Tag: remote-code-execution
-
New OpenSSH Vulnerability Could Lead to RCE as Root on Linux Systems
OpenSSH maintainers have released security updates to contain a critical security flaw that could result in unauthenticated remote code execution with… First seen on thehackernews.com Jump to article: thehackernews.com/2024/07/new-openssh-vulnerability-could-lead-to.html
-
Only one critical issue disclosed as part of Microsoft Patch Tuesday
The lone critical security issue is a remote code execution vulnerability due to a use-after-free issue in the HTTP handling function of Microsoft Mes… First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/only-one-critical-issue-disclosed-as-part-of-microsoft-patch-tuesday/
-
Prompt Injection Flaw in Vanna AI Exposes Databases to RCE Attacks
Cybersecurity researchers have disclosed a high-severity security flaw in the Vanna.AI library that could be exploited to achieve remote code executio… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/prompt-injection-flaw-in-vanna-ai.html
-
RCE bug in widely used Ghostscript library now exploited in attacks
A remote code execution vulnerability in the Ghostscript document conversion toolkit, widely used on Linux systems, is currently being exploited in at… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/rce-bug-in-widely-used-ghostscript-library-now-exploited-in-attacks/
-
Attackers Exploiting Remote Code Execution Vulnerability in Ghostscript
Vulnerability in Ghostscript (CVE-2024-29510) allows attackers to bypass sandbox for remote code execution. The post Attackers Exploiting Remote Code … First seen on securityweek.com Jump to article: www.securityweek.com/attackers-exploiting-remote-code-execution-vulnerability-in-ghostscript/
-
USENIX Security ’23 Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js
Tags: remote-code-executionAuthors/Presenters:Mikhail Shcherbakov, Musard Balliu, Cristian-Alexandru Staicu Many thanks to USENIX for publishing their outstanding USENIX Securit… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/usenix-security-23-silent-spring-prototype-pollution-leads-to-remote-code-execution-in-node-js/
-
Vanna AI Prompt Injection Vulnerability Enables RCE
First seen on packetstormsecurity.com Jump to article: packetstormsecurity.com/news/view/36048/Vanna-AI-Prompt-Injection-Vulnerability-Enables-RCE.html
-
Critical OpenSSH Flaw Enables Full System Compromise
A newly discovered RCE vulnerability, which can lead to full system compromise, has put over 14 million OpenSSH server instances are potentially at ri… First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/openssh-flaw-system-compromise/
-
Critical RCE Vulnerability Discovered in Ollama AI Infrastructure Tool
Tags: ai, cybersecurity, flaw, infrastructure, intelligence, open-source, rce, remote-code-execution, tool, update, vulnerabilityCybersecurity researchers have detailed a now-patch security flaw affecting the Ollama open-source artificial intelligence (AI) infrastructure platfor… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/critical-rce-vulnerability-discovered.html
-
Threat Actor Claiming of Sandbox Escape RCE in 0-day Google Chrome
Threat Actor has claimed to have discovered a critical zero-day vulnerability in Google Chrome. This exploit, which reportedly enables a sandbox escap… First seen on gbhackers.com Jump to article: gbhackers.com/claiming-sandboxrce-0-day/
-
Patched: RCE Flaw That Affects Critical Manufacturing
Hackers Have Not Yet Exploited the CVSS 10-Rated Flaw, Says PTC. Software maker for critical manufacturing organizations PTC patched a critical flaw t… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/patched-rce-flaw-that-affects-critical-manufacturing-a-25699
-
Critical unauthenticated remote code execution flaw in OpenSSH server
A critical flaw in the OpenSSH server can be exploited to achieve unauthenticated remote code execution with root privileges in glibc-based Linux syst… First seen on securityaffairs.com Jump to article: securityaffairs.com/165087/security/openssh-server-critical-flaw.html
-
New regreSSHion OpenSSH RCE bug gives root on Linux servers
First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-regresshion-openssh-rce-bug-gives-root-on-linux-servers/
-
Probllama: Ollama Remote Code Execution Vulnerability
First seen on packetstormsecurity.com Jump to article: packetstormsecurity.com/news/view/36037/Probllama-Ollama-Remote-Code-Execution-Vulnerability.html
-
Splunk Patches High-Severity Vulnerabilities in Enterprise Product
Splunk has patched multiple vulnerabilities in Splunk Enterprise, including high-severity remote code execution bugs. The post as patched multiple vul… First seen on securityweek.com Jump to article: www.securityweek.com/splunk-patches-high-severity-vulnerabilities-in-enterprise-product/
-
Hackers Claiming of Sandbox Escape RCE in 0-DAY Google Chrome
Tags: browser, chrome, exploit, google, group, hacker, rce, remote-code-execution, vulnerability, zero-dayA group of hackers has claimed to have discovered a critical zero-day vulnerability in Google Chrome. This exploit, which reportedly enables a sandbox… First seen on gbhackers.com Jump to article: gbhackers.com/claiming-sandboxrce-0-day/
-
‘Perfect 10’ Apple Supply Chain Bug, Millions of Apps at Risk of CocoaPods RCE
First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/cocoapods-apple-vulns-richixbw/
-
regreSSHion OpenSSH RCE Vulnerability Impacts 700K Linux Systems
The Qualys Threat Research Unit has identified a newly discovered vulnerability in OpenSSH, dubbed >>regreSSHion
-
OpenSSH Remote Code Execution Vulnerability (CVE-2024-6387) Notification
Overview Recently, NSFOCUS CERT detected that OpenSSH issued a security announcement and fixed the remote code execution vulnerability of OpenSSH (CVE… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/openssh-remote-code-execution-vulnerability-cve-2024-6387-notification/
-
Millions of OpenSSH Servers Potentially Vulnerable to Remote regreSSHion Attack
Millions of OpenSSH servers could be vulnerable to unauthenticated remote code execution due to a vulnerability tracked as regreSSHion and CVE-2024-63… First seen on securityweek.com Jump to article: www.securityweek.com/millions-of-openssh-servers-potentially-vulnerable-to-remote-regresshion-attack/
-
regreSSHion RCE Flaw Impacts 700K Linux Systems
The Qualys Threat Research Unit has identified a newly discovered vulnerability in OpenSSH, dubbed >>regreSSHion
-
regreSSHion: RCE Vulnerability in OpenSSH Server (CVE-2024-6387)
First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/regresshion-rce-vulnerability-in-openssh-server-cve-2024-6387/
-
Mailcow Mail Server Flaws Expose Servers to Remote Code Execution
Two security vulnerabilities have been disclosed in the Mailcow open-source mail server suite that could be exploited by malicious actors to achieve a… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/mailcow-mail-server-flaws-expose.html
-
Critical VMware Bugs Open Swaths of VMs to RCE, Data Theft
First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/critical-vmware-bugs-open-swaths-of-vms-to-rce-data-theft
-
Threat Actor Claims 0Day Sandbox Escape RCE in Chrome Browser
A threat actor has claimed to have discovered a zero-day vulnerability in the widely-used Google Chrome browser. The claim was made public via a tweet… First seen on gbhackers.com Jump to article: gbhackers.com/threat-actor-claims-0day-sandbox-escape-rce-in-chrome-browser/
-
Patched Weeks Ago, RCE Bug in AI Tool Still a ‘Probllama’
Companies Eager for Tools Are Putting AI’s Transformative Power Ahead of Security. Hackers targeting a popular open-source project for running artific… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/patched-weeks-ago-rce-bug-in-ai-tool-still-probllama-a-25611
-
New Ollama RCE vulnerability immediately fixed
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/new-ollama-rce-vulnerability-immediately-fixed
-
POC exploit code published for 9.8-rated Apache HugeGraph RCE flaw
First seen on theregister.com Jump to article: www.theregister.com/2024/06/07/poc_apache_hugegraph/
-
Week in review: CDK Global cyberattack, critical vCenter Server RCE fixed
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: The rise of SaaS security teams In this Help Net Sec… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/23/week-in-review-cdk-global-cyberattack-vcenter-server-critical-rce-fixed/
-
Vulnerability Recap 6/10/24 RCE Attacks in Major Platforms
First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/vulnerability-recap-june-10-2024/

