Vulnerabilities
Exploit released for Fortra GoAnywhere MFT auth bypass bug
Exploit code is now available for a critical authentication bypass vulnerability in Fortra’s GoAnywhere MFT (Managed File Transfer) software which allows attackers to ...
Vulnerabilities
Apache ActiveMQ flaw exploited in the Godzilla Web Shell attacks
Cybersecurity researchers are warning of a rise in attacks exploiting a now-patched flaw in Apache ActiveMQ to deliver a malicious code that borrows ...
Vulnerabilities
GitHub rotates keys to mitigate impact of credential-exposing flaw
GitHub has rotated some keys in response to a security vulnerability that could be potentially exploited by attackers to gain access to credentials ...
Vulnerabilities
Ivanti zero-days exploited by multiple actors globally
Two zero-day vulnerabilities in Ivanti products which were revealed last week are being exploited globally, with over 1700 devices already compromised. Volexity stated ...
Vulnerabilities
Ivanti warns critical EPM bug lets hackers hijack enrolled devices
Ivanti recently addressed a critical remote code execution (RCE) vulnerability in its Endpoint Management software (EPM) that can let unauthenticated hackers hijack enrolled ...
Vulnerabilities
50K WordPress sites exposed to RCE attacks
A critical severity vulnerability in a WordPress plugin with over 90,000 installs can let attackers gain remote code execution to fully compromise vulnerable ...
Vulnerabilities
Hackers exploit recent F5 BIG-IP flaws in stealthy attacks
F5 has warned BIG-IP admins that hackers are exploiting two recently disclosed vulnerabilities that impacts BIG-IP and could result in unauthenticated remote code ...
Vulnerabilities
iLeakage flaw can prompt iPhones and Macs to share password and more
A team of researchers has devised a novel side-channel attack dubbed iLeakage which exploits a weakness in the A- and M-series CPUs running ...
Vulnerabilities
Trend Micro patches endpoint protection zero-day used in attacks
Trend Micro patched a remote code execution zero-day vulnerability in the Apex One endpoint protection solution that was actively exploited in the wild. ...
Vulnerabilities
Over 3,000 Openfire servers vulnerable to takeover attacks
Thousands of Openfire servers are vulnerable to CVE-2023-32315, an actively exploited and path traversal vulnerability that allows an unauthenticated user to create new ...




















