Articles tagged "Update"

Found 191 articles

Researchers have identified a serious vulnerability in Gitea, an open-source platform used for version control, that allows unauthorized users to access private container images. This flaw, labeled CVE-2026-27771, impacts all versions of Gitea prior to 1.26.2. Attackers can exploit this weakness without needing any credentials, which could lead to unauthorized access to sensitive data stored in container images. Given the nature of Gitea as a self-hosted solution, organizations using outdated versions are particularly at risk. It’s crucial for users to update their installations to the latest version to safeguard their private resources.

Impact: Gitea versions prior to 1.26.2
Remediation: Upgrade to Gitea version 1.26.2 or later to address the vulnerability.
Read Original

A serious vulnerability in Universal Robots' PolyScope operating system has been identified, allowing potential attackers to execute commands remotely. This flaw, tracked as CVE-2026-8153, has a high severity rating of 9.8, indicating a significant risk. It affects all versions of PolyScope software prior to 5.25.1, which means any users operating older versions are at risk. The ability for remote command execution could enable unauthorized access to connected systems, posing a threat to operational security. Users and organizations utilizing Universal Robots' systems need to take immediate action to update their software to the latest version to mitigate this risk.

Impact: Universal Robots PolyScope OS versions prior to 5.25.1
Remediation: Update PolyScope software to version 5.25.1 or later.
Read Original
RondoDox Botnet Exploits Critical 2018 Vulnerability to Hijack ASUS Routers

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Hackers are exploiting a significant vulnerability from 2018 to take control of over a million ASUS routers. According to VulnCheck, this flaw allows attackers to bypass authentication mechanisms, making it easier for them to hijack affected devices. The vulnerability impacts various ASUS router models, posing a risk to users who may unknowingly have their networks compromised. This incident is concerning because it shows how older vulnerabilities can still be leveraged for large-scale attacks, highlighting the need for users to regularly update their devices and apply security patches. Failure to address these vulnerabilities could lead to unauthorized access and further exploitation of personal or sensitive information.

Impact: ASUS routers, specific models not detailed
Remediation: Users should apply the latest firmware updates from ASUS to mitigate the vulnerability. Regularly checking for updates and changing default settings is also advisable.
Read Original

A newly discovered Linux local privilege escalation vulnerability, named PinTheft, affects the RDS subsystem and has a public exploit available. This flaw poses a significant risk to Arch Linux users, as they are particularly vulnerable to attacks utilizing this exploit. The vulnerability was identified by the V12 security team, and given the increasing number of similar security issues in Linux, users are urged to take immediate action. Patching the affected systems is crucial to prevent potential exploitation. This incident serves as a reminder for users and administrators to stay vigilant and regularly update their systems to safeguard against emerging threats.

Impact: Arch Linux systems, RDS subsystem
Remediation: Users should apply the latest patches for Arch Linux immediately to mitigate the risk.
Read Original

The Grafana data breach occurred due to a failure in rotating a GitHub workflow token after a recent npm supply-chain attack involving TanStack. This oversight allowed unauthorized access to Grafana's systems, potentially exposing sensitive data. The incident raises concerns about the importance of maintaining secure token management practices, especially in the wake of supply-chain vulnerabilities. Companies using Grafana may be at risk if they rely on outdated or improperly managed tokens. This breach serves as a reminder for organizations to regularly review and update their security protocols to prevent similar incidents.

Impact: Grafana systems and GitHub workflow tokens
Remediation: Implement regular token rotation and review access controls for GitHub workflows.
Read Original

Drupal is set to release a core security update today to address a significant vulnerability that could be exploited by attackers shortly after its announcement. The organization has cautioned that malicious actors are likely to create exploits within hours of the update going public. This means that any websites or applications running on affected versions of Drupal could be at risk if they do not update promptly. Users of Drupal should prioritize applying this critical update to protect their systems from potential attacks. The announcement underscores the need for vigilance in maintaining the security of web applications, particularly those built on widely used platforms like Drupal.

Impact: Drupal core versions prior to the upcoming security update
Remediation: Users should update to the latest version of Drupal as soon as the security release is available.
Read Original
Banana RAT Malware in Fake Invoices Hits Customers at 16 Brazilian Banks

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

A new malware strain known as Banana RAT is targeting customers of 16 Brazilian banks through deceptive tactics involving fake invoices and misleading security update screens. This malware is designed to steal sensitive information by tricking users into scanning fraudulent QR codes. The attack not only compromises personal data but also poses a significant financial risk to victims. As cybercriminals increasingly exploit these social engineering techniques, it's vital for users to remain vigilant and question unexpected communications that ask for sensitive information. The situation underscores the need for heightened security awareness among banking customers.

Impact: Customers of 16 Brazilian banks
Remediation: Users should avoid scanning QR codes from untrusted sources and verify the authenticity of invoices and updates directly with their banks.
Read Original

Drupal has announced that it will release a core security update on May 20, 2026, between 5-9 p.m. UTC. This update will affect all supported versions of the Drupal content management system. The Drupal Security Team is advising users to prepare for the update, as vulnerabilities could be exploited shortly after the release. It’s crucial for site administrators to allocate time for these updates to protect their websites from potential attacks. Ignoring these updates could leave sites vulnerable to exploits within days of the release.

Impact: All supported branches of the Drupal content management system (CMS)
Remediation: Users should reserve time for core updates during the specified release window to ensure their sites are secure.
Read Original

Researchers recently released a proof of concept (PoC) for a vulnerability in the Linux kernel known as DirtyDecrypt, which was patched back in April. This vulnerability allows local attackers to gain elevated privileges, potentially giving them root access to affected systems. While the vulnerability was addressed in a previous update, the release of the PoC means that those who haven't applied the patch could be at risk. It is crucial for users and administrators of Linux systems to ensure they are running the latest updates to mitigate this risk. The implications of this vulnerability are significant, especially for environments where security is paramount, such as servers and critical infrastructure.

Impact: Linux kernel versions prior to the April 2023 patch
Remediation: Users should apply the patch released in April 2023 to address the vulnerability.
Read Original

A new variant of the SHub macOS infostealer has been discovered that tricks users into believing they need to install a security update. Using AppleScript, this malware presents a fake update message, which, when interacted with, leads to the installation of a backdoor on the user's system. This malicious software primarily targets macOS users, potentially compromising their personal information and system integrity. The ability to deceive users with a legitimate-looking update notice makes this variant particularly concerning. It underscores the need for users to be vigilant about unexpected prompts and verify updates directly from Apple's official channels.

Impact: macOS systems, users of Apple's software
Remediation: Users should avoid interacting with suspicious update prompts and ensure that updates are only installed through official Apple channels. Regularly check for updates directly on Apple's website or through the system settings.
Read Original

A vulnerability in the Funnel Builder plugin for WordPress, which is used by over 40,000 websites, has been exploited by attackers to steal payment data. This flaw allows unauthenticated users to change global settings through an unprotected checkout endpoint. As a result, any website using this plugin could be at risk of having sensitive payment information compromised. Website owners should take immediate action to secure their sites, as the potential for financial loss and damage to customer trust is significant. This incident serves as a reminder for users to regularly update their plugins and monitor for security patches.

Impact: Funnel Builder plugin for WordPress, used by over 40,000 websites
Remediation: Website owners should update the Funnel Builder plugin to the latest version as soon as a patch is available, and review their website security settings to ensure proper protection against unauthorized access.
Read Original

Google's latest Chrome update, version 148, addresses several critical vulnerabilities, including a serious use-after-free issue affecting various browser components. This type of vulnerability can allow attackers to execute arbitrary code, potentially leading to unauthorized access or data breaches. Users of Chrome should update to the latest version to ensure their browsers are secure. Keeping browsers up to date is crucial, as these vulnerabilities can be exploited if left unpatched. The update underscores the ongoing need for vigilance in cybersecurity, especially given the frequency of browser-based attacks.

Impact: Google Chrome version 148 and earlier
Remediation: Update to Chrome version 148 or later
Read Original

OpenAI has confirmed that two of its employees' devices were compromised in a recent supply chain attack involving TanStack, which affected a wide range of npm and PyPI packages. As a precautionary measure, OpenAI has rotated its code-signing certificates to enhance security. This incident highlights the vulnerabilities that can arise from supply chain attacks, where attackers target third-party packages to infiltrate larger systems. While OpenAI has not specified if any of its applications were directly exploited, the breach raises concerns about the security of software dependencies and the potential risks to users and developers who rely on these packages. Companies are reminded to regularly review their security practices and update their systems accordingly.

Impact: npm and PyPI packages, OpenAI applications
Remediation: Rotated code-signing certificates
Read Original

Recent cyber campaigns attributed to Chinese advanced persistent threat (APT) groups have expanded their targets and updated their tactics. The group known as Salt Typhoon has reportedly attacked an energy entity in Azerbaijan, raising concerns about the security of critical infrastructure in the region. Another group, Twill Typhoon, has focused on entities in Asia, deploying an updated remote access Trojan (RAT) that enhances their capabilities. These developments suggest that these APTs are adapting to better infiltrate and exploit various sectors, which could lead to increased risks for organizations in affected areas. As these campaigns evolve, organizations need to bolster their cybersecurity measures to defend against such sophisticated attacks.

Impact: Energy sector in Azerbaijan, Asian entities
Remediation: Organizations should enhance their cybersecurity defenses, monitor for unusual activity, and ensure timely updates to security software.
Read Original

A new malware known as 'Mini Shai-Hulud' has compromised hundreds of open-source packages in a significant supply-chain attack. This malware has targeted major registries, disguising itself behind legitimate release signatures, which allows it to infiltrate software updates unnoticed. As a result, developers and organizations relying on these open-source packages may unknowingly integrate malicious code into their applications. This incident emphasizes the vulnerabilities present in the software update process and raises concerns about the security of open-source software. Researchers are urging developers to be vigilant and to verify the integrity of their dependencies before use.

Impact: Hundreds of open-source packages across major registries
Remediation: Developers should verify the integrity of their software dependencies and consider implementing additional security measures for package management.
Read Original
Page 1 of 13Next