CVEs
"Routine initial exploitation of zero-day vulnerabilities represents the new normal which should concern end-user organisations and vendors alike."
There is no workaround for the critical CVE, which is one of a pair of bugs which let attackers carry out remote code execution or escalate privileges.
No full exploit chain yet but plenty of hints in new breakdown from WatchTowr
Ransomware-as-a-service variant formerly known as Cyclops and Knight has "established itself as an efficient and successful service model" and attracted "high-profile affiliates from other prominent variants".
CVE-2024-38063 lets unauthenticated attackers carry out remote code execution by "repeatedly sending IPv6 packets".
Vulnerabilities identified in workplace and cybersecurity products offered by ServiceNow and Acronis
Security agency adds CVE-2012-4792 to its catalogue of known vulns and warns it can "execute arbitrary code via a crafted web site"