‘Mass exploitation’ of Citrix Bleed underway as ransomware crews pile in

October 31, 2023 at 04:48PM The critical information-disclosure bug known as Citrix Bleed is being heavily exploited. Over 5,000 vulnerable servers have been identified on the public internet. Even after patching the flaw, session tokens can still be used. Multiple ransomware gangs are involved in the mass exploitation, and the vulnerability is being targeted across … Read more

It’s 2023 and Microsoft WordPad can be exploited to hijack vulnerable systems

October 10, 2023 at 07:58PM Microsoft has released over 100 security updates, including fixes for two bugs that are already being actively exploited. One of the vulnerabilities, known as Rapid Reset, is an HTTP/2 weakness that has been used since August to launch distributed denial of service (DDoS) attacks. Microsoft WordPad also has an information … Read more