+44 (0)203 88 020 88

Menu

Search

Vulnerabilities

SonicWall and Cisco patch critical vulnerabilities

This week both SonicWall and Cisco have released patches for critical vulnerabilities in their networking products. SonicWall zero day The SonicWall vulnerability (CVE-2021-20016) is a zero-day under active attack – in fact it was used to breach SonicWall’s own network in January according to their security advisory.  The flaw affects SonicWall SMA 100 series devices

SonicWall and Cisco patch critical vulnerabilities Read More »

Microsoft Patches Critical Bugs

Microsoft starts the year with their first patch Tuesday bundle of security fixes targeting 10 Critical vulnerabilities include a zero-day being exploited in Windows Defender. The Windows Defender vulnerability (CVE-2021-1647) is reported by Microsoft as having been detected under active exploitation in the wild – but precious little context information is provided under the firm’s

Microsoft Patches Critical Bugs Read More »

100000 Zyxel firewalls have hardcoded backdoor exposed

Taiwan based Zyxel Networks has issued patches for their enterprise grade firewalls after a hard coded credential vulnerability was discovered by security researchers.  The vulnerability provides attackers with root level access over SSH or the Web Administration interface allowing firewall rules to be changed to permit easy access to the network behind the firewall. Zyxel

100000 Zyxel firewalls have hardcoded backdoor exposed Read More »

SolarWinds hack sends chills through security industry

SolarWinds provides tools used by security and network managers in many of the largest businesses and governments in the world.  Since March 2020 hackers inserted their own code into SolarWinds Orion software which was downloaded by some 18,000 customers – providing a backdoor into those customers’ networks. SolarWinds Orion is a network health and performance

SolarWinds hack sends chills through security industry Read More »

Drupal vulnerability affects a million sites

A vulnerability in the Drupal web content management system can be exploited to allow arbitrary code execution, affecting almost a million websites. A security advisory from Drupal describes how this critical vulnerability can be exploited to perform arbitrary execution of PHP code.  Security patches are available for Drupal versions 7, 8 and 9. The problem

Drupal vulnerability affects a million sites Read More »

Hackers target Oracle WebLogic vulnerability

Oracle patched a vulnerability in their WebLogic server in October 2020 – eight days later working exploit code was published online and now it is being used by criminals. CVE-2020-14882 allows an attacker to perform a Remote Code Execution attack with minimal effort or skill required.  Juniper Networks security researchers reports at least five different

Hackers target Oracle WebLogic vulnerability Read More »

VMWare warns of critical zero-day vulnerability

VMWare has issued a security advisory warning of a command injection vulnerability that could allow someone with access to the VMWare Configurator admin account to issue command with unrestricted privileges on the underlying operating system. The vulnerability (CVE-2020-4006) affects VMWare Workspace One Access, Access Connector, Identity Manage and Identify Manager Connector administrative configurator.  A malicious

VMWare warns of critical zero-day vulnerability Read More »

0

No products in the basket.

No products in the basket.