Ivanti warns of another critical CSA flaw exploited in attacks

September 19, 2024 at 02:45PM Ivanti warns of ongoing exploitation of a Cloud Services Appliance (CSA) vulnerability, CVE-2024-8963, allowing remote attackers to access restricted functions. Attackers also exploit CVE-2024-8190 to bypass admin authentication and execute arbitrary commands. Ivanti advises immediate patching and emphasizes the end-of-life status of Ivanti CSA 4.6. Federal agencies are mandated to … Read more

GitLab Patches Critical SAML Authentication Bypass Flaw in CE and EE Editions

September 19, 2024 at 01:36AM GitLab released patches to address a critical flaw in both Community and Enterprise Editions, rooted in the ruby-saml library, allowing an authentication bypass. The vulnerability affects single sign-on security, prompting the update of dependencies and urging self-managed installations to enable two-factor authentication as a mitigation. Threat indicators suggest active exploitation … Read more

Patch Issued for Critical VMware vCenter Flaw Allowing Remote Code Execution

September 18, 2024 at 01:57AM Broadcom released updates to fix a critical security flaw in VMware vCenter Server, allowing possible remote code execution. Two similar flaws were also addressed, as well as a privilege escalation flaw. The flaws were discovered during a cybersecurity competition in June 2024 and have been fixed in various versions. Customers … Read more

WhatsApp fix to make View Once chats actually disappear is beaten in less than a week

September 17, 2024 at 08:24PM Meta’s attempt to prevent unauthorized access to WhatsApp’s View Once messages was circumvented by white-hat hackers within a week. The feature, designed to ensure message privacy, relied on digital rights management but was found to be vulnerable on certain operating systems. Despite Meta’s initial fix, security concerns remain unresolved. Based … Read more

Ivanti Warns of Active Exploitation of Newly Patched Cloud Appliance Vulnerability

September 14, 2024 at 12:39AM Ivanti disclosed an actively exploited high-severity vulnerability (CVE-2024-8190) in its Cloud Service Appliance, impacting version 4.6, prompting customers to upgrade to version 5.0. The company noted confirmed exploitation in the wild targeting a limited number of customers and urged federal agencies to apply fixes by October 4, 2024. Additionally, a … Read more

Ivanti fixes maximum severity RCE bug in Endpoint Management software

September 10, 2024 at 03:37PM Ivanti has patched a critical vulnerability (CVE-2024-29847) in its Endpoint Management software that could allow unauthenticated attackers to execute remote code on the core server. The company has also addressed almost two dozen other high and critical severity flaws in its products. Ivanti has seen a rise in fixed flaws … Read more

Microsoft fixes Windows Smart App Control zero-day exploited since 2018

September 10, 2024 at 02:15PM Microsoft has resolved a zero-day exploit in Windows Smart App Control and SmartScreen, labeled as CVE-2024-38217, that threat actors have been exploiting since at least 2018. The vulnerability allowed them to bypass security features and launch untrusted files. Elastic Security Labs has detected and reported the flaw, and Microsoft is … Read more

Critical Security Flaw Found in LiteSpeed Cache Plugin for WordPress

September 6, 2024 at 03:27AM A critical security flaw (CVE-2024-44000) has been found in LiteSpeed Cache plugin for WordPress, affecting versions up to 6.4.1. Unauthenticated users could take control of arbitrary accounts. The vulnerability, resolved in version 6.5.0.1, stems from a publicly exposed debug log file. Users are urged to check for the file and … Read more

New Eucleak attack lets threat actors clone YubiKey FIDO keys

September 4, 2024 at 01:59PM A new “EUCLEAK” flaw affects FIDO devices, such as Yubico’s YubiKey 5 Series, using the Infineon SLE78 microcontroller, allowing attackers to extract Elliptic Curve Digital Signature Algorithm (ECDSA) secret keys. The attack requires extended physical access and specialized equipment, limiting the risk to highly sophisticated, state-sponsored threat actors against high-value … Read more

Zyxel Patches Critical OS Command Injection Flaw in Access Points and Routers

September 4, 2024 at 08:31AM Zyxel has released software updates to address a critical security flaw (CVE-2024-7261) affecting some access points and security routers, along with updates for seven other vulnerabilities. The flaws could result in unauthorized command execution, denial-of-service, or access to browser-based information. D-Link has announced that certain security vulnerabilities will not be … Read more