π¨ Warning: A critical #vulnerability (CVE-2024-9680) in Firefox is being actively exploited.
Donβt waitβensure your browsers are updated now to protect against potential remote code execution.
Learn more: https://thehackernews.com/2024/10/mozilla-warns-of-active-exploitation-in.html
Donβt waitβensure your browsers are updated now to protect against potential remote code execution.
Learn more: https://thehackernews.com/2024/10/mozilla-warns-of-active-exploitation-in.html
π±25π13π€―6π₯3π2π1
A critical unpatched #vulnerability (CVE-2024-9441) in the Nice Linear eMerge E3 access controller has been uncovered, carrying a CVSS score of 9.8, with proof-of-concept exploits already circulating.
Learn more: https://thehackernews.com/2024/10/experts-warn-of-critical-unpatched.html
Learn more: https://thehackernews.com/2024/10/experts-warn-of-critical-unpatched.html
π4π4β‘1
Iranian threat actor OilRig is exploiting a Windows Kernel #vulnerability (CVE-2024-30088) to gain SYSTEM privileges, enabling backdoor deployment and data theft.
Learn how to protect your systems now https://thehackernews.com/2024/10/oilrig-exploits-windows-kernel-flaw-in.html
Learn how to protect your systems now https://thehackernews.com/2024/10/oilrig-exploits-windows-kernel-flaw-in.html
π28π₯10β‘8π€5π3π€―2π±1
π Kubernetes Image Builder #vulnerability (CVE-2024-9486) has a serious root access flaw.
With a CVSS score of 9.8, this flaw lets attackers exploit default credentials to take over virtual machines using certain image builds.
Read: https://thehackernews.com/2024/10/critical-kubernetes-image-builder.html
With a CVSS score of 9.8, this flaw lets attackers exploit default credentials to take over virtual machines using certain image builds.
Read: https://thehackernews.com/2024/10/critical-kubernetes-image-builder.html
π10π±5β‘3π€―3π2
VMware has released updates for CVE-2024-38812, a critical #vulnerability in vCenter Server.
With a CVSS score of 9.8, this heap-overflow flaw could allow remote code execution, fundamentally jeopardizing organizational security.
Read: https://thehackernews.com/2024/10/vmware-releases-vcenter-server-update.html
With a CVSS score of 9.8, this heap-overflow flaw could allow remote code execution, fundamentally jeopardizing organizational security.
Read: https://thehackernews.com/2024/10/vmware-releases-vcenter-server-update.html
π16β‘4π₯4π1
A new #vulnerability in Styra's Open Policy Agent (CVE-2024-8260) could expose NTLM credentials to attackers.
Attackers can exploit it to relay authentication, reinforcing the need for stringent input validation across all applications.
Read: https://thehackernews.com/2024/10/security-flaw-in-styras-opa-exposes.html
Attackers can exploit it to relay authentication, reinforcing the need for stringent input validation across all applications.
Read: https://thehackernews.com/2024/10/security-flaw-in-styras-opa-exposes.html
π€―11π4π3
North Korea's Lazarus Group exploits a zero-day #vulnerability (CVE-2024-4947) in Google Chrome to target the #cryptocurrency sector.
Exploitation strategy involved social media manipulation and fake game promotions.
Learn more: https://thehackernews.com/2024/10/lazarus-group-exploits-google-chrome.html
Exploitation strategy involved social media manipulation and fake game promotions.
Learn more: https://thehackernews.com/2024/10/lazarus-group-exploits-google-chrome.html
π₯15π10π€―4
Cisco has patched CVE-2024-20481, a #vulnerability affecting its ASA and Firepower devices that could lead to a denial-of-service (DoS) for Remote Access VPNs.
Learn more: https://thehackernews.com/2024/10/cisco-issues-urgent-fix-for-asa-and-ftd.html
Learn more: https://thehackernews.com/2024/10/cisco-issues-urgent-fix-for-asa-and-ftd.html
π7π₯7π3π1
Researchers identified a #vulnerability in AWS CDK that may lead to account takeover, with over 1% of users at risk from predictable S3 bucket names.
The solution: update your CDK version and customize bucket names.
Read: https://thehackernews.com/2024/10/aws-cloud-development-kit-vulnerability.html
The solution: update your CDK version and customize bucket names.
Read: https://thehackernews.com/2024/10/aws-cloud-development-kit-vulnerability.html
π10π€5π₯4π3
Attention: CVE-2024-41992 #vulnerability in Wi-Fi Test Suite could give attackers full control over Arcadyan routers. The flaw allows for command injection, enabling full administrative access.
Find details here β https://thehackernews.com/2024/10/researchers-discover-command-injection.html
Find details here β https://thehackernews.com/2024/10/researchers-discover-command-injection.html
π€―12π10β‘3π2