Tag : Vulnerabilities

image_pdfimage_print

Google this week announced the release of Chrome 112 in the stable channel with patches for 16 vulnerabilities, including 14 reported by external researchers. Of the externally reported flaws, two are rated ‘high severity’, nine have a severity rating of ‘medium’, while the remaining three are low-severity issues. The most severe of these is a ..

Leggi tutto

Google this week announced the April 2023 security updates for Android devices, with patches for over 65 vulnerabilities, including two critical bugs leading to remote code execution (RCE). Google’s Android security bulletin for April 2023 describes 26 vulnerabilities resolved in the Framework and System components as part of the 2023-04-01 security patch level. Most of ..

Leggi tutto

The US Cybersecurity and Infrastructure Security Agency (CISA) has added to its ‘Must Patch’ list a Zimbra vulnerability exploited by Russian hackers in attacks targeting NATO countries. The flaw, tracked as CVE-2022-27926 (CVSS score of 6.1), is described as a reflected cross-site scripting (XSS) bug in Zimbra Collaboration version 9.0. Because of this issue, an ..

Leggi tutto

A severe vulnerability in the Elementor Pro plugin is being exploited to hack WordPress websites, WordPress security company Patchstack warns. Described as a broken access control issue, the flaw can be exploited on vulnerable websites with the WooCommerce plugin installed to change any WordPress setting. An attacker would need to be authenticated as a low-privileged ..

Leggi tutto

A water pumping system made by ProPump and Controls is affected by several vulnerabilities that could allow hackers to cause significant problems.  The impacted product is the Osprey Pump Controller made by US-based ProPump and Controls, a company that specializes in pumping systems and automated controls for a wide range of applications, including golf courses ..

Leggi tutto

A misconfiguration in Azure Active Directory (AAD) that exposed applications to unauthorized access could have led to a Bing.com takeover, according to cybersecurity firm Wiz. Microsoft’s AAD, a cloud-based identity and access management (IAM) service, is typically used as the authentication mechanism for Azure App Services and Azure Functions applications. The service supports different types ..

Leggi tutto