Tag: remote-code-execution
-
Week in review: Veeam fixes RCE flaw in backup management platform, Patch Tuesday forecast
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Veeam fixes RCE flaw in backup management platform (… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/05/12/week-in-review-veeam-fixes-rce-flaw-in-backup-management-platform-patch-tuesday-forecast/
-
Cinterion Modem Flaws Pose Risk to Millions of Devices in Industrial, Other Sectors
A critical vulnerability in the Cinterion cellular modems can be exploited for remote code execution via SMS messages. The post al vulnerability in th… First seen on securityweek.com Jump to article: www.securityweek.com/cinterion-modem-flaws-pose-risk-to-millions-of-devices-in-industrial-other-sectors/
-
Apache OFBiz RCE Flaw Let Attackers Execute Malicious Code Remotely
Many businesses use enterprise resource planning (ERP) systems like Apache OFBiz. However, it has been found to have significant security holes that l… First seen on gbhackers.com Jump to article: gbhackers.com/apache-ofbiz-rce-flaw/
-
HPE Aruba Vulnerabilities: Prevent Systems From RCE Attacks
Recently, HPE Aruba Networking, formerly known as Aruba Networks, has encountered significant security challenges. Vulnerabilities in their ArubaOS, t… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/hpe-aruba-vulnerabilities-prevent-systems-from-rce-attacks/
-
Most Tinyproxy Instances are potentially vulnerable to flaw CVE-2023-49606
A critical Remote Code Execution vulnerability in the Tinyproxy service potentially impacted 50,000 Internet-Exposing hosts. Researchers from Cisco Ta… First seen on securityaffairs.com Jump to article: securityaffairs.com/162866/hacking/tinyproxy-rce.html
-
Patch up 4 critical bugs in ArubaOS lead to remote code execution
First seen on theregister.com Jump to article: www.theregister.com/2024/05/02/hpe_aruba_patches/
-
Veeam fixes RCE flaw in backup management platform (CVE-2024-29212)
Veeam has patched a high-severity vulnerability (CVE-2024-29212) in Veeam Service Provider Console (VSPC) and is urging customers to implement the pat… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/05/08/cve-2024-29212/
-
Widespread RCE compromise likely with critical TinyProxy bug
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/widespread-rce-compromise-likely-with-critical-tinyproxy-bug
-
Veeam RCE Flaws Let Hackers Gain Access To VSPC Servers
Veeam Service Provider console has been discovered with two critical vulnerabilities that were associated with Remote Code Execution. A CVE for these … First seen on gbhackers.com Jump to article: gbhackers.com/veeam-rce-flaws-vspc-servers/
-
Palo Alto Networks discloses RCE zero-day vulnerability
Tags: exploit, flaw, injection, network, rce, remote-code-execution, software, threat, vulnerability, zero-dayThreat actors have exploited the remote code injection flaw, which affects the GlobalProtect gateway in Palo Alto Networks’ PAN-OS software, in a ‘lim… First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366580732/Palo-Alto-Networks-discloses-RCE-zero-day-vulnerability
-
Over 50,000 Tinyproxy servers vulnerable to critical RCE flaw
First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/over-50-000-tinyproxy-servers-vulnerable-to-critical-rce-flaw/
-
Bug hunters can get up to $450,000 for an RCE in Google’s Android apps
Google has drastically increased the rewards bug hunters can get for reporting vulnerabilities in Android apps it develops and maintains. >>We increas… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/05/03/google-android-apps-vulnerabilities/
-
HPE Aruba Networking addressed four critical ArubaOS RCE flaws
HPE Aruba Networking addressed four critical remote code execution vulnerabilities impacting its ArubaOS network operating system. HPE Aruba Networkin… First seen on securityaffairs.com Jump to article: securityaffairs.com/162663/security/hpe-aruba-networking-critical-flaws.html
-
HPE Aruba Networking fixes four critical RCE flaws in ArubaOS
HPE Aruba Networking has issued its April 2024 security advisory detailing critical remote code execution (RCE) vulnerabilities impacting multiple ver… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hpe-aruba-networking-fixes-four-critical-rce-flaws-in-arubaos/
-
Google now pays up to $450,000 for RCE bugs in some Android apps
Google has increased rewards for reporting remote code execution vulnerabilities within select Android apps by ten times, from $30,000 to $300,000, wi… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/google-now-pays-up-to-450-000-for-rce-bugs-in-some-android-apps/
-
Patched Deserialization Flaw in Siemens Product Allows RCE
The Siemens Simatic Energy Manager Used an Unsafe BinaryFormatter Method. Researchers detailed a deserialization vulnerability in Siemens software use… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/patched-deserialization-flaw-in-siemens-product-allows-rce-a-24980
-
Beware! Zero-click RCE Exploit for iMessage Circulating on Hacker Forums
A new cybersecurity threat has emerged as a zero-click remote code execution (RCE) exploit targeting Apple’s iMessage service is reportedly being circ… First seen on gbhackers.com Jump to article: gbhackers.com/beware-zero-click-rce-exploit/
-
Multiple MySQL2 Flaw Let Attackers Arbitrary Code Remotely
The widely used MySQL2 has been discovered to have three critical vulnerabilities: remote Code execution, Arbitrary code injection, and Prototype Poll… First seen on gbhackers.com Jump to article: gbhackers.com/multiple-mysql2-flaws-remote-code-execution/
-
Active Kubernetes RCE Attack Relies on Known OpenMetadata Vulns
Once attackers have control over a workload in the cluster, they can leverage access for lateral movement both inside the cluster and to external reso… First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/active-kubernetes-rce-attack-relies-on-known-openmetadata-vulns
-
Telegram Desktop: Tippfehler im Quellcode mündet in RCE-Schwachstelle
Ein Tippfehler im Code der Windows-App von Telegram ermöglicht die Ausführung von Schadcode auf fremden Systemen. Es reicht ein Klick auf ein vermeint… First seen on golem.de Jump to article: www.golem.de/news/telegram-desktop-tippfehler-im-quellcode-muendet-in-rce-schwachstelle-2404-184135.html
-
Hackers hijack OpenMetadata apps in Kubernetes cryptomining attacks
In an ongoing Kubernetes cryptomining campaign, attackers target OpenMetadata workloads using critical remote code execution and authentication vulner… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-hijack-openmetadata-apps-in-kubernetes-cryptomining-attacks/
-
Vulnerabilities for AI and ML Applications are Skyrocketing
In their haste to deploy LLM tools, organizations may overlook crucial security practices. The rise in threats like Remote Code Execution indicates an… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/04/vulnerabilities-for-ai-and-ml-applications-are-skyrocketing/
-
Microsoft .NET, .NET Framework, Visual Studio Vulnerable To RCE Attacks
A new remote code execution vulnerability has been identified to be affecting multiple Microsoft products including .NET, .NET Framework and Visual St… First seen on gbhackers.com Jump to article: gbhackers.com/microsoft-net-rce-vulnerability/
-
Critical RCE Vulnerability in 92,000 D-Link NAS Devices
Cyber attacks have become increasingly prevalent. This has caused significant adverse impacts on businesses of all sizes. According to the latest Pone… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/04/critical-rce-vulnerability-in-92000-d-link-nas-devices/
-
Alert! Palo Alto RCE Zero-day Vulnerability Actively Exploited in the Wild
In a recent security bulletin, Palo Alto Networks disclosed a critical vulnerability in its GlobalProtect Gateway, identified as CVE-2024-3400. This f… First seen on gbhackers.com Jump to article: gbhackers.com/alert-palo-alto-rce-zero-day-vulnerability-actively-exploited-in-the-wild/
-
March Patch Tuesday fixes critical Hyper-V vulnerabilities
Microsoft also corrects a remote-code execution flaw on Exchange Server and issues an advisory related to changes with an outdated file-scanning featu… First seen on techtarget.com Jump to article: www.techtarget.com/searchwindowsserver/news/366573352/March-Patch-Tuesday-fixes-critical-Hyper-V-vulnerabilities
-
How to track and stop CVE-2024-3400: Palo Alto Devices API Exploit Causing Critical Infrastructure and Enterprise Epidemics
On Friday April 12, Palo Alto disclosed that some versions of PAN-OS are not only vulnerable to remote code execution, but that the vulnerability has … First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/04/how-to-track-and-stop-cve-2024-3400-palo-alto-devices-api-exploit-causing-critical-infrastructure-and-enterprise-epidemics/
-
Malicious Code in XZ Utils for Linux Systems Enables Remote Code Execution
The malicious code inserted into the open-source library XZ Utils, a widely used package present in major Linux distributions, is also capable of faci… First seen on thehackernews.com Jump to article: thehackernews.com/2024/04/malicious-code-in-xz-utils-for-linux.html
-
Fortinet fixed a critical remote code execution bug in FortiClientLinux
Fortinet addressed multiple issues in FortiOS and other products, including a critical remote code execution flaw in FortiClientLinux. Fortinet fixed … First seen on securityaffairs.com Jump to article: securityaffairs.com/161674/security/forticlientlinux-rce.html
-
Fortinet patches FortiClientLinux critical RCE vulnerability
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/fortinet-patches-forticlientlinux-critical-rce-vulnerability

