Articles tagged "Critical"

Found 725 articles

Anthropic's AI initiative, Project Glasswing, has identified over 10,000 serious vulnerabilities within just one month of operation. This alarming discovery exposes a significant gap in the ability of organizations to patch and manage these vulnerabilities effectively. The vulnerabilities range in severity from high to critical, raising concerns for companies and users who rely on the affected systems. As the number of vulnerabilities continues to grow, it becomes increasingly clear that many organizations struggle with timely patching and security management. This situation not only jeopardizes the security of sensitive data but also highlights the urgent need for improved cybersecurity practices across the industry.

Impact: N/A
Remediation: N/A
Read Original

Last week, the hacking group TeamPCP claimed to have breached GitHub's internal codebase by using a poisoned Visual Studio Code (VS Code) extension. GitHub, owned by Microsoft, confirmed the breach and has since launched an investigation into how their private code repositories were compromised. This incident raises serious concerns about the security of development tools widely used by programmers. Moreover, researchers recently discovered a critical flaw in NGINX, a popular web server software, which is being actively exploited. These incidents highlight the ongoing vulnerabilities in essential software and the need for robust security measures to protect sensitive information.

Impact: GitHub's internal codebase, Visual Studio Code extensions, NGINX web server software
Remediation: GitHub is investigating the breach; users should ensure their VS Code extensions are from trusted sources. For NGINX, users should apply the latest security patches as they become available.
Read Original

Anthropic announced that its Project Glasswing has identified over 10,000 high- or critical-severity vulnerabilities in widely-used software since its launch last month. This initiative involves collaboration with around 50 partners and focuses on software deemed systemically important on a global scale. These vulnerabilities pose significant risks to organizations and users relying on this software, potentially exposing them to data breaches or cyberattacks. The findings emphasize the urgent need for software developers and companies to address these flaws promptly to safeguard their systems and users. This proactive approach highlights the role of AI in enhancing cybersecurity efforts.

Impact: N/A
Remediation: N/A
Read Original
RondoDox Botnet Exploits Critical 2018 Vulnerability to Hijack ASUS Routers

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Hackers are exploiting a significant vulnerability from 2018 to take control of over a million ASUS routers. According to VulnCheck, this flaw allows attackers to bypass authentication mechanisms, making it easier for them to hijack affected devices. The vulnerability impacts various ASUS router models, posing a risk to users who may unknowingly have their networks compromised. This incident is concerning because it shows how older vulnerabilities can still be leveraged for large-scale attacks, highlighting the need for users to regularly update their devices and apply security patches. Failure to address these vulnerabilities could lead to unauthorized access and further exploitation of personal or sensitive information.

Impact: ASUS routers, specific models not detailed
Remediation: Users should apply the latest firmware updates from ASUS to mitigate the vulnerability. Regularly checking for updates and changing default settings is also advisable.
Read Original

Ubiquiti has patched three serious vulnerabilities in its UniFi OS, labeled CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910. These flaws could allow unauthorized users to make system changes, access sensitive system files through path traversal, and execute commands remotely via command injection. This is a significant concern for users of UniFi OS, as it could lead to unauthorized access and control over network devices. Ubiquiti is urging all users to apply the updates as soon as possible to protect their systems from potential exploitation. Given the nature of these vulnerabilities, companies using UniFi OS should prioritize updating their systems to ensure their networks remain secure.

Impact: UniFi OS users, specifically versions affected by CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910.
Remediation: Ubiquiti has released patches for the vulnerabilities in the latest update of UniFi OS. Users are advised to update their systems immediately to the latest version to close these security gaps.
Read Original

Cisco's recent research has raised concerns about the reliability of AI-generated security incident reports. The study found that large language models (LLMs) can produce inconsistent results, even when querying the same data. This variability can lead to confusion and mistakes in understanding security incidents, which is critical for organizations relying on accurate reporting for their security posture. The findings suggest that companies using AI for cybersecurity reporting need to be cautious and verify the data produced by these systems, as discrepancies could hinder effective incident response. As AI becomes more integrated into security operations, ensuring its accuracy will be vital for maintaining trust and effectiveness in cybersecurity efforts.

Impact: N/A
Remediation: Organizations should verify AI-generated reports and cross-check with human analysis to ensure accuracy.
Read Original

The Belarus-linked hacking group Ghostwriter, also known as UAC-0057 and UNC1151, has launched a multi-stage cyberattack targeting Ukraine. Researchers have identified that the group is using the Prometheus learning platform as bait to lure victims into their traps. This tactic raises concerns as it not only threatens the security of individuals and organizations in Ukraine but also highlights the ongoing cyber warfare linked to the conflict in the region. The implications are significant, as such attacks can disrupt critical infrastructure and undermine trust in digital platforms, especially in a time of heightened tensions. As the situation evolves, vigilance is essential for those engaged in online education and other sectors potentially impacted by these tactics.

Impact: Prometheus learning platform, Ukraine's digital infrastructure
Remediation: Users and organizations should enhance their cybersecurity measures, including employee training on phishing and social engineering tactics, as well as implementing robust endpoint protection solutions.
Read Original

Drupal has issued a warning about a significant SQL injection vulnerability that is currently being targeted by hackers. This flaw, which was announced earlier in the week, poses a serious risk to websites running on the Drupal content management system. Attackers can exploit this vulnerability to gain unauthorized access to databases, potentially leading to data breaches or site compromises. Users and administrators of Drupal sites are urged to take immediate action to secure their systems, as the risk of exploitation is high. It is crucial for affected parties to stay vigilant and apply any available patches to mitigate this threat.

Impact: Drupal content management system versions affected by the SQL injection vulnerability.
Remediation: Site administrators should apply the latest security updates and patches released by Drupal to address the SQL injection vulnerability.
Read Original

Lawmakers from both sides of the political aisle are expressing concerns that the budget cuts to the Cybersecurity and Infrastructure Security Agency (CISA) are excessive, especially given the increasing cyber threats posed by countries like China. Representatives Don Bacon and James Walkinshaw pointed out that these cuts come at a time when the need for robust cybersecurity measures is more critical than ever. As CISA plays a vital role in protecting civilian networks, the reduction in its funding could leave the nation more vulnerable to cyberattacks. This bipartisan agreement underscores the urgency for Congress to reevaluate the agency's budget and ensure it has the necessary resources to defend against evolving threats. Without adequate support, the effectiveness of CISA in safeguarding essential infrastructure may be compromised.

Impact: CISA operations and its ability to protect civilian networks
Remediation: Reevaluation of CISA's budget and funding support
Read Original

A newly discovered vulnerability, identified as CVE-2024-12802, affects SonicWall Gen6 SSL-VPN appliances. This security flaw allows attackers to bypass multi-factor authentication (MFA) by using a specific user principal name (UPN) login format. Organizations using these appliances could be at risk, as this vulnerability may enable unauthorized access to sensitive systems. Companies that rely on SonicWall for secure remote access should take immediate action to assess their exposure to this threat. Given the critical role of MFA in securing remote connections, this issue underscores the need for vigilance and prompt remediation.

Impact: SonicWall Gen6 SSL-VPN appliances
Remediation: Users should review their SonicWall configurations and apply any available patches. It is recommended to monitor for unusual login attempts and to consider additional security measures until a patch is implemented.
Read Original

In the current AI-driven landscape, the speed at which security exploits occur poses a significant challenge for organizations. A recent observation indicates that resolving security issues now takes an average of 43 days, a timeframe that is no longer acceptable given the rapid nature of attacks. This shift emphasizes the need for companies to adopt faster remediation strategies to protect sensitive identity information. As identity-related breaches become more common, the focus on improving response times is critical for maintaining security and trust. Organizations must rethink their security protocols to keep pace with evolving threats and minimize potential damage.

Impact: Identity-related systems and protocols
Remediation: Organizations should implement faster remediation strategies and improve security protocols
Read Original

Researchers have identified a new piece of Linux malware called Showboat, which has been targeting a telecommunications provider in the Middle East since at least mid-2022. This malware acts as a modular framework that allows attackers to gain remote access to systems, transfer files, and create a SOCKS5 proxy for further exploitation. The use of such a backdoor poses significant risks to the telecommunications infrastructure, potentially compromising sensitive data and disrupting services. As the attack has been ongoing for over a year, it raises concerns about the security measures in place within the affected organization and signals a growing trend of targeted attacks on critical sectors. Companies in similar industries should be vigilant and enhance their security protocols to protect against such sophisticated threats.

Impact: Linux systems used by telecommunications providers
Remediation: Implement enhanced security measures, conduct regular system audits, and monitor for unusual network activity.
Read Original

The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities Catalog by introducing a new nomination form. This form allows organizations to report vulnerabilities they believe should be included in the catalog, which serves to inform the public about security flaws that are actively being exploited by attackers. The catalog aims to help organizations prioritize their cybersecurity efforts by focusing on vulnerabilities that pose the most immediate risk. This initiative is particularly important as it encourages collaboration between the public and private sectors in identifying and addressing security weaknesses. By expanding the catalog, CISA hopes to enhance the overall security posture of critical infrastructure and other sectors.

Impact: N/A
Remediation: N/A
Read Original

Drupal has issued urgent security updates to address a serious vulnerability in Drupal Core, identified as CVE-2026-9082. This flaw can allow attackers to execute malicious code remotely, escalate privileges, or disclose sensitive information on PostgreSQL sites. With a CVSS score of 6.5, the vulnerability affects users relying on Drupal's database abstraction API. This issue is particularly concerning for organizations using Drupal for their web applications, as the potential for exploitation could lead to significant data breaches or system compromises. Users are strongly advised to apply the available security updates promptly to mitigate the risk.

Impact: Drupal Core, PostgreSQL sites
Remediation: Users should apply the latest security updates provided by Drupal to address CVE-2026-9082. Specific patch numbers or versions are not mentioned, but updating to the latest version of Drupal Core is recommended.
Read Original

A serious vulnerability has been found in the operating system used by certain robotic systems, allowing unauthenticated attackers to execute command injections. This flaw enables attackers to gain remote access, potentially leading to significant disruptions in environments that rely on these robots. Affected organizations need to take immediate action to protect their systems, as the implications of such control could be severe, impacting operations and safety. Users of the affected robotic systems should prioritize applying any available patches to mitigate this risk. The vulnerability underscores the need for ongoing vigilance in securing operational technology environments.

Impact: Robotic operating systems used in operational technology environments.
Remediation: Patch the affected robotic operating systems as soon as updates are available.
Read Original
PreviousPage 2 of 49Next