoS terminals from PAX can be exploited to downgrade bootloaders, execute arbitrary code. The post Vulnerabilities Expose PAX Payment Terminals to Hacking appeared first on SecurityWeek. Read More
-
Ivanti zero-day flaws under ‘widespread’ exploitation
Post ContentRead More
