Plex is urging users to update their software due to multiple undisclosed security flaws that have been patched in recent updates. Users are advised to upgrade to Plex Media Server version 1.43.3 and Plex Desktop version 1.115.0. While Plex has not provided specific details about the vulnerabilities, they have requested CVE identifiers, indicating that they take the issues seriously. This call to action is important for all Plex server owners and desktop users to ensure their systems remain secure. Failing to update could leave users vulnerable to potential attacks that exploit these unpatched flaws.
Articles tagged "Update"
Found 439 articles
Google has rolled out a security update to address 12 vulnerabilities in Chrome, including a high-severity flaw tracked as CVE-2026-85046. This vulnerability, identified as a type confusion bug in V8, the JavaScript and WebAssembly engine used by Chrome, has been actively exploited in the wild. Users of Chrome versions prior to 152.0.7977.82 are particularly at risk, as this flaw could allow attackers to execute malicious code remotely. This situation underscores the urgent need for users to update their browsers to the latest version to protect against potential attacks. Keeping software up to date is crucial in safeguarding against emerging threats.
Hewlett Packard Enterprise (HPE) has addressed a serious security vulnerability in its ArubaOS-CX network operating system. This flaw could allow attackers to execute remote code, potentially compromising affected systems. Organizations using ArubaOS-CX are at risk, as this vulnerability could lead to unauthorized access and manipulation of network functions. HPE has released patches to fix the issue, and it's crucial for users to update their systems promptly to prevent exploitation. Cybersecurity experts recommend that companies prioritize applying these updates to safeguard their networks from potential attacks.
The Hacker News
In this latest update on cybersecurity threats, attackers are increasingly using tactics that exploit user trust and familiarity. Phishing kits targeting CEOs are on the rise, alongside hacks affecting around 5,000 Dropbox accounts. These attacks often appear legitimate, with users receiving calls from IT, sharing files, or being prompted to click 'Allow' on trusted apps. Additionally, attackers are employing fake login pages and old account links to trick users into giving up their credentials. This highlights the need for heightened awareness and caution when interacting with seemingly innocuous requests, as one small mistake can lead to significant breaches.
The Hacker News
Cisco has issued critical patches for a vulnerability in its Nexus 9000 series switches, specifically those based on Silicon One architecture. This flaw, identified as CVE-2026-20212, carries a CVSS score of 9.8, indicating a severe risk. It allows remote attackers, without needing to authenticate, to execute code with root privileges on impacted systems. Alongside this vulnerability, Cisco also released a hardening update for IOS XR that includes seven additional CVEs, two of which are also rated very high at 9.8. Users of these Nexus switches should prioritize applying the patches as there are currently no workarounds available for the IOS XR versions affected.
Inductive Automation's Ignition platform has a serious vulnerability that allows any authenticated user to create projects, due to a misconfigured setting in versions 8.1.53 and earlier. This is classified as CVE-2026-77393 and has a CVSS score of 8.8, indicating a high-level risk. The issue stems from the 'Create Project Role(s)' setting being left blank, which means no role restrictions were enforced. Users are encouraged to upgrade to version 8.1.54 or later, where project creation is limited to Designer sessions, or to configure their current version to restrict project creation appropriately. This vulnerability poses risks in critical sectors such as manufacturing and energy, making it crucial for organizations using this software to address the issue promptly to prevent unauthorized project creation.
A vulnerability in the OPC Foundation's OPC UA LocalDiscoveryServer (LDS) could allow attackers to gain control of high-privilege terminal sessions during installation. This affects versions of the software prior to 1.04.420 and has been assigned CVE-2026-77477. To exploit this vulnerability, an attacker needs elevated privileges and access to the system during installation, potentially allowing them to execute arbitrary commands. This issue is particularly concerning for sectors like energy, chemical, and critical manufacturing, where the software is widely used. Users are advised to upgrade to version 1.04.420 or later to mitigate the risk.
Tycon Systems has identified several vulnerabilities in its TPDIN-Monitor-WEB3 device, affecting versions 2.2.9 and earlier. These vulnerabilities could allow attackers to conduct man-in-the-middle attacks, perform factory resets, or access sensitive information due to hard-coded credentials, cross-site request forgery (CSRF), and missing authorization. The CVEs associated with these issues are CVE-2026-77847, CVE-2026-82712, and CVE-2026-82684, with severity ratings ranging from medium to high. Tycon Systems has released a firmware update, version 2.4.2, which addresses these vulnerabilities. Users still operating on the older version are urged to upgrade promptly to enhance their security posture and protect against potential exploits.
All CISA Advisories
Schneider Electric has identified a serious vulnerability affecting several of its products, which could allow hackers to hijack user sessions. This flaw, cataloged as CVE-2026-4827, impacts a range of devices including the Easergy MiCOM series, EcoStruxure Power Automation products, and various PowerLogic and Saitel devices. If exploited, attackers could gain unauthorized access, potentially leading to disruptions in critical infrastructure sectors such as energy and water management. Users of the affected versions are urged to apply the necessary updates to mitigate this risk. The vulnerability is significant given the critical nature of the systems involved, necessitating prompt action from users worldwide to secure their operations.
A vulnerability has been identified in Rockwell Automation's ControlFLASH software, which could allow attackers to execute arbitrary code with the permissions of the logged-in user. This issue affects versions of ControlFLASH up to and including 15.07, and it stems from the software granting write permissions to the 'Everyone' group on its installation directory. Users are urged to update to version 15.08, which addresses the vulnerability. For those unable to upgrade, Rockwell Automation provides a workaround to remove the 'Everyone' group from the permissions. This vulnerability is particularly concerning as it impacts critical infrastructure sectors such as manufacturing, energy, and water management, making it essential for organizations to take prompt action to mitigate potential risks. No public exploitation of this vulnerability has been reported yet, but the nature of the issue poses significant security risks.
Rockwell Automation has identified serious vulnerabilities in its ArmorStart LT product, specifically versions up to v2.001. These vulnerabilities could allow attackers to execute malicious scripts through cross-site scripting (XSS) attacks or cause a denial of service by sending crafted HTTP requests, leading to web server outages. Users are strongly advised to update to firmware version v2.002 to mitigate these risks. The vulnerabilities affect critical manufacturing systems worldwide, raising concerns about the security of industrial control systems. Organizations should act swiftly to ensure their systems are protected, following best practices for cybersecurity.
A vulnerability in the IXON VPN Client, specifically versions earlier than 1.4.7, has been discovered that allows attackers to execute remote code with elevated privileges. This issue arises from improper handling of CRLF sequences, which can lead to command injection. The affected software is widely used across various critical sectors, including energy and information technology, and its exploitation could have severe implications for security. Users are urged to upgrade to version 1.4.7 or later to mitigate risks, as IXON has begun rejecting connections from older versions. Until the update is applied, users should consider uninstalling the VPN client if it is no longer needed.
Plex has alerted its users to update their desktop clients and media servers due to several identified security vulnerabilities. These flaws could potentially allow attackers to exploit the software, putting user data at risk. The company emphasizes the urgency of the update, as failure to patch could leave systems vulnerable to unauthorized access. Users of Plex should prioritize this update to ensure their media servers and clients are secure. It's a critical reminder of the importance of keeping software up to date to protect personal information and maintain security.
The Hacker News
Hackers have executed a Border Gateway Protocol (BGP) hijack to redirect traffic meant for Softaculous, allowing them to deliver a malicious update for Virtualizor. This incident has compromised at least five out of thirty-four Virtualizor hypervisors at a hosting provider, granting the attackers root access to these systems. The attack window is reported to have occurred on August 28. This breach raises concerns for users relying on Virtualizor for virtualization management, as the malicious update could lead to unauthorized control over their servers. Organizations using this software should take immediate steps to assess their systems for vulnerabilities and potential intrusions.
A recent cybersecurity incident involved a malicious update for Virtualizor, a server virtualization software, which was delivered through a BGP hijacking attack. Attackers used a valid TLS certificate for Softaculous’ domains to redirect users to counterfeit software update sites. This means that unsuspecting users who tried to update their software could have inadvertently downloaded malicious code. The incident raises significant concerns about the integrity of software updates and the potential for widespread exploitation of compromised systems. Companies relying on Virtualizor should review their security measures and monitor for any signs of compromise.