Tag : Vulnerabilities

image_pdfimage_print

A researcher has published a proof-of-concept (PoC) tool that exploits an unpatched KeePass vulnerability to retrieve the master password from the program’s memory. An open source password manager primarily designed for Windows, KeePass can also be used on macOS and Linux, through the open source .NET-compatible framework Mono. Tracked as CVE-2023-32784, the issue impacts KeePass ..

Leggi tutto

Cisco this week announced patches for critical-severity vulnerabilities in multiple small business switches and warned that proof-of-concept (PoC) code that targets them exists publicly. Identified in the web-based user interface of the impacted switches, the flaws can be exploited remotely, without authentication, to execute arbitrary code with root privileges. The root cause of these issues, ..

Leggi tutto

Researchers at industrial cybersecurity companies Otorio and Claroty have teamed up to conduct a detailed analysis of products made by Teltonika and found potentially serious vulnerabilities that can expose many organizations to remote hacker attacks. Teltonika Networks is a Lithuania-based company that makes LTE routers, gateways, modems and other networking solutions that are used worldwide ..

Leggi tutto

Threat actors were seen adopting public proof-of-concept (PoC) exploit code targeting a cross-site scripting (XSS) vulnerability in the Advanced Custom Fields WordPress plugin only two days after a patch was released, Akamai reports. Tracked as CVE-2023-30777, the high-severity vulnerability could allow attackers to inject malicious scripts and other payloads into vulnerable websites. The code would ..

Leggi tutto

The US Cybersecurity and Infrastructure Security Agency (CISA) has added several Linux and Linux-related flaws to its known exploited vulnerabilities (KEV) catalog. The agency added seven new vulnerabilities to its KEV catalog on Friday: Ruckus AP remote code execution (CVE-2023-25717), Red Hat Polkit privilege escalation (CVE-2021-3560), Linux kernel privilege escalations (CVE-2014-0196 and CVE-2010-3904), Jenkins UI ..

Leggi tutto

A vulnerability discovered in the official website of luxury sports car maker Ferrari could have exposed potentially sensitive information, according to a cybersecurity firm. The issue was discovered in March by researchers at Char49, a company that provides penetration testing, auditing and training services. Ferrari addressed the weakness within a week. The researchers noticed that ..

Leggi tutto

Exploitation of a critical vulnerability in the Essential Addons for Elementor WordPress plugin began immediately after a patch was released, WordPress security firm Defiant warns. With over one million installations, the Essential Addons for Elementor plugin provides additional elements and extensions for the Elementor website building platform. Tracked as CVE-2023-32243 (CVSS score of 9.8), the ..

Leggi tutto

Industrial and IoT cybersecurity firm Claroty on Thursday disclosed the details of five vulnerabilities that can be chained in an exploit potentially allowing threat actors to hack certain Netgear routers. The vulnerabilities were first presented at the 2022 Pwn2Own Toronto hacking competition, where white hat hackers earned a total of nearly $1 million for exploits ..

Leggi tutto

Microsoft this week released patches for a severe vulnerability that bypassed mitigations rolled out for a no-interaction Outlook zero-day leading to credential theft. Tracked as CVE-2023-29324, the bug was addressed in the Windows MSHTML component as part of the May 2023 Patch Tuesday updates. The vulnerability was discovered by Akamai security researcher Ben Barnea as ..

Leggi tutto