Internet-connected Peloton fitness equipment is plagued with numerous security issues that could allow attackers to obtain device information or deploy malware, cybersecurity firm Check Point reports. An analysis of the software running on the Peloton Treadmill has revealed exposure to security risks associated with Android devices that are not updated to the most recent platform ..
Tag : Vulnerabilities
Researchers at cloud security firm Wiz have discovered two easily exploitable privilege escalation vulnerabilities in Ubuntu’s OverlayFS module affecting 40% of Ubuntu cloud workloads. OverlayFS is a union filesystem that allows one filesystem to overlay another, enabling file modifications without changing the base. It allows users to copy files from the base to the upper ..
Researchers at cloud security startup Wiz are reporting that a whopping 62 percent of AWS environments may be exposed to the newly documented Zenbleed information leak vulnerability in AMD Zen 2 processors. In a research note posted Wednesday, Wiz calculated that more than 60 percent of AWS environments are running EC2 instances with Zen 2 ..
Cybersecurity firm Fortinet has published details on three critical- and high-severity vulnerabilities patched recently in the Microsoft Message Queuing (MSMQ) service. Two of these flaws, tracked as CVE-2023-21554 and CVE-2023-28302, could lead to remote code execution (RCE) and denial-of-service (DoS) and were addressed by Microsoft with its April 2023 Patch Tuesday updates. No CVE identifier ..
More than 900,000 MikroTik devices are impacted by a RouterOS vulnerability leading to arbitrary code execution, vulnerability intelligence provider VulnCheck reports. Tracked as CVE-2023-30799 (CVSS score of 9.1), the issue is described as a privilege escalation bug impacting RouterOS versions before 6.49.7 and RouterOS long-term versions through 6.48.6. “A remote and authenticated attacker can escalate ..
Five vulnerabilities, two deemed to be critical, have been found in the Terrestrial Trunked Radio (TETRA) standard. TETRA is the most widely used police radio communication system outside of the US. It is used by fire and ambulance services, transportation agencies, utilities, and military, border control and customs agencies in more than 100 nations globally ..
AMD has started releasing microcode patches to address a Zen 2 processor vulnerability that can allow an attacker to access sensitive information. The flaw, dubbed Zenbleed and officially tracked as CVE-2023-20593, was discovered by Google researchers as part of a new CPU research project and reported to AMD on May 15. Google Information Security’s Tavis ..
A new zero-day vulnerability affecting a product of US-based enterprise software provider Ivanti has been exploited in an attack aimed at the Norwegian government. Norwegian authorities announced on Monday that a dozen government ministries had been targeted in a cyberattack involving a previously unknown vulnerability. The country’s National Security Authority later clarified that the attack ..
Apple on Monday pushed out major security-themed updates to its flagship iOS, macOS and iPadOS platforms, warning that at least one of the patched vulnerabilities has already been exploited in the wild. The Cupertino device maker announced patches for critical code execution flaws in iOS and macOS, including a kernel bug that was used in ..
A new exploit technique targeting a recent Citrix Application Delivery Controller (ADC) and Gateway vulnerability can be used against thousands of unpatched devices, cybersecurity firm Bishop Fox claims. Tracked as CVE-2023-3519 and patched last week, the critical-severity bug can be exploited to execute arbitrary code remotely, without authentication, on vulnerable appliances that are configured as ..


