Tag: remote-code-execution
-
WhatsUp Gold Flaw Could Lead to RCE, System Hijacking
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/whatsup-gold-flaw-could-lead-to-rce-system-hijacking
-
ToddyCat APT Abuses SMB, Exploits IKEEXT A Exchange RCE To Deploy ICMP Backdoor
ToddyCat is an APT group that has been active since December 2020, and primarily it targets the government and military entities in Europe and Asia. T… First seen on gbhackers.com Jump to article: gbhackers.com/toddycat-apt-exploits/
-
D-Link Warns of Code Execution Flaws in Discontinued Router Model
D-Link warns of multiple remote code execution vulnerabilities impacting its discontinued DIR-846 router model. The post D-Link Warns of Code Executio… First seen on securityweek.com Jump to article: www.securityweek.com/d-link-warns-of-code-execution-flaws-in-discontinued-router-model/
-
D-Link says it is not fixing four RCE flaws in DIR-846W routers
D-Link is warning that four remote code execution (RCE) flaws impacting all hardware and firmware versions of its DIR-846W router will not be fixed as… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/d-link-says-it-is-not-fixing-four-rce-flaws-in-dir-846w-routers/
-
North Korean Hackers Actively Exploiting Chromium RCE Zero-Day In The Wild
Tags: exploit, hacker, microsoft, north-korea, rce, remote-code-execution, threat, vulnerability, zero-dayMicrosoft has identified a North Korean threat actor, Citrine Sleet, exploiting a zero-day vulnerability in Chromium (CVE-2024-7971) to gain remote co… First seen on gbhackers.com Jump to article: gbhackers.com/chromium-rce-zero-day-in-the-wild/
-
Week in review: SonicWall critical firewalls flaw fixed, APT exploits WPS Office for Windows RCE
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: SonicWall patches critical flaw affecting its firewa… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/09/01/week-in-review-sonicwall-critical-firewalls-flaw-fixed-apt-exploits-wps-office-for-windows-rce/
-
WPML Multilingual CMS Authenticated Contributor+ Remote Code Execution Via SSTI
Tags: remote-code-executionFirst seen on packetstormsecurity.com Jump to article: packetstormsecurity.com/news/view/36260/WPML-Multilingual-CMS-Authenticated-Contributor-Remote-Code-Execution-Via-SSTI.html
-
Malware exploits 5-year-old zero-day to infect end-of-life IP cameras
The Corona Mirai-based malware botnet is spreading through a 5-year-old remote code execution (RCE) zero-day in AVTECH IP cameras, which have been dis… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malware-exploits-5-year-old-zero-day-to-infect-end-of-life-ip-cameras/
-
APT group exploits WPS Office for Windows RCE vulnerability (CVE-2024-7262)
ESET researchers discovered a remote code execution vulnerability in WPS Office for Windows (CVE-2024-7262). APT-C-60, a South Korea-aligned cyberespi… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/08/28/cve-2024-7262-cve-2024-7263/
-
RCE attacks likely with pair of Traccar GPS system bugs
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/rce-attacks-likely-with-pair-of-traccar-gps-system-bugs
-
Critical, Actively Exploited Jenkins RCE Bug Suffers Patch Lag
First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/critical-actively-exploited-jenkins-rce-bug-patch-lag
-
Google Now Offering Up to $250,000 for Chrome Vulnerabilities
Google has significantly increased the rewards for Chrome browser vulnerabilities, offering up to $250,000 for remote code execution bugs. The post Go… First seen on securityweek.com Jump to article: www.securityweek.com/google-now-offering-up-to-250000-for-chrome-vulnerabilities/
-
Another critical SolarWinds Web Help Desk bug fixed (CVE-2024-28987)
A week after SolarWinds released a fix for a critical code-injection-to-RCE vulnerability (CVE-2024-28986) in Web Help Desk (WHD), another patch for a… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/08/23/cve-2024-28987/
-
SolarWinds: Critical RCE Bug Requires Urgent Patch
First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/solarwinds-critical-rce-bug-requires-urgent-patch
-
Traccar 5 Remote Code Execution Vulnerabilities
This post walks through the vulnerabilities we disclosed affecting Gradio, and our work with Hugging Face to harden the Spaces platform after a recent… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/08/traccar-5-remote-code-execution-vulnerabilities/
-
Novel Msupedge backdoor deployed via patched PHP RCE exploit
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/novel-msupedge-backdoor-deployed-via-patched-php-rce-exploit
-
Passwort Folge 11: News von Windows-RCE bis zu ungeheimen Geheimnissen
In der elften Folge des Podcasts schauen sich Sylvester und Christopher den aktuellen Windows-IPv6-Bug an, reden über Phishing, Malvertising und mehr…. First seen on heise.de Jump to article: www.heise.de/news/Passwort-Folge-11-News-von-Windows-RCE-bis-zu-ungeheimen-Geheimnissen-9838216.html
-
CISA Warns of Critical SolarWinds RCE Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning regarding a newly discovered vulnerability in SolarWind… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/08/cisa-warns-of-critical-solarwinds-rce-vulnerability-exploited-in-attacks/
-
From Object Transition To RCE In The Chrome Renderer
First seen on packetstormsecurity.com Jump to article: packetstormsecurity.com/news/view/36219/From-Object-Transition-To-RCE-In-The-Chrome-Renderer.html
-
Attacks Leveraging Critical SolarWinds RCE Underway
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/cisa-attacks-leveraging-critical-solarwinds-rce-underway
-
Attacks Leveraging Critical SolarWinds Remote Code Execution Underway
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/cisa-attacks-leveraging-critical-solarwinds-remote-code-execution-underway
-
CISA warns of Jenkins RCE bug exploited in ransomware attacks
‹CISA has added a critical Jenkins vulnerability that can be exploited to gain remote code execution to its catalog of security bugs, warning that it’… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-warns-of-jenkins-rce-bug-exploited-in-ransomware-attacks/
-
Critical Flaw in Donation Plugin Exposed 100,000 WordPress Sites to Takeover
A critical vulnerability in the GiveWP WordPress plugin could be exploited for remote code execution and arbitrary file deletion. The post Critical Fl… First seen on securityweek.com Jump to article: www.securityweek.com/critical-flaw-in-donation-plugin-exposed-100000-wordpress-sites-to-takeover/
-
Critical Remote Code Execution Vulnerability Addressed in GiveWP Plugin
The GiveWP plugin, a widely used donation and fundraising tool for WordPress, has recently undergone a crucial update to address a severe security fla… First seen on thecyberexpress.com Jump to article: thecyberexpress.com/critical-givewp-vulnerability-fixed/
-
SolarWinds Urges Upgrade After Revealing Critical RCE Bug
First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/solarwinds-upgrade-critical-rce-bug/
-
Unauthenticated RCE in WordPress Plugin Exposes 100,000 WordPress Sites
A critical vulnerability has been discovered in the GiveWP plugin, a popular WordPress donation and fundraising platform. This vulnerability, CVE-2024… First seen on gbhackers.com Jump to article: gbhackers.com/unauthenticated-rce-in-wordpress-plugin/
-
Microsoft Patched 6 Actively Exploited Zero-Day Flaws
Patch Tuesday brought updates for 90 security vulnerabilities, including patching severe remote code execution vulnerabilities and closing some doors … First seen on techrepublic.com Jump to article: www.techrepublic.com/article/microsoft-zero-day-vulnerabilities-exploited/
-
Microsoft Reveals Four OpenVPN Flaws Leading to Potential RCE and LPE
Microsoft on Thursday disclosed four medium-severity security flaws in the open-source OpenVPN software that could be chained to achieve remote code e… First seen on thehackernews.com Jump to article: thehackernews.com/2024/08/microsoft-reveals-four-openvpn-flaws.html
-
Experts Uncover Severe AWS Flaws Leading to RCE, Data Theft, and Full-Service Takeovers
Cybersecurity researchers have discovered multiple critical flaws in Amazon Web Services (AWS) offerings that, if successfully exploited, could result… First seen on thehackernews.com Jump to article: thehackernews.com/2024/08/experts-uncover-severe-aws-flaws.html
-
CISA warns critical SolarWinds RCE bug is exploited in attacks
CISA warned on Thursday that attackers are exploiting a recently patched critical vulnerability in SolarWinds’ Web Help Desk solution for customer sup… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-warns-critical-solarwinds-rce-bug-is-exploited-in-attacks/

