Skip to Content

The US Cybersecurity and Infrastructure Security Agency (CISA) has added two privilege elevation vulnerabilities – one in Microsoft Exchange Server and one in Windows – to its Known Exploited Vulnerabilities (KDEV) Catalog. US Federal Civilian Executive Branch Agencies have until January 31 to mitigate the flaws. Note CVE-2022-41080 – an Exchange privilege escalation flaw from …

Read More about CISA Adds Two Flaws to Known Exploited Vulnerabilities Catalog

Cisco has published an advisory alerting users to vulnerabilities in some of its small business routers. The flaws, an authentication bypass vulnerability and a remote commend execution vulnerability, affect Cisco Small Business RV016, RV042, RV042G, and RV082 routers. Cisco will not release updates to address the flaws. Note Cisco last sold these devices in 2016. …

Read More about Cisco Advisory Warns of Vulnerabilities in Small Business Routers

An architectural vulnerability in more than 100 models of Siemens SIMATIC and SIPLUS S7-1500 programmable logic controllers (PLCs) could be exploited to install firmware and bypass all protected boot features. Because of the nature of the flaw, it cannot be fixed with a software patch. Siemens notes that exploiting the flaw requires physical access to …

Read More about Critical Architectural Vulnerabilities in Siemens PLC

Fortinet says that an unknown threat actor exploited a critical flaw in its FortiOS SSL-VPN to infect systems at government and government-related organizations. Fortinet released a fix for the heap-based buffer overflow vulnerability (CVE-2022-42475) late last year. FortiOS SSL-VPN version 7.2.8 was released at the end of November; Fortinet published an advisory on December 12. …

Read More about Fortinet FortiOS SSL-VPN Flaw Was Exploited to Infect Government Systems

Hackers are exploiting a known critical vulnerability in the Web Control Panel web hosting interface. The unauthenticated remote code execution flaw was patched in October 2022; users are urged to update to version 0.9.8.1147 or later. Note This is an attack on “CentOS Web Panel,” which is a very analogous project to the classic “Webmin” …

Read More about Critical Control Web Panel Vulnerability is Being Actively Exploited

On Tuesday, January 10, Microsoft released fixes for nearly 100 vulnerabilities. One of the flaws, a privilege elevation vulnerability in Windows Advanced Local Procedure Call (ALPC), is being actively exploited. The vulnerability could lead to a browser sandbox escape and be exploited to gain system privileges. Eleven of the vulnerabilities are deemed critical; the others …

Read More about Microsoft Patch Tuesday: January 2023

Updated on 2023-01-09: Hitachi Energy Vulnerabilities The US Cybersecurity and Infrastructure Security Agency (CISA) has published three Industrial Control System (ICS) advisories regarding vulnerabilities in Hitachi Energy products. The flaws affect Hitachi Energy UNEM, Hitachi Energy FOXMAN-UN, and Hitachi Energy Lumada Asset Performance Management. Hitachi has addressed the vulnerabilities and urges users to update to …

Read More about Hitachi Energy Vulnerabilities

Updated on 2023-01-09: Security Flaws Affect Millions of Cars Researchers have detected security bugs affecting vehicles from 16 companies in the automotive industry. The flaws could be exploited to lock and unlock cars, to start and stop engines, take over accounts, execute code remotely, and track the location of vehicles, and conduct other troublesome activity. …

Read More about API Vulnerabilities Security Flaws Affect Millions of Cars

In December, Auth0 released an updated version of JsonWebToken open source library to address a remote code execution vulnerability. The flaw was detected by researchers at Palo Alto Networks Unit 42; they reported the issue to Auth0 in July. Users are urged to update to JsonWebToken version 9.0.0 or newer. Note Interesting vulnerability, in particular …

Read More about JsonWebToken Secret Poisoning Vulnerability Has Been Patched

Updated on 2023-01-05: New WordPress backdoor Dr.Web researchers have found a new exploit tool designed to attack WordPress sites, infect them with a backdoor, and then inject malicious scripts in their codebase. The malware targets vulnerabilities in more than 30 WordPress themes and plugins and exclusively targets Linux-based servers. Read more: Linux backdoor malware infects …

Read More about Linux Malware Exploits Backdoor Flaws in Multiple WordPress Plug-ins

Updated on 2022-12-30 The US Cybersecurity and Infrastructure Security Agency (CISA) has added two JasperReports vulnerabilities to its known exploited vulnerabilities catalog: CVE-2018-5430 (CVSS score: 7.7) and CVE-2018-18809 (CVSS score: 9.9). The flaws were disclosed in 2018; fixes are available for both flaws. CISA says it has become aware that the vulnerabilities – an information …

Read More about CISA Adds JasperReports Flaws from 2018 to Known Exploited Vulnerabilities Catalog

National Cyber Awareness System CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA Releases Three Industrial Systems Control Advisories Fortinet Releases Security Updates for FortiADC Ubuntu Security Notices USN-5794-1: Linux kernel (AWS) vulnerabilities USN-5793-1: Linux kernel vulnerabilities USN-5792-1: Linux kernel vulnerabilities USN-5791-1: Linux kernel vulnerabilities USN-5790-1: Linux kernel vulnerabilities USN-5789-1: Linux kernel (OEM) vulnerabilities USN-5788-1: …

Read More about Security Advisories Notices Update on 2023-01-10

Updated on 2022-12-22: macOS Gatekeeper bypass Microsoft has published a write-up on another macOS Gatekeeper bypass found by its MSTIC team. I don’t know how I feel about Microsoft’s security teams sifting through Apple’s products when their Exchange servers keep getting ransomed left and right. Read more: Gatekeeper’s Achilles heel: Unearthing a macOS vulnerability Overview: …

Read More about macOS Gatekeeper bypass

The US Cybersecurity and Infrastructure Security Agency (CISA) has published three advisories regarding vulnerabilities in Rockwell Automation controllers. Rockwell has released updates to address two of the vulnerabilities: an improper access control issue in Rockwell Automation Studio 5000 Logix Emulate and an improper input validation issue in Rockwell Automation GuardLogix and ControlLogix controllers. Rockwell has …

Read More about Vulnerabilities in Rockwell Automation Controllers
Ads Blocker Image Powered by Code Help Pro

Your Support Matters...

We run an independent site that is committed to delivering valuable content, but it comes with its challenges. Many of our readers use ad blockers, causing our advertising revenue to decline. Unlike some websites, we have not implemented paywalls to restrict access. Your support can make a significant difference. If you find this website useful and choose to support us, it would greatly secure our future. We appreciate your help. If you are currently using an ad blocker, please consider disabling it for our site. Thank you for your understanding and support.