Tag : Vulnerabilities

image_pdfimage_print

Fortinet warns of a massive spike in exploitation attempts targeting a five-year-old authentication bypass vulnerability in TBK DVR devices. A video surveillance company, TBK Vision provides network CCTV devices, DVRs, and other types of related equipment for protecting industrial and critical infrastructure facilities. The vendor claims it has over 600,000 cameras, 50,000 CCTV recorders, and ..

Leggi tutto

Cisco informed customers this week that it’s working on a patch for a vulnerability found in the company’s Prime Collaboration Deployment product by a member of NATO’s Cyber Security Centre (NCSC). Prime Collaboration Deployment is a tool designed to assist in the management of Unified Communications (UC) applications. The security hole, identified as CVE-2023-20060, is ..

Leggi tutto

The US government is notifying healthcare providers and lab personnel about a component used by several Illumina medical devices being affected by serious vulnerabilities that can allow remote hacking. On Thursday, the Cybersecurity and Infrastructure Security Agency (CISA) and the Food and Drug Administration (FDA) issued public notifications to inform organizations about the vulnerabilities affecting ..

Leggi tutto

Taiwanese network equipment manufacturer Zyxel this week announced patches for a critical-severity vulnerability impacting its ATP, USG FLEX, VPN, and ZyWALL/USG firewalls. Tracked as CVE-2023-28771 (CVSS score of 9.8), the security defect can be exploited remotely to execute OS commands. “Improper error message handling in some firewall versions could allow an unauthenticated attacker to execute ..

Leggi tutto

A Cl0p ransomware operator affiliated with the FIN11 and TA505 threat actors has been exploiting recently patched PaperCut vulnerabilities since April 13, Microsoft says. Impacting the PaperCut MF/NG print management system and tracked as CVE-2023-27350 (CVSS score of 9.8), the issue can be exploited to bypass authentication and achieve remote code execution (RCE) with System ..

Leggi tutto

Russian cybercrime group FIN7 has been observed exploiting unpatched Veeam Backup & Replication instances in recent attacks, cybersecurity company WithSecure reports. Around since at least 2015 and also referred to as Anunak, and Carbanak, FIN7 is a financially motivated group mainly focused on credit card information theft. Security researchers believe there are numerous sub-groups operating ..

Leggi tutto

A high-severity vulnerability in the Service Location Protocol (SLP) can be exploited to launch denial-of-service (DoS) attacks with a high amplification factor, security researchers at Bitsight and Curesec warn. A legacy internet protocol created in 1997, SLP is used for local network service discovery, without prior configuration, and can be scaled from small to large ..

Leggi tutto

Malicious attackers can exploit Apache Superset installations running default configurations to gain administrator access and execute code on servers and databases, penetration testing firm Horizon3.ai warns. An open source application written in Python and based on the Flask web framework, Apache Superset provides users with the ability to explore and visualize large amounts of data. ..

Leggi tutto

VMware this week announced patches for a critical-severity vulnerability in Workstation and Fusion that was disclosed in March 2023 at the Pwn2Own Vancouver hacking contest. Tracked as CVE-2023-20869 (CVSS score of 9.3), the issue was discovered by Star Labs researchers, who earned an $80,000 bug bounty reward for the finding. VMware’s advisory describes the security ..

Leggi tutto

Most Windows and macOS PaperCut installations have not been patched against a critical-severity vulnerability already exploited in attacks, according to a warning from endpoint and response security firm Huntress. The security defect, tracked as CVE-2023-27350 (CVSS 9.8/10), is described as an improper access control bug in the PaperCut MF/NG print management system. Attackers can exploit ..

Leggi tutto