June 19, 2024 | Cybernews
VMware has patched critical vulnerabilities in its vSphere and Cloud Foundation products, including heap-overflow flaws in the DCE/RPC protocol and a local privilege escalation issue in vCenter, with fixes released by Broadcom.
June 18, 2024 | Cybernews
ASUS releases urgent firmware updates for multiple router models to address critical security vulnerabilities, including authentication bypass and buffer overflow flaws.
June 13, 2024 | Cybernews
Chinese threat actors exploit zero-day vulnerability in Fortinet’s FortiOS and FortiProxy software, deploying Coathanger RAT malware on over 14,000 devices, including government systems in the Netherlands.
June 12, 2024 | Cybernews
Arm and NVIDIA have identified zero-day vulnerabilities in their products, including a serious out-of-bounds write error in NVIDIA’s GPU Display Driver, prompting customers to patch their systems promptly to prevent unauthorized access and data breaches.
April 30, 2024 | Cybernews
Judge0, a widely used open-source service for secure sandboxed code execution, has been found to have critical vulnerabilities that could allow attackers to execute sandbox escapes and gain root access to host machines.
April 18, 2024 | Cybernews
Ivanti has issued a security advisory for its Avalanche mobile device management (MDM) product, urging users to update to the latest version, Avalanche 643, to address critical vulnerabilities, including heap overflow bugs that could potentially allow arbitrary command execution.
March 11, 2024 | Cybernews
Attackers are actively exploiting the CVE-2023-22527 vulnerability in Atlassian Confluence Data Center and Confluence Server, using in-memory payloads to execute arbitrary code and control compromised servers.
February 15, 2024 | Cybernews
The APT group Water Hydra has exploited a zero-day vulnerability, CVE-202421412, to target crypto traders with spearphishing techniques and deploy the DarkMe malware.
February 7, 2024 | Cybernews
Orca security firm discovers three vulnerabilities in Microsoft Azure’s HDInsight big-data analytics service, including denial-of-service and privilege escalation bugs, which have been promptly addressed by Microsoft.
February 1, 2024 | Cybernews
A heap-based buffer overflow vulnerability in the GNU C library (glibc) has been found, enabling unauthorized users to gain root access.