+44 (0)203 88 020 88

Vulnerabilities

WinRAR Remote Code Execution Flaw Patched

A high severity vulnerability has been found in RARLAB’s popular Windows file archiver WinRAR. Security researchers at the Zero Day Initiative who first identified this vulnerability in June have published a security advisory about this flaw now that an update has been issued by the vendor. This vulnerability has the possibility of allowing remote, unauthenticated …

WinRAR Remote Code Execution Flaw Patched Read More »

Stack-Based Buffer Overflows in Ivanti Avalanche

Multiple stack-based buffer overflows have been identified in Ivanti Avalanche, tracked as a single vulnerability with a critical severity rating and CVSS base score of 9.8/10. Ivanti Avalanche is an enterprise mobility management (EMM) solution used by organisations to manage and monitor mobile devices securely. Researchers at Tenable discovered and investigated these flaws, publishing an …

Stack-Based Buffer Overflows in Ivanti Avalanche Read More »

LinkedIn Accounts Hijacked By Cyber Criminals

LinkedIn accounts have been targeted by attackers in hacking events that have led to users being locked out of their own accounts by LinkedIn, and unable to recover them through LinkedIn support. The cyber criminals conducting these account takeover attacks have pressured their victims into paying ransoms to recover their accounts under the threat of …

LinkedIn Accounts Hijacked By Cyber Criminals Read More »

Malware Attacks Target Zyxel End-Of-Life Routers

A five-year-old vulnerability is currently being exploited in Zyxel P660HN-T1A routers to introduce a Gafgyt malware variant onto target networks. An outbreak alert has been issued by Fortinet to inform users that this end-of-life router running versions before 7.3.15.0 v001/ 3.40 (ULM.0)b31 is being actively targeted in the wild. Zyxel published a security advisory back …

Malware Attacks Target Zyxel End-Of-Life Routers Read More »

Actively Exploited Office RCE Attack Chain Patched

A Defense-In-Depth Office update has been released by Microsoft as a part of the Patch Tuesday updates made available this week to fix an actively exploited remote code execution (RCE) flaw. This vulnerability was first identified last month, when it was confirmed to be actively exploited and publicly disclosed. At the time of discovery, it …

Actively Exploited Office RCE Attack Chain Patched Read More »

PaperCut Flaw Allows RCE on Windows Servers

A critical severity flaw in PaperCut NG and PaperCut MF print management applications that can allow unauthenticated attackers to perform remote code execution (RCE) on vulnerable Windows servers. Any use of the affected PaperCut software prior to version 22.1.3 on Windows that is exposed to the internet is vulnerable to exploitation. For the best security, …

PaperCut Flaw Allows RCE on Windows Servers Read More »

Canon Printers Retain Wi-Fi Information After Wipe

Canon Inkjet printers have been found to retain sensitive Wi-Fi information after the usual wipe that is performed in the initialisation process. Canon have released a security advisory to warn their customers that information that can be used to connect to previously connected Wi-Fi is kept within the memory of the Wi-Fi connection settings, and …

Canon Printers Retain Wi-Fi Information After Wipe Read More »

Ivanti Patch Actively Exploited EPMM Zero-Day Flaw

An actively exploited vulnerability has been patched in that latest updates for Ivanti Endpoint Manager Mobile (EPMM), previously known as MobileIron Core. This zero-day flaw affects all supported versions of this mobile device management software, as well as some older release versions before EPMM 11.8.1.0 that are no longer managed by the developers. Ivanti have …

Ivanti Patch Actively Exploited EPMM Zero-Day Flaw Read More »

Unpatched Redis Servers Targeted by P2P Malware

A peer-to-peer (P2P) worm known as P2PInfect has been discovered by security researchers at Unit42 to be actively targeting Windows and Linux based Redis servers. Redis is an open-source database application used in cloud environments. This Rust-based worm targets publicly communicating internet-exposed cloud-based servers by exploiting a flaw that is over a year old. There …

Unpatched Redis Servers Targeted by P2P Malware Read More »

Scroll to Top