Tag: remote-code-execution
-
Samsung to pay $1,000,000 for RCEs on Galaxy’s secure vault
Samsung has launched a new bug bounty program for its mobile devices with rewards of up to $1,000,000 for reports demonstrating critical attack scenar… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/samsung-to-pay-1-000-000-for-rces-on-galaxys-secure-vault/
-
Critical Apache OFBiz pre-auth RCE flaw fixed, update ASAP! (CVE-2024-38856)
CVE-2024-38856, an incorrect authorization vulnerability affecting all but the latest version of Apache OFBiz, may be exploited by remote, unauthentic… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/08/05/cve-2024-38856/
-
Critical Flaw in Telerik Report Server Poses Remote Code Execution Risk
Progress Software is urging users to update their Telerik Report Server instances following the discovery of a critical security flaw that could resul… First seen on thehackernews.com Jump to article: thehackernews.com/2024/07/critical-flaw-in-telerik-report-server.html
-
Schwachstelle in Rockwell Automation PanelView Plus
Microsoft hat zwei Remote Code Execution-Schwachstellen in Rockwell Automation PanelView Plus entdeckt. Diese ermöglichen nicht authentifizierten Angr… First seen on borncity.com Jump to article: www.borncity.com/blog/2024/07/28/schwachstelle-in-rockwell-automation-panelview-plus/
-
Ghostscript Vulnerability Actively Exploited in Attacks
A significant remote code execution (RCE) vulnerability was identified in the Ghostscript library, a widely used tool on Linux systems. This vulnerabi… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/ghostscript-vulnerability-actively-exploited-in-attacks/
-
New Specula tool uses Outlook for remote code execution in Windows
Microsoft Outlook can be turned into a C2 beacon to remotely execute code, as demonstrated by a new red team post-exploitation framework named Specula… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-specula-tool-uses-outlook-for-remote-code-execution-in-windows/
-
PatchNow: ServiceNow Critical RCE Bugs Under Active Exploit
First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/patchnow-servicenow-critical-rce-bugs-active-exploit
-
Progress Patches Critical Telerik Report Server Vulnerability
Progress Software calls attention to a critical remote code execution flaw in the Telerik Report Server product. The post Progress Patches Critical Te… First seen on securityweek.com Jump to article: www.securityweek.com/progress-patches-critical-telerik-report-server-vulnerability/
-
Progress fixes critical RCE flaw in Telerik Report Server, upgrade ASAP! (CVE-2024-6327)
Progress Software has fixed a critical vulnerability (CVE-2024-6327) in its Telerik Report Server solution and is urging users to upgrade as soon as p… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/07/26/cve-2024-6327/
-
Attacks exploiting critical ServiceNow RCE bugs underway
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/attacks-exploiting-critical-servicenow-rce-bugs-underway
-
Progress Software fixed critical RCE CVE-2024-6327 in the Telerik Report Server
Progress Software addressed a critical remote code execution vulnerability, tracked as CVE-2024-6327, in the Telerik Report Server. Telerik Report Ser… First seen on securityaffairs.com Jump to article: securityaffairs.com/166168/security/telerik-report-server-cve-2024-6327.html
-
Critical ServiceNow RCE flaws actively exploited to steal credentials
Tags: breach, credentials, data, exploit, flaw, government, rce, remote-code-execution, theft, threatThreat actors are chaining together ServiceNow flaws using publicly available exploits to breach government agencies and private firms in data theft a… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-servicenow-rce-flaws-actively-exploited-to-steal-credentials/
-
Progress warns of critical RCE bug in Telerik Report Server
Progress Software has warned customers to patch a critical remote code execution security flaw in the Telerik Report Server that can be used to compro… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/progress-warns-of-critical-rce-bug-in-telerik-report-server/
-
CISA Warns of Actively Exploited RCE Flaw in GeoServer GeoTools Software
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical security flaw impacting OSGeo GeoServer GeoTools to its Kn… First seen on thehackernews.com Jump to article: thehackernews.com/2024/07/cisa-warns-of-actively-exploited-rce.html
-
Hackers are actively exploiting PHP RCE vulnerability (CVE-2024-4577)
A critical vulnerability in PHP, designated CVE-2024-4577, has become a prime target for cybercriminals within a day of its public disclosure in June … First seen on securityonline.info Jump to article: securityonline.info/hackers-are-actively-exploiting-php-rce-vulnerability-cve-2024-4577/
-
RCE flaw and DNS zero-day top list of Patch Tuesday bugs
Tags: authentication, dns, flaw, microsoft, rce, remote-code-execution, update, vulnerability, zero-dayAn RCE vulnerability in a Microsoft messaging feature and a third-party flaw in a DNS authentication protocol are the most pressing issues to address … First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366588458/RCE-flaw-and-DNS-zero-day-top-list-of-Patch-Tuesday-bugs
-
New OpenSSH Vulnerability Discovered: Potential Remote Code Execution Risk
Select versions of the OpenSSH secure networking suite are susceptible to a new vulnerability that can trigger remote code execution (RCE).The vulnera… First seen on thehackernews.com Jump to article: thehackernews.com/2024/07/new-openssh-vulnerability-discovered.html
-
Microsoft delivers 51 fixes for June Patch Tuesday
A critical remote-code execution flaw in Windows and a denial-of-service vulnerability affecting DNS in Windows Server top the list of patching priori… First seen on techtarget.com Jump to article: www.techtarget.com/searchwindowsserver/news/366588484/Microsoft-delivers-51-fixes-for-June-Patch-Tuesday
-
CISA warns critical Geoserver GeoTools RCE flaw is exploited in attacks
First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-warns-critical-geoserver-geotools-rce-flaw-is-exploited-in-attacks/
-
Critical OpenSSH Vulnerability (regreSSHion) Gives Root Access
An unauthenticated remote code execution vulnerability (CVE-2024-6387) was discovered in OpenSSH, a widely used tool for secure remote access. Dubbed … First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/critical-openssh-vulnerability-regresshion-gives-root-access/
-
Microsoft Says Windows Not Impacted by regreSSHion as Second OpenSSH Bug Is Found
A second remote code execution vulnerability, tracked as CVE-2024-6409, was found in OpenSSH during an analysis of the regreSSHion flaw. The post Micr… First seen on securityweek.com Jump to article: www.securityweek.com/microsoft-says-windows-not-impacted-by-regresshion-as-second-openssh-bug-is-found/
-
Microsoft Outlook Faced Critical Zero-Click RCE Vulnerability
First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/microsoft-outlook-zero-click-rce/
-
PHP bug executes RCEs, cryptominers and DDoS attacks
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/php-bug-executes-rces-cryptominers-and-ddos-attacks
-
Active exploitation of Ghostscript RCE underway
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/active-exploitation-of-ghostscript-rce-underway
-
A new flaw in OpenSSH can lead to remote code execution
A vulnerability affects some versions of the OpenSSH secure networking suite, it can potentially lead to remote code execution. The vulnerability CVE-… First seen on securityaffairs.com Jump to article: securityaffairs.com/165535/hacking/openssh-flaw-cve-2024-6409.html
-
New OpenSSH Vulnerability Could Lead to RCE as Root on Linux Systems
OpenSSH maintainers have released security updates to contain a critical security flaw that could result in unauthenticated remote code execution with… First seen on thehackernews.com Jump to article: thehackernews.com/2024/07/new-openssh-vulnerability-could-lead-to.html
-
Only one critical issue disclosed as part of Microsoft Patch Tuesday
The lone critical security issue is a remote code execution vulnerability due to a use-after-free issue in the HTTP handling function of Microsoft Mes… First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/only-one-critical-issue-disclosed-as-part-of-microsoft-patch-tuesday/
-
Prompt Injection Flaw in Vanna AI Exposes Databases to RCE Attacks
Cybersecurity researchers have disclosed a high-severity security flaw in the Vanna.AI library that could be exploited to achieve remote code executio… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/prompt-injection-flaw-in-vanna-ai.html
-
RCE bug in widely used Ghostscript library now exploited in attacks
A remote code execution vulnerability in the Ghostscript document conversion toolkit, widely used on Linux systems, is currently being exploited in at… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/rce-bug-in-widely-used-ghostscript-library-now-exploited-in-attacks/
-
Attackers Exploiting Remote Code Execution Vulnerability in Ghostscript
Vulnerability in Ghostscript (CVE-2024-29510) allows attackers to bypass sandbox for remote code execution. The post Attackers Exploiting Remote Code … First seen on securityweek.com Jump to article: www.securityweek.com/attackers-exploiting-remote-code-execution-vulnerability-in-ghostscript/

