Adobe on Friday announced patches for a critical-severity vulnerability in ColdFusion that could be exploited to achieve arbitrary code execution. Tracked as CVE-2023-38203 (CVSS score of 9.8), the flaw is described as “deserialization of untrusted data” in ColdFusion versions 2023, 2021 and 2018. This typically allows an attacker to supply specially crafted data and trigger the ..
Tag : Vulnerabilities
A remotely-exploitable critical vulnerability in the Cisco SD-WAN vManage software could allow unauthenticated attackers to retrieve information from vulnerable instances. Tracked as CVE-2023-20214 (CVSS score of 9.1), the vulnerability exists because the REST API feature of vManage does not sufficiently validate requests. The vManage API allows administrators to configure, control, and monitor Cisco devices over ..
Several instances of the Reddit alternative Lemmy were hacked in recent days by attackers who had apparently exploited a zero-day vulnerability. Lemmy is an open source software designed for running self-hosted news aggregation and discussion forums. Each Lemmy instance is run by a different individual or organization, but they are interconnected, allowing users from one ..
Google security researchers have discovered a Zimbra zero-day vulnerability that has been exploited in the wild. Users are being advised to manually patch their installations. Exploitation of the zero-day affecting the popular email and collaboration solution was discovered by Clement Lecigne from Google’s Threat Analysis Group (TAG). A security update that includes a patch for ..
Research into the widely used QuickBlox SDK and API led to the discovery of critical vulnerabilities built into chat and video applications used by industries including telemedicine, smart IoT, and finance. The researchers from Claroty Team82 and Check Point Research (CPR) developed PoC exploits demonstrating that these vulnerabilities threatened the personal information of millions of ..
The All-In-One Security (AIOS) WordPress plugin was found to be logging plaintext passwords from login attempts. Installed on more than one million WordPress sites, the security and firewall plugin was designed to prevent cyberattacks such as brute-force attempts, warn when the default admin username is used for login, prevent bot attacks, log user activity, and ..
An unnamed advanced persistent threat (APT) group has set its sights on two Rockwell Automation product vulnerabilities that they could use to cause disruption or destruction in critical infrastructure organizations. According to its advisory (only accessible to registered users), Rockwell has worked with the US government to analyze what it describes as a new exploit ..
Multiple hardcoded credentials found on the Technicolor TG670 DSL gateway router allow attackers to completely take over devices, the CERT Coordination Center (CERT/CC) warns. A broadband router for small offices and home offices, the Technicolor TG670 router allows administrators to authenticate over HTTP, SSH, or Telnet. With the remote management functionality enabled, users gain complete ..
The application of artificial intelligence is still in its infancy, but we are already seeing one major effect: the democratization of hacking. The annual Bugcrowd report, Inside the Mind of a Hacker 2023, examines the attitudes held and methods used by the Bugcrowd pool of bug hunters. This year, the report focuses on the effect ..
Citrix on Tuesday announced the release of patches for a critical-severity vulnerability in the Secure Access client for Ubuntu that could be exploited to achieve remote code execution (RCE). According to Citrix’s advisory, however, exploitation of the issue, which is tracked as CVE-2023-24492 (CVSS score of 9.6), requires user interaction. “A vulnerability has been discovered ..


