A cybersecurity firm has disclosed the details of critical SAP vulnerabilities, including a wormable exploit chain, that can expose organizations to attacks. The vulnerabilities were reported to the enterprise software giant by Fabian Hagg, researcher at SEC Consult, an Austria-based cybersecurity consulting firm that is part of the Atos Group’s Eviden business. Hagg found the ..
Tag : Vulnerabilities
Proof-of-concept (PoC) code targeting a high-severity authentication bypass vulnerability in the Arcserve Unified Data Protection (UDP) backup software was published one day after patches were released earlier this week. Tracked as CVE-2023-26258, the security defect was identified in the web management interface of Arcserve UDP. Successful exploitation of the bug could allow an attacker to ..
Google this week announced a new Chrome 114 update that patches a total of four vulnerabilities, including three high-severity bugs reported by external researchers. The internet giant says it paid out a total of $35,000 in bug bounty rewards to the reporting researchers. The highest payout went to GitHub Security Lab researcher Man Yue Mo, ..
Fortinet has released patches to address a critical vulnerability in its FortiNAC network access control solution. The zero trust access solution allows organizations to view devices and users on the network and provides granular control over network access policies. Tracked as CVE-2023-33299 (CVSS score of 9.6), the critical flaw is described as an issue related ..
The Internet Systems Consortium (ISC) has released patches for three remotely exploitable denial-of-service (DoS) vulnerabilities in the DNS software suite BIND. Tracked as CVE-2023-2828, CVE-2023-2829 and CVE-2023-2911, these high-severity issues could be exploited to exhaust the available memory, or could cause named – BIND’s daemon that functions both as a recursive resolver and as an ..
The National Security Agency (NSA) has published technical mitigation guidance to help organizations harden systems against BlackLotus UEFI bootkit infections. The NSA’s recommendations provide a blueprint for defenders to protect systems from BlackLotus, a stealthy malware that emerged on underground forums in late 2022 with capabilities that include user access control (UAC) and secure boot ..
The US government’s cybersecurity agency CISA on Thursday added another batch of security flaws to its Known Exploited Vulnerabilities (KEV) catalog and urged federal agencies to patch these issues as a matter of urgency. The already exploited vulnerabilities affect users of the open-source Roundcube webmail server and VMware Aria Operations for Networks. Exploitation of the ..
Virtualization giant VMware has published software updates to address multiple memory corruption vulnerabilities in vCenter Server that could lead to remote code execution. A total of five security defects were patched in the software’s implementation of the DCERPC protocol, including four that VMware flags as ‘important’, with a CVSS score of 8.1. Two of these ..
A security researcher has published proof-of-concept (PoC) code targeting a recently patched high-severity vulnerability in the Cisco AnyConnect Secure Mobility Client and Secure Client for Windows. The software allows remote employees to connect to an organization’s network using a secure virtual private network (VPN) and provides monitoring capabilities. Tracked as CVE-2023-20178 (CVSS score of 7.8), ..
Exploit trends help reveal the areas that cybercriminals are actively investigating for potential attacks and what they’re currently targeting. New intelligence allows CISOs to prioritize risk mitigation and reduce the active attack surface with an expanded “Red Zone” approach. Entering the Red Zone When FortiGuard Labs researchers looked at data from the second half of ..


