Vulnerabilities | News, how-tos, features, reviews, and videos
A successful attacker could view sensitive information that even admins can’t access.
The vendor has issued a patch to close four holes in its flagship Backup & Replication suite; version 13 users are advised to audit their backup config files and closely monitor backup jobs.
“Threat actors are actively attempting to exploit this vulnerability in the wild,” warns vendor.
An unauthenticated user can execute the attack, and there’s no mitigation, just a hotfix that should be applied immediately.
Flaws in Fluent Bit could let attackers inject fake logs, reroute telemetry, and execute arbitrary code across cloud platforms.
There’s no evidence of exploitation but sysadmins will want to check their environments.
Researchers uncover problems with firmware validation checks and Root of Trust.
Static root credentials left in limited Unified Communications Manager builds could let attackers gain full control over enterprise communications systems.
CISA has added CVE-2024-54085 to its known exploited vulnerabilities list as enterprises struggle with incomplete vendor patches.
Security experts call vulnerability a 'textbook case' of dangerous coding practices; Cisco issues urgent patch.