Tag : Vulnerabilities

image_pdfimage_print

Fortinet on Tuesday announced security updates that address a critical-severity vulnerability in FortiOS and FortiProxy that could be exploited for remote code execution (RCE). Tracked as CVE-2023-33308 (CVSS score of 9.8), the bug is described as a stack-based overflow issue impacting the deep inspection function in proxy mode. “A stack-based overflow vulnerability in FortiOS & ..

Leggi tutto

Russian spies and cybercriminals are actively exploiting still-unpatched security flaws in Microsoft Windows and Office products, according to an urgent warning from the world’s largest software maker. In an unusual move, Microsoft documented “a series of remote code execution vulnerabilities” impacting Windows and Office users and confirmed it was investigating multiple reports of targeted code ..

Leggi tutto

Software maker Adobe on Tuesday called attention to critical security flaws in its InDesign and ColdFusion products, warning that the defects expose users to malicious hacker attacks. The company’s scheduled July Patch Tuesday rollout includes fixes for a dozen documented vulnerabilities in Adobe InDesign, including a bug serious enough to lead to arbitrary code execution ..

Leggi tutto

Virtualization technology giant VMware on Monday warned that exploit code has been publicly released for a pre-authentication remote code execution flaw in its enterprise-facing VMware Aria Operations for Logs product. In an update to a critical-level advisory originally released in April this year, VMware said it has confirmed that exploit code for CVE-2023-20864 has been ..

Leggi tutto

A recently patched vulnerability in Ubiquiti EdgeRouter and AirCube devices could be exploited to execute arbitrary code, vulnerability reporting firm SSD Secure Disclosure warns. Tracked as CVE-2023-31998, the issue is described as a heap overflow vulnerability that can be exploited over a LAN connection. According to Ubiquiti, an attacker exploiting this bug may interrupt UPnP ..

Leggi tutto

A critical vulnerability in the decentralized social networking platform Mastodon could be exploited to take over servers. The issue was disclosed last week, when Mastodon announced patches for five vulnerabilities in the open source software, including two rated ‘critical’. The most important of these is CVE-2023-36460 (CVSS score of 9.9), an arbitrary file creation issue ..

Leggi tutto

Faced with a barrage of ransomware attacks hitting zero-days in its MOVEit product line, Progress Software late Thursday announced plans to release regular service sacks promising a “predictable, simple and transparent process for product and security fixes.” Less than a month after the notorious Cl0p ransomware gang started naming organizations hit by MOVEit zero-day exploits, ..

Leggi tutto

SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under the radar. We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape. Each week, we will curate and present ..

Leggi tutto