VMware Alert: Uninstall EAP Now – Critical Flaw Puts Active Directory at Risk

February 21, 2024 at 01:15AM VMware has reported critical security flaws in the Enhanced Authentication Plugin (EAP), urging users to uninstall it. The vulnerability enables a malicious actor to manipulate service tickets and hijack sessions. Additionally, SonarSource disclosed cross-site scripting flaws in Joomla!. Salesforce’s Apex programming language also faces high-severity vulnerabilities. Users are advised to … Read more

Crucial Airline Flight Planning App Open to Interception Risks

February 6, 2024 at 03:09PM Airbus-owned IT services company NAVBLUE’s Flysmart+ Manager app, used by airline pilots for crucial flight planning, had a disabled App Transport Security feature, making it vulnerable to attacks. Pen Test Partners discovered the issue, which could lead to unsafe takeoff and landing. The exploit was deemed difficult to execute but … Read more

Airbus App Vulnerability Introduced Aircraft Safety Risk: Security Firm

February 5, 2024 at 06:06PM Pen Test Partners discovered a security issue in the Flysmart+ suite of applications for pilot electronic flight bags developed by Airbus-owned Navblue. The iOS app had an important security feature disabled, making it vulnerable to potential attacks, which could have resulted in severe consequences for aircraft safety. Airbus confirmed the … Read more