As Citrix Urges Its Clients to Patch, Researchers Release an Exploit

October 25, 2023 at 04:08PM A critical security update has been released for the Citrix NetScaler vulnerability, but an exploit is also available. The exploit is simpler to use and allows attackers to read session tokens and gain access to environments. Patching may not be enough as hijacked sessions can persist even after applying patches. … Read more

Pro-Russia group exploits Roundcube zero-day in attacks on European government emails

October 25, 2023 at 12:50PM The Winter Vivern cyber spy group has targeted European governments by exploiting an XSS zero-day vulnerability in the Roundcube webmail client. The group, linked to Russia and Belarus, used a convincing phishing email to launch a malicious payload, allowing them to access victims’ Roundcube accounts. Researchers warn that the group’s … Read more

Citrix Bleed exploit lets hackers hijack NetScaler accounts

October 25, 2023 at 11:30AM A proof-of-concept exploit has been released for the ‘Citrix Bleed’ vulnerability (CVE-2023-4966) allowing attackers to retrieve authentication session cookies from vulnerable Citrix NetScaler ADC and NetScaler Gateway appliances. The vulnerability was previously abused as a zero-day in limited attacks and Citrix has urged administrators to patch the flaw immediately. The … Read more

Nation State Hackers Exploiting Zero-Day in Roundcube Webmail Software

October 25, 2023 at 09:45AM The Winter Vivern threat actor has been using a zero-day vulnerability in Roundcube webmail software to access victim’s email accounts. Winter Vivern has previously targeted Ukraine, Poland, and government entities in Europe and India. The newly discovered vulnerability, CVE-2023-5631, allows for the injection of arbitrary JavaScript code. Attackers employ a … Read more

VMware vCenter Flaw So Critical, Patches Released for End-of-Life Products

October 25, 2023 at 09:21AM Virtualization technology leader VMware has issued an urgent warning about a critical remote code execution flaw in its vCenter Server and VMware Cloud Foundation products. The vulnerability allows attackers with network access to execute remote code. VMware has released patches for the affected products, including older versions. Additionally, a moderate-severity … Read more

Act Now: VMware Releases Patch for Critical vCenter Server RCE Vulnerability

October 25, 2023 at 07:03AM VMware has released security updates to fix a critical flaw in the vCenter Server that could allow remote code execution. The vulnerability, tracked as CVE-2023-34048, is an out-of-bounds write issue in the DCE/RPC protocol. The company has urged users to apply the patches without delay as there are no workarounds … Read more

VMware reveals critical vCenter vuln that you may have patched already without knowing it

October 25, 2023 at 12:33AM VMware has disclosed a critical vulnerability in its vCenter Server, along with a patch to fix it. The vulnerability, known as CVE-2023-34048, allows a malicious actor with network access to trigger an out-of-bounds write and potentially execute remote code. VMware has also released patches for unsupported versions of the software. … Read more

Rockwell Automation Warns Customers of Cisco Zero-Day Affecting Stratix Switches

October 24, 2023 at 03:03PM Rockwell Automation has issued a warning to customers that its Stratix industrial switches are vulnerable to an actively exploited Cisco IOS XE zero-day vulnerability. Hackers have been taking advantage of this vulnerability to create high-privileged accounts and gain complete control of affected devices. Rockwell has confirmed that its Stratix 5800 … Read more

Backdoor Implant on Hacked Cisco Devices Modified to Evade Detection

October 24, 2023 at 05:45AM The threat actor behind the recent Cisco device backdoor attack has modified the implant to avoid detection through previous fingerprinting methods. The attacks exploit zero-day vulnerabilities, allowing the actor to gain access to devices and deploy a Lua-based implant. Cisco is rolling out security updates, but the exact identity of … Read more

Cyberattackers Alter Implant on 30K Compromised Cisco IOS XE Devices

October 23, 2023 at 05:07PM Security researchers have observed a sharp decline in the number of infected Cisco IOS XE systems over the weekend. The reason behind this decline is that the attacker altered the implant, making it no longer visible via previous fingerprinting methods. However, nearly 38,000 devices remain compromised if one knows how … Read more