+44 (0)203 88 020 88

Menu

Search

News

Unpatched Redis Servers Targeted by P2P Malware

A peer-to-peer (P2P) worm known as P2PInfect has been discovered by security researchers at Unit42 to be actively targeting Windows and Linux based Redis servers. Redis is an open-source database application used in cloud environments. This Rust-based worm targets publicly communicating internet-exposed cloud-based servers by exploiting a flaw that is over a year old. There […]

Unpatched Redis Servers Targeted by P2P Malware Read More »

Adobe ColdFusion Attack Chain Actively Exploited

Adobe ColdFusion vulnerabilities are being actively exploited by attackers to bypass authentication and execute remote commands to create a webshell on the vulnerable endpoint. ColdFusion is an Adobe product for web developers providing cloud based coding environments to build apps. Researchers at Rapid7 discovered an improper access control vulnerability in Adobe ColdFusion 2018, 2021, and

Adobe ColdFusion Attack Chain Actively Exploited Read More »

Mastodon Patch High and Critical Vulnerabilities

Open-source social network Mastodon has needed to address one high severity and two critical severity vulnerabilities affecting their platform and servers, as well as one moderate severity flaw. Security advisories released by Mastodon explain that these vulnerabilities were discovered by auditors at Cure53 during a code review they were completing on behalf of Mozilla.   The

Mastodon Patch High and Critical Vulnerabilities Read More »

Android July Update Patches Actively Exploited Flaws

The new Android security update for this month has fixed a total of 46 vulnerabilities, three of which are thought to be actively exploited in what Android describe as “limited, targeted” attacks. Two security patch levels have been released, 2023-07-01, which addresses all issues within this security patch level for the system and framework as

Android July Update Patches Actively Exploited Flaws Read More »

Zero-Day Vulnerability Exploited in WordPress Plugin

A critical zero-day vulnerability has been exploited in the WordPress plugin Ultimate Member that allows attackers to escalate their privileges and gain full control over the website. Ultimate Member is a WordPress plugin that enables users to sign-up, and for the WordPress website to handle memberships and profiles. It currently has over 200,000+ active installations,

Zero-Day Vulnerability Exploited in WordPress Plugin Read More »

Exploit for Critical Auth Bypass Flaw in ArcServe UDP

A critical vulnerability has been discovered in ArcServe Unified Data Protection (UDP) versions 7.0 to 9.0 that can be exploited to bypass authentication on the system. ArcServe UDP is data protection software used for ransomware protection through attack neutralisation, data restoration, and disaster recovery. This authentication bypass vulnerability could result in attackers obtaining admin privileges,

Exploit for Critical Auth Bypass Flaw in ArcServe UDP Read More »

OpenSSH Cryptomining Attacks on Linux and IoTs

Internet-facing Linux-based systems and Internet of Things (IoT) devices are being targeted in a recent attack that uses a patched version of OpenSSH to take over the devices and install cryptomining malware.    Cryptomining involves the solving of complex mathematical problems to verify the payments carried out in cryptocurrency transactions, and creating new cryptocurrency tokens

OpenSSH Cryptomining Attacks on Linux and IoTs Read More »

Apple Fix Exploited Flaws Used to Deploy Spyware

Three actively exploited vulnerabilities have recently been patched by Apple, two of which have been used to deploy Triangulation spyware onto iOS devices. Russian security firm Kaspersky published a report investigating the use of these vulnerabilities in what they have termed ‘Operation Triangulation’ which involves the implant of TriangleDB (Kaspersky’s term) on vulnerable iOS devices.

Apple Fix Exploited Flaws Used to Deploy Spyware Read More »

Grafana Fix Azure AD Authentication Bypass Flaw

Open-source data analytics and visualisations organisation Grafana have released a new security update for their app that patches a critical severity authorisation bypass flaw. This vulnerability affects Grafana accounts that use Azure Active Directory (AD) for account authentication. The new releases include Grafana versions 10.0.1, 9.5.5, 9.4.13, 9.3.16, 9.2.20, and 8.5.27. Other security fixes are

Grafana Fix Azure AD Authentication Bypass Flaw Read More »

0

No products in the basket.

No products in the basket.