PaperCut has issued a second emergency patch for its NG and MF print management software due to two vulnerabilities that are currently being exploited. Researchers found that there were ways to bypass the initial fixes provided in the first patch, which prompted the urgent release of this new update. Organizations using PaperCut's software should prioritize applying this patch to protect against potential attacks, as the vulnerabilities can lead to unauthorized access and exploitation. It’s critical for users to stay informed and ensure their systems are updated to mitigate these risks.
Articles tagged "Update"
Found 419 articles
A serious vulnerability has been found in the GiveWP donation plugin for WordPress, which could allow an unauthenticated attacker to execute arbitrary commands on the server where the plugin is hosted. This flaw poses a significant risk to websites using this plugin, as it could lead to unauthorized access and control over the server. The issue affects all versions of the GiveWP plugin prior to the latest patch, making it crucial for site administrators to update their installations immediately. Given the nature of the vulnerability, there is a potential for widespread exploitation, which could compromise sensitive data and functionality for many organizations relying on this donation tool. Users and organizations should prioritize applying the necessary updates to safeguard their systems.
The Hacker News
ServiceNow has patched four security vulnerabilities in its AI Platform, three of which are rated 10.0 on the CVSS scale, indicating they are highly critical. These flaws could allow unauthenticated attackers to execute arbitrary code and SQL commands under certain conditions, posing a significant risk to organizations using the platform. ServiceNow has already rolled out security updates to hosted instances and provided updates to partners and self-hosted customers. Organizations that deploy their own instances need to ensure they apply these patches promptly to protect against potential exploitation. Given the severity of these vulnerabilities, immediate action is crucial to safeguard sensitive data and maintain system integrity.
Recent vulnerabilities have been discovered in the Xiiaozet LK100W device, affecting versions below 2.1.240. These vulnerabilities could allow attackers to take control of the device through OS command injection, missing authentication for critical functions, and authentication bypass methods. The most severe of these issues has a CVSS score of 9.8, indicating a critical risk of unauthorized access. Users worldwide are urged to update their devices to version 2.1.240 as a primary remediation step. The vulnerabilities expose sensitive information and could potentially lead to complete device compromise, making it crucial for organizations to address these security gaps promptly.
Mitsubishi Electric has identified a vulnerability affecting several models in its CNC Series, specifically relating to improper validation of input indices. This flaw, designated as CVE-2025-2399, can be exploited remotely, leading to an out-of-bounds read that could disrupt service. Affected models include the M800VW, M800VS, M80V, and several others across different series. Users of these products are urged to update to specific fixed versions to prevent potential exploitation. Additionally, Mitsubishi Electric recommends using firewalls, VPNs, and IP filters as interim measures to secure their systems while waiting for updates.
Mitsubishi Electric has disclosed a significant vulnerability affecting multiple models of its CC-Link IE TSN Remote I/O products. This flaw, identified as CVE-2025-3511, allows remote attackers to trigger a denial-of-service (DoS) condition by sending specially crafted UDP packets. Affected devices include various models of CC-Link IE TSN Remote I/O modules, Analog-Digital and Digital-Analog Converter modules, FPGA modules, and MELSEC iQ series components. The potential for disruption is considerable, as it could lead to communication delays or complete service outages in critical manufacturing environments. Companies using these affected products should prioritize immediate action to mitigate risks associated with this vulnerability.
The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that U.S. government agencies must address a serious remote code execution vulnerability affecting Citrix NetScaler appliances by this Saturday. This flaw is currently being exploited by attackers, which raises urgent concerns for the security of government networks. Citrix NetScaler is widely used for application delivery and load balancing, making it critical for agencies to implement the patch to prevent unauthorized access and potential data breaches. The deadline emphasizes the need for swift action to mitigate risks, as failure to patch could lead to significant security incidents. Agencies are strongly advised to prioritize this update to protect their systems and sensitive information.
A group known for operating a click-fraud botnet is now targeting infotainment systems in vehicles, exploiting legitimate update mechanisms to spread malware. This new tactic allows attackers to hijack the update process, potentially infecting car head units with malicious software. The implications of this are concerning, as it could compromise the functionality of car systems and expose personal data of drivers and passengers. This type of attack not only puts individuals at risk but also raises questions about the security of automotive software updates. Users of affected vehicle infotainment systems should remain vigilant and consider how they manage software updates to protect against these threats.
SCM feed for Latest
WhatsApp has made a significant update to its security features by allowing users to create multiple passkeys. This new functionality enables users to have separate secure logins for different devices and platforms, enhancing account security. With the rise of cyber threats, this move aims to protect user accounts from unauthorized access. Users will benefit from increased flexibility and security, as they can manage logins across various devices more effectively. This update is particularly important as it addresses ongoing concerns about digital privacy and security in messaging apps.
Ubiquiti has addressed three serious security vulnerabilities that could allow remote attackers to exploit systems without needing any user privileges. These vulnerabilities are classified with maximum severity, indicating a high risk for users of Ubiquiti's products. The company has released patches to fix these issues, and users are strongly advised to apply these updates promptly to safeguard their networks. Given the nature of these vulnerabilities, the potential for unauthorized access could lead to significant security breaches if left unaddressed. This incident serves as a reminder for organizations to regularly update their systems and stay vigilant about security patches.
BleepingComputer
WhatsApp is enhancing its account security with the introduction of multiple passkeys and a more robust two-step verification process. These features aim to provide users with better protection against unauthorized access to their accounts. The update is part of WhatsApp's ongoing efforts to improve security, especially as the platform continues to grow in popularity. Users will benefit from these added layers of security, making it harder for attackers to compromise their accounts. This move is particularly important given the increasing number of phishing attempts and account takeovers targeting messaging apps.
Marimo has fixed a serious security flaw in its notebook software that could allow attackers to run unauthorized commands. This vulnerability, identified by VulnCheck's CVE Numbering Authority, enables an attacker to execute Model Context Protocol (MCP) commands when a specially crafted notebook is opened in edit mode. If exploited, this could lead to unauthorized actions on a user's system, particularly affecting individuals using the notebook software in environments where sensitive data is handled. Users are urged to update their software promptly to mitigate potential risks associated with this flaw.
CISA has added a new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, specifically CVE-2026-60004, which is a code injection vulnerability in Gitea. This vulnerability is being actively exploited and poses significant risks, particularly to federal agencies. In response, CISA has emphasized the urgency for federal agencies to prioritize the remediation of this high-risk vulnerability, as it can grant attackers total control over affected systems. While the directive primarily targets Federal Civilian Executive Branch agencies, CISA encourages all organizations to adopt similar risk-based vulnerability management practices. The agency will continue to update the KEV Catalog with vulnerabilities that meet its criteria, and organizations are encouraged to report any known exploits not currently listed.
Siemens has identified a serious vulnerability in its SIMATIC IoT2050 Advanced devices that run Industrial OS with Node-RED installed. The flaw arises from a lack of authentication on the Node-RED HTTP interface, which could allow remote attackers to access and manipulate system commands on the server without any authentication. This means they could create harmful flows and execute arbitrary code with full system privileges. Siemens has urged users to update their devices to version 4.3.4.1 or later to mitigate this risk. The affected devices are used across various critical infrastructure sectors, including chemical, manufacturing, energy, and transportation, highlighting the need for immediate action to protect against potential exploitation.
Bendix has identified critical vulnerabilities in its EC80 Brake ECU, which could allow attackers to disrupt essential vehicle functions like ABS, steering assist, and traction control. The affected versions include multiple models such as EC80ESP+ and EC80ESP PLC across various configurations. These vulnerabilities stem from issues like stack-based buffer overflows, out-of-bounds writes, and the use of hard-coded credentials. Users of the affected products are urged to update their firmware to the latest versions to mitigate these risks. This situation is particularly concerning as it affects vehicle safety systems, making prompt action crucial for those using the impacted equipment.