A Chinese cyberespionage group tracked as UNC3886 has been observed exploiting a VMware ESXi zero-day vulnerability to escalate privileges on guest virtual machines, Mandiant warns. Initially detailed in September 2022, UNC3886 has been using malicious vSphere Installation Bundles (VIBs) – packages that are typically used to maintain systems and deploy updates – to install backdoors ..
Tag : Vulnerabilities
Today we find ourselves using cloud native technologies to increase flexibility, scaling and cost savings in many respects. The modern cloud stack using IaaS, abstracts the hardware maintenance component away and you are left with everything above such as the operating system and software. Golden images have been a simple concept used in practice for ..
Progress Software has released another round of patches for its MOVEit products after researchers discovered new vulnerabilities while analyzing the recent zero-day. The news comes just as more organizations hit by the zero-day attack have come forward. The zero-day affecting the MOVEit Transfer and Cloud managed file transfer (MFT) software, tracked as CVE-2023-34362 and described ..
Fortinet has patched a critical FortiGate vulnerability that can be exploited by an unauthenticated attacker for remote code execution, according to the researchers who reported the flaw to the vendor. The vulnerability is tracked as CVE-2023-27997 and it was discovered by researchers at French offensive IT security firm Lexfo. Charles Fol, one of the researchers, ..
Newly uncovered evidence suggests that cybercriminals have known about the recently patched MOVEit Transfer zero-day vulnerability since mid-2021. The zero-day affecting the managed file transfer (MFT) software, tracked as CVE-2023-34362, started being widely exploited on or around May 27. The product’s developer, Progress Software, alerted customers on May 31, but at least 100 organizations have ..
A researcher has disclosed the details of serious vulnerabilities discovered in a Honda ecommerce platform used for equipment sales. Exploitation of the flaws could have allowed an attacker to gain access to customer and dealer information. The security holes and the data exposure were discovered earlier this year by US-based researcher Eaton Zveare, who notified ..
Cisco on Wednesday announced patches for a critical vulnerability in its Expressway series and TelePresence Video Communication Server (VCS) enterprise collaboration and video communication solutions. Tracked as CVE-2023-20105 (CVSS score of 9.6), the vulnerability allows an administrator with ‘read-only’ rights to elevate their privileges to ‘read-write’. The issue exists because password change requests are not ..
Open source password manager KeePass was updated over the weekend to patch a vulnerability allowing attackers to retrieve the cleartext master password from a memory dump. Tracked as CVE-2023-32784 and impacting KeePass 2.x versions, the issue is related to the custom-developed textbox used for password entry, which creates a leftover string in memory for each ..
Google on Monday released a Chrome 114 security update that patches the third zero-day vulnerability found in the web browser in 2023. Google said the latest version of Chrome patches two flaws, including CVE-2023-3079, a type confusion issue affecting the V8 JavaScript engine. The internet giant noted that the vulnerability, discovered on June 1, has ..
Taiwan-based networking device manufacturer Zyxel is urging customers to update the firmware of ATP, USG Flex, VPN, and ZyWALL/USG firewall devices, to prevent the exploitation of recently patched vulnerabilities. Tracked as CVE-2023-28771, CVE-2023-33009 and CVE-2023-33010, the issues can lead to OS command execution, remote code execution (RCE), and denial-of-service (DoS). The first of the issues ..


