Articles tagged "Update"

Found 419 articles

A vulnerability in OpenSSH versions prior to 10.5 allowed users to inadvertently expose local-only keys when locking the ssh-agent. In OpenSSH 10.4, locking the agent disabled a security check that determined whether connection requests came from the local machine or a remote, forwarded connection. This flaw meant that if users locked their ssh-agent, it could still respond to requests that shouldn't be permitted. The issue was addressed in the recently released OpenSSH 10.5, which restores the proper functionality of the lock feature. Users relying on ssh-agent for secure connections should update to this version to ensure their private keys remain protected.

Read Original

A recent analysis has uncovered 176 vulnerabilities in Samsung's proprietary mobile applications, which are pre-installed and cannot be removed by users. These apps operate outside of Google Play Protect, leaving them exposed to potential security risks. The vulnerabilities could allow attackers to exploit these apps, potentially compromising user data and device security. This is particularly concerning as Samsung devices are widely used around the world. Users of Samsung mobile devices need to stay alert and update their apps as soon as patches are available to mitigate these risks.

Read Original

This week saw a range of cybersecurity issues, including the resurgence of old vulnerabilities and concerns over supply chain attacks. Researchers pointed out that common actions like cloning repositories or trusting default settings continue to lead to significant security breaches. One notable incident involved a zero-day vulnerability in Metabase, which could allow unauthorized access to sensitive data. Additionally, there are reports of supply-chain attacks targeting MCP systems, raising concerns about the integrity of software and hardware components. These incidents serve as a reminder for organizations to remain vigilant about their security practices and to frequently update their systems to counteract these evolving threats.

Read Original

A group known as Head Mare has been exploiting vulnerabilities in unpatched TrueConf servers to carry out attacks against various Russian companies. These companies operate in sectors like instrumentation, electronics, transport, energy, IT, and software development. Kaspersky, a cybersecurity firm, reported detecting these attacks in July 2026. The attackers are reportedly replacing legitimate client installers with malicious software called PhantomCore, which could compromise the security of the affected organizations. This situation raises concerns for companies still using outdated versions of TrueConf, as failure to update could lead to severe security breaches.

Read Original
Actively Exploited

Metabase has patched a significant security vulnerability that allowed unauthenticated remote attackers to gain administrative access to its instances. This flaw posed a serious risk, as it enabled attackers to potentially manipulate data and settings without needing any credentials. The issue has been classified as a zero-day exploit, meaning it was actively being exploited in the wild before the patch was released. Users of Metabase should ensure they update to the latest version to protect against this vulnerability. This incident serves as a reminder of the importance of timely software updates and vigilant security practices in safeguarding sensitive data.

Read Original

GitHub has expanded its malware detection capabilities to cover eight different ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer, in addition to its existing support for npm. This update comes after GitHub's Advisory Database began integrating malware reports from OpenSSF's malicious-packages repository, which has accumulated over 15,000 reports since its launch in 2023. These reports include various types of malicious packages, such as typosquats and dependency confusion. This change is significant as it helps developers and users identify and avoid potentially harmful packages across multiple ecosystems, enhancing overall security in software development. Previously, users were only alerted to npm-related malware, leaving them vulnerable when using packages from other sources.

Read Original

The Head Mare hacktivist group has been targeting unpatched TrueConf video conferencing servers, exploiting vulnerabilities to swap out legitimate client installers with malicious versions that contain backdoors. This means that unsuspecting users who download these compromised installers may unknowingly install malware that could allow attackers unauthorized access to their systems. TrueConf, which is used for video conferencing, is now facing scrutiny as users may be at risk of data breaches and privacy violations. Organizations using TrueConf need to ensure their servers are updated and secure to prevent these kinds of attacks, which are becoming increasingly common as hackers look for easy targets. It's crucial for users to be aware of the risks and to regularly update their software to protect against such vulnerabilities.

Read Original

Researchers from Varonis have discovered a serious vulnerability in Atlassian’s Rovo AI that allows attackers to exploit a one-click method known as the RovoBlast attack. This vulnerability could potentially enable unauthorized access to sensitive enterprise data stored in applications like Confluence, Jira, and SharePoint. Organizations using these tools should be particularly concerned, as the exposure of this data could lead to significant breaches and loss of confidential information. The discovery emphasizes the need for companies to regularly update their security protocols and patch vulnerabilities promptly to safeguard their data. As of now, the specific details about whether this vulnerability is being actively exploited are not confirmed.

Read Original

N-able has issued a hotfix for its N-central Remote Monitoring and Management (RMM) software amid ongoing attacks exploiting a recently identified security flaw. The company is enhancing its protective measures as it observes evolving tactics from threat actors targeting managed systems. This update is part of their commitment to maintaining system integrity and safeguarding user data. Users of N-central should apply the latest hotfix to mitigate the risks associated with these active exploitation attempts. The situation underscores the importance of timely updates in the face of persistent cyber threats.

Read Original

Researchers at Pwn have identified a serious vulnerability in WordPress, dubbed the XSS2Shell flaw, which allows attackers to take control of an admin account and execute remote code. The issue arises when a user inputs a non-existent username, triggering a response from WordPress that contains a minor formatting error. This flaw can be exploited to gain unauthorized access to the server. WordPress users are strongly advised to update their installations to the patched versions to protect against this vulnerability. Failure to do so could leave sites open to full server takeover, posing significant risks to website security and data integrity.

Read Original

A long-standing vulnerability in the Linux SCTP networking code, present since 2008, has been discovered to allow local users to gain root access on the host system. Tencent researchers demonstrated that this use-after-free bug could enable an attacker to escape from a container and access the underlying machine. This issue affects users running older Linux kernels that have SCTP enabled. Fortunately, patches have been released for multiple stable kernel versions, including 7.1.6 and 6.6.148, as of August 3. It's crucial for anyone using affected kernels to update promptly to prevent potential exploitation.

Read Original
Critical
Medixant RadiAnt DICOM

All CISA Advisories

A vulnerability has been discovered in Medixant's RadiAnt DICOM software that could allow attackers to exploit specially crafted DICOM files. Versions 2025.2 and earlier of the software are affected, which could lead to application crashes or even remote code execution due to an out-of-bounds write triggered by malicious JPEG-compressed pixel data. Users are advised to upgrade to version 2026.1 to mitigate this risk. The vulnerability is particularly concerning for healthcare and public health sectors worldwide, as it could compromise patient data and system integrity. While there are currently no reports of this vulnerability being actively exploited, users should remain cautious and only open DICOM files from trusted sources.

Read Original
Critical
Johnson Controls Inc. TL280

All CISA Advisories

A recently discovered vulnerability in Johnson Controls Inc.'s TL280 device could allow attackers to access sensitive information. Specifically, versions of the TL280 prior to 5.63 are impacted due to the use of hardcoded credentials in the device's firmware. This presents a significant risk, particularly for sectors such as critical manufacturing, government services, and energy. To mitigate the threat, Johnson Controls recommends updating to firmware version 5.63 and implementing several network security measures, such as restricting access to trusted VLANs and monitoring device access logs for unusual activity. Although no active exploitation of this vulnerability has been reported, organizations should take proactive steps to protect their systems.

Read Original

Brown Health Medical Group in Massachusetts has reported a significant data breach affecting over 311,000 individuals. Hackers gained access to the healthcare provider's servers, compromising sensitive personal, medical, and financial information. The breach was traced back to a legacy file server, which raises concerns about the security of outdated systems. Affected individuals may face risks such as identity theft and financial fraud, making it crucial for them to monitor their accounts and consider additional protective measures. This incident serves as a reminder for healthcare organizations to prioritize data security and regularly update their systems to prevent similar breaches.

Read Original

HashiCorp, Veeam, and the Django Software Foundation have addressed 11 vulnerabilities in their respective products, with three being particularly severe. Veeam's Service Provider Console has a critical flaw that allows unauthenticated access to a managed agent's credentials, rated at 9.5 on the CVSS scale. HashiCorp's Terraform MCP server has a cross-tenant vulnerability that could let one user's token be reused by others, potentially exposing sensitive data. Django has also patched vulnerabilities that could affect its web framework. These issues are important because they could allow unauthorized access to systems and sensitive information. Users of these platforms should update their software to mitigate these risks.

Read Original
PreviousPage 5 of 28Next