Industrial routers made by Chinese company Yifan are affected by several critical vulnerabilities that can expose organizations to attacks, Cisco’s Talos threat intelligence and research group reported on Wednesday. The vendor was notified in late June and given more than 90 days to release patches. However, no fixes appear to have been released and Cisco ..
Tag : Vulnerabilities
The maintainers of the cURL data transfer project on Wednesday rolled out patches for a severe memory corruption vulnerability that exposes millions of enterprise OSes, applications and devices to malicious hacker attacks. According to an high-risk bulletin, the flaw poses a direct threat to the SOCKS5 proxy handshake process in cURL and can be exploited ..
Citrix on Tuesday announced patches for a critical-several vulnerability impacting multiple versions of NetScaler Application Delivery Controller (ADC) and NetScaler Gateway. Tracked as CVE-2023-4966 (CVSS score of 9.4), the security defect could lead to sensitive information disclosure, the tech giant notes in an advisory. According to Citrix, the issue can be exploited without authentication on ..
Google on Tuesday announced the release of Chrome 118 to the stable channel with fixes for 20 vulnerabilities, including 14 reported by external researchers. The most severe of the externally reported flaws is CVE-2023-5218, a critical bug described as a use-after-free issue in Site Isolation, Chrome’s component responsible for preventing sites from stealing other sites’ ..
Major tech companies and other organizations have rushed to respond to the newly disclosed HTTP/2 zero-day vulnerability that has been exploited to launch the largest distributed denial-of-service (DDoS) attacks seen to date. The existence of the attack method, named HTTP/2 Rapid Reset, and the underlying vulnerability, tracked as CVE-2023-44487, were disclosed on Tuesday by Cloudflare, ..
The US cybersecurity agency CISA on Tuesday announced that it has added five more security defects to its Known Exploited Vulnerabilities catalog, warning organizations of attacks exploiting an Adobe Acrobat and Reader flaw that came to light earlier this year. The Adobe Acrobat and Reader issue is CVE-2023-21608, a use-after-free vulnerability which can be exploited ..
Researchers at Microsoft say a known nation-state threat actor is behind the zero-day exploits hitting Atlassian’s Confluence Data Center and Server products. A note from Redmond linked the ongoing attacks to an APT group tracked as Storm-0062 and warned that malicious activity dates back to September 14, a full three weeks before Atlassian’s public disclosure ..
Software maker Adobe on Tuesday released fixes for at least 13 security vulnerabilities in multiple product lines, warning that critical flaws in Adobe Commerce and Photoshop will require immediate attention. As part of its scheduled batch of Patch Tuesday updates, Adobe documented at least 10 serious flaws in Adobe Commerce and Magento Open Source, a product line ..
German software maker SAP this week announced the release of seven new and two updated security notes as part of its October 2023 Security Patch Day. The most severe of the security notes brings an update to the Chromium browser in SAP Business Client, which contains 37 fixes, including two critical- and 20 high-severity vulnerabilities. ..
GitHub’s Security Lab has warned Linux users about a serious remote code execution vulnerability affecting a component of the popular GNOME desktop environment. The flaw was found in Libcue, a library designed for parsing ‘cue’ files, which describe how the tracks on a CD are laid out. Libcue is used by a search engine called ..


