Security researchers discovered recently that the online travel agency Booking.com was impacted by serious vulnerabilities that could have been exploited to take complete control of a user’s account. The issues were identified by API security firm Salt Security and reported to Booking.com in early December 2022. Patches were rolled out in the next few weeks ..
Tag : Vulnerabilities
Cisco this week announced software updates that address a critical vulnerability in the web-based management interface of its 6800, 7800, and 8800 series IP phones. Tracked as CVE-2023-20078 (CVSS score of 9.8), the issue can be exploited by an unauthenticated, remote attacker to execute code with root privileges. The security defect, Cisco explains in its ..
Endor Labs has introduced an OWASP-style listing of the most important or impactful risks inherent in the use of open source software (OSS). Use of OSS is effectively free and readily available – it satisfies the commercial need for speed at low cost in software development. It is not uncommon for more than 80% of ..
Security researchers at Quarkslab have identified a pair of serious security defects in the Trusted Platform Module (TPM) 2.0 reference library specification, prompting a massive cross-vendor effort to identify and patch vulnerable installations. The vulnerabilities, tracked as CVE-2023-1017 and CVE-2023-1018, provide pathways for an authenticated, local attacker to overwrite protected data in the TPM firmware ..
In 2022, the widespread exploitation of new vulnerabilities was down 15% over the previous year; zero-day attacks declined 52% from 2021; and there were 33% fewer vulnerabilities known to have been exploited as part of a ransomware attack. On the surface, it might appear that things were easier for security teams last year. That would ..
A critical vulnerability affecting the Houzez premium WordPress theme has been exploited in the wild, WordPress security company Patchstack warned on Monday. Houzez is a premium theme for the real estate industry, with more than 35,000 sales on ThemeForest. It allows agencies to easily manage content and listings. Patchstack CTO Dave Jong discovered recently that ..
Cisco on Wednesday informed customers about the availability of patches for two high-severity vulnerabilities affecting components of its Application Centric Infrastructure (ACI) software-defined networking solution. One of these flaws, CVE-2023-20011, impacts the management interface of the Cisco Application Policy Infrastructure Controller (APIC) and Cloud Network Controller. APIC is the unified point of automation and management ..
In-the-wild exploitation of a Fortinet FortiNAC vulnerability tracked as CVE-2022-39952 was seen just days after a patch was announced, and on the same day a proof-of-concept (PoC) exploit was made public. Fortinet published 40 security advisories on February 16, including one describing a critical vulnerability in the company’s FortiNAC network access control (NAC) solution. The ..
Intel has paid out more than $4.1 million through its bug bounty program since its creation in 2017, according to a product security report published by the chip giant on Wednesday. Between 2018 and 2021, Intel paid out, on average, $800,000 through its bug bounty program each year for vulnerabilities discovered in the company’s products. ..
Google paid out a total of $12 million through its bug bounty programs in 2022. This includes a $605,000 payout that represents the company’s highest reward ever. More than 700 researchers from 68 countries were rewarded in 2022 for helping Google make its products and services more secure, roughly the same as in 2021. However, ..


