Ubiquiti has issued urgent security updates to address seven vulnerabilities in its UniFi OS, including a particularly severe flaw that could allow attackers to execute command injection attacks. This vulnerability is critical because it gives unauthorized users a way to run malicious commands on affected systems. The issue affects various Ubiquiti products that utilize UniFi OS, which is widely used in network management. Users and organizations that rely on these devices should prioritize applying the latest patches to protect their networks. Failure to update could leave systems exposed to potential attacks, putting sensitive data at risk.
Articles tagged "Update"
Found 419 articles
Siemens has identified multiple vulnerabilities in its SINEC OS, particularly affecting the RUGGEDCOM RST2428P product. The issues stem from improper input validation, leading to potential allocation failures that could compromise system operations. Siemens has recommended users upgrade to version 4.0 or later to mitigate these risks. The vulnerabilities have been assigned CVE identifiers, indicating their recognition in the cybersecurity community. This situation is significant as it affects industrial control systems, which are critical for operational integrity and security.
CISA has added a new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, specifically CVE-2026-48282, which affects Adobe ColdFusion. This path traversal vulnerability allows attackers to gain unauthorized access and control over affected systems, posing significant risks, particularly to federal agencies. The Binding Operational Directive (BOD) 26-04 emphasizes the need for federal agencies to address high-risk vulnerabilities quickly, while also encouraging all organizations to adopt similar risk-based vulnerability management practices. CISA will continue to update the catalog as new vulnerabilities are identified, and organizations are urged to report any exploited vulnerabilities not currently listed. Rapid remediation is essential to mitigate potential exploitation risks.
Siemens Mendix Studio Pro has a significant security vulnerability that affects multiple versions of the software, specifically those before version 11.12. This flaw allows attackers to execute arbitrary code by tricking users into opening malicious project files during the build process. The affected versions include Mendix Studio Pro 10.11 through 10.24, as well as 11.0 through 11.9. Siemens has released updates to address this issue, urging users to upgrade to version 10.24.21 or later, or version 11.6.7 or later. This vulnerability poses a serious risk, particularly in critical sectors like manufacturing and energy, making timely updates essential to protect user systems from potential exploits.
Labcenter Electronics' Proteus 9 software has been found to have several critical vulnerabilities, including out-of-bounds write, stack-based buffer overflow, and use-after-free issues. These vulnerabilities could allow attackers to execute arbitrary code on affected installations, potentially compromising sensitive systems in various sectors like healthcare, energy, and defense. Specifically, version 9.1_SP4_Build_42914 is affected, and users are urged to upgrade to the latest version, 9.2 SPO, to protect against these risks. While there are currently no known public exploits actively targeting these vulnerabilities, the potential for abuse remains concerning. It’s crucial for organizations to apply the recommended updates and implement security measures to safeguard their systems.
Hitachi Energy has identified a buffer overflow vulnerability in specific versions of its e-mesh EMS product, which could lead to application outages and potential arbitrary code execution. The affected versions include e-mesh EMS 4.1.6, 4.4.2, and 4.7.0, which utilize NGINX versions 1.30.0 and below. Attackers could exploit this vulnerability by sending specially crafted HTTP requests under certain conditions, particularly if the system's Address Space Layout Randomization (ASLR) is disabled. Users are advised to apply a hotfix to update NGINX to version 1.30.2 or later and ensure ASLR is active. This vulnerability poses a significant risk to critical infrastructure sectors like energy, as it could lead to denial of service and operational disruptions.
SCM feed for Latest
Researchers have identified seven vulnerabilities in the FatFs library, which is commonly used in the firmware of various devices such as security cameras, drones, and industrial controllers. These vulnerabilities can be exploited through malformed USB drives, SD cards, or firmware updates, putting many devices at risk. This is concerning because it could allow attackers to execute arbitrary code or manipulate device functions. Users of affected devices should be aware of this issue, as it could lead to unauthorized access or control over their equipment. Manufacturers need to address these vulnerabilities promptly to safeguard their products and customers.
BleepingComputer
Opera has launched a new feature called Paste Protect aimed at preventing ClickFix-style attacks. These attacks use social engineering techniques to deceive users into executing harmful commands, often through clipboard manipulation. With Paste Protect, Opera seeks to enhance user security by blocking such malicious actions before they can take effect. This update affects all users of the Opera browser, as it aims to create a safer browsing experience by addressing a growing concern in online security. Implementing this feature is crucial as it helps safeguard users from increasingly sophisticated attacks that exploit human behavior.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a vulnerability in Microsoft SharePoint that is currently being exploited by attackers. This vulnerability, identified as CVE-2026-45659, allows for remote code execution, which means that hackers can run malicious code on affected systems. Organizations using SharePoint should take this threat seriously, as it could lead to unauthorized access and data breaches. Microsoft has already released a patch to address this issue, so it's crucial for users to apply the update as soon as possible to protect their systems from potential exploitation.
SCM feed for Latest
The Ousaban banking trojan is targeting users in Spain and Portugal through a new phishing campaign. This campaign begins with a deceptive PDF file that appears to be corrupted, luring users to click an 'Update' button. Once activated, the trojan can compromise personal banking information, posing significant risks to individuals' finances. This type of attack demonstrates a shift towards more stealthy methods, making it harder for users to recognize the threat. As phishing techniques continue to evolve, it's crucial for users to remain vigilant and skeptical of unexpected prompts, especially those urging software updates.
Citrix has released a security update addressing six vulnerabilities in its NetScaler product line, with a particular focus on one high-severity flaw that bears a resemblance to the previously exploited CitrixBleed issue. This flaw could potentially allow attackers to exploit the system if left unpatched. Organizations using affected versions of NetScaler should prioritize applying these patches to safeguard their systems from possible exploitation. The timely response is crucial, especially given the history of similar vulnerabilities being actively targeted by cybercriminals. Users and administrators are encouraged to check their systems and ensure they are running the latest versions to mitigate any risks associated with this flaw.
WhatsApp has introduced a new feature that allows users to create usernames, enabling them to keep their phone numbers private from individuals who are not in their contact lists. This update aims to enhance user privacy, particularly in conversations with strangers or in group chats. With this change, users can interact without revealing their phone numbers, which can help reduce the risk of unwanted contacts and potential harassment. The rollout of usernames is a significant step for WhatsApp, as it aligns with growing demands for better privacy measures in messaging apps. Users should consider adopting this feature to enhance their security and maintain greater control over their personal information.
Curl has released an update addressing 18 vulnerabilities, including a significant bug that has existed since 2001. The oldest vulnerability, tracked as CVE-2026-8932, was identified through AI-assisted analysis and is related to versions of Curl dating back to March 2001. This update is crucial for users of Curl, which is widely used in various applications for transferring data. The vulnerabilities could potentially allow unauthorized access or manipulation of data, making it essential for developers and system administrators to apply the latest patches. Users are encouraged to update their Curl installations to ensure they are protected against these security issues.
All CISA Advisories
The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have issued a new warning about Russian Intelligence Services (RIS) targeting commercial messaging applications through phishing campaigns. This update comes from a previous alert released in March 2026 and details the latest tactics used by these cybercriminals, along with examples of phishing messages they employ. Users of popular messaging platforms are particularly at risk, as attackers seek to exploit vulnerabilities in these widely used applications. The warning emphasizes the importance of being cautious and implementing security measures to protect against these ongoing threats. As phishing attacks continue to evolve, it is crucial for users and organizations to stay informed and vigilant to safeguard their communications and sensitive information.
The Federal Communications Commission (FCC) has approved new cybersecurity regulations aimed at enhancing the security of national emergency systems and the review processes for undersea cable providers. These rules are designed to prevent potential hijacking of emergency systems, which could lead to significant public safety risks. Additionally, the updated security measures for undersea cables are crucial, as these cables are vital for global communications and can be targets for cyber attacks. The changes reflect a growing recognition of the need to protect critical infrastructure from evolving cybersecurity threats. This move is expected to bolster the overall resilience of the nation’s emergency response capabilities and communication networks.