Monday , March 31 2025

Vulnerabilities

SSRF Vulnerability Patched in Bitdefender GravityZone Console On-Premise

Bitdefender

Bitdefender fixed a serious vulnerability (CVE-2024-4177, CVSS 8.1) in its GravityZone Console On-Premise product. This flaw, found by security researcher Nicolas Verdier (n1nj4sec), could enable attackers to carry out server-side request forgery (SSRF) attacks, possibly resulting in unauthorized access and data breaches. GravityZone Console is a security management platform by …

Read More »

SOLARWINDS FIXED MULTIPLE FLAWS IN SERV-U

solarwind

SolarWinds released updates to fix several security issues in Serv-U and the SolarWinds Platform. These vulnerabilities impact Platform 2024.1 SR 1 and older versions. The company fixed a security issue, known as CVE-2024-28996, reported by a penetration tester from NATO. NATO Communications and Information Agency pentester Nils Putnins discovered a …

Read More »

Explore the Latest Monthly Vulnerabilities Report: May 2024

calender

The very month May-2024 is observed a significant increase in cybersecurity vulnerabilities across various software and operating systems. Many of these vulnerabilities have the potential to be exploited by malicious actors, posing a serious risk to organizations and individuals alike. It is crucial for organizations to stay vigilant and prioritize …

Read More »

Zyxel Releases Patches for Firmware Vulnerabilities

zyxel

Zyxel has released patches addressing command injection and remote code execution vulnerabilities in two NAS products that have reached end-of-vulnerability-support. Users are advised to install them for optimal protection. Three out of five vulnerabilities could allow an unauthorized attacker to run operating system commands and arbitrary code on affected installations. …

Read More »

CISA Adds ORACLE WEBLOGIC SERVER FLAW TO ITS KEV

oracle

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added Oracle WebLogic Server to the Known Exploited Vulnerabilities (KEV) catalog. CVE-2017-3506 is an operating system (OS) command injection vulnerability which could be exploited to obtain unauthorized access as well as the full control. “Oracle WebLogic Server, a product within the …

Read More »

ALERT
NGINX Releases Security Updates: HTTP/3 Vulnerabilities Patched

NGINX

NGINX team released important updates for their web server software and is advising users to upgrade as soon as possible. The updates fix four important vulnerabilities in the HTTP/3 implementation, especially affecting configurations using the “ngx_http_v3_module.” CVE-2024-32760: A vulnerability in NGINX Plus or NGINX OSS causes HTTP/3 QUIC module to …

Read More »

First American December data breach impacts 44,000 people

In December 2023, The First American Financial Corporation, a major title insurance company in the US, experienced a cyberattack. This resulted in the personal information of approximately 44,000 individuals being exposed. The company disclosed this data breach to the US Securities and Exchange Commission (SEC) on May 28, 2024. This …

Read More »