Content Paint

vulnerabilities

new MOVEit vulnerability and federal agencies hacked

Hackers "often breach the Department’s defensive perimeter and roam freely within our information systems"

MFA is no protection against this critical new Fortinet vulnerability, CVE-2023-27997

"It is a pre-auth RCE [and] has been proven to be exploitable in a consistent manner; we found it during a Red Team engagement and have exploited it remotely..."

UPDATED: File transfer software under active attack. Banks, gov't hit as CVE, new IOCs released

Admins should urgently modify firewall rules to deny HTTP and HTTPs traffic to MOVEit Transfer on ports 80 and 443. (Also, can we start fuzzing for SQL Injection properly, please?)

Known exploited list: 15 million systems still exposed

... and probably shot to high heaven with malware.

As CVE-2023-23397 exploits proliferate, worry mounts

Security experts are warning that a critical Microsoft Outlook exploit is trivial to deploy and “will likely be leveraged imminently by actors for espionage purposes or financial gain” – after Ukrainian cybersecurity authorities disclosed CVE-2023-23397, a critical vulnerability that requires no user interaction to exploit. As The Stack reported, the critical

Urgent: Microsoft 365 Apps being exploited in wild via CVSS 9.8 bug

Get domain admin by... just emailing the domain admin?

Veeam urges “immediate” updates after vulnerability exposes backup hosts

This may generate a lot of Black Hat interest...

Server backup vulnerability piggybacked to live systems

Open source bug leads to server backup bug leads to... crime.

Over 83,000 ESXi servers are internet-exposed as mass attack continues

VMware denies zero day being used

Search the site

Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Great! You've successfully signed up.
Great! You've successfully signed up.
Welcome back! You've successfully signed in.
Success! You now have access to additional content.