Vulnerability

Chinese Hackers Exploiting VMware 0-Day Flaw Since 2021

Mandiant and VMware recently uncovered a sophisticated cyber espionage campaign. The attackers, a Chinese group identified as UNC3886, leveraged a…

11 months ago

Researchers Use Raspberry Pi Pico to Crack BitLocker Under a Minute

BitLocker is a computer program provided by Microsoft that users can use to encrypt their entire volumes, preventing unauthorized access…

11 months ago

Critical Cisco Expressway Flaw Let Remote Execute Arbitrary Code

Cisco released patches to address multiple vulnerabilities in the Cisco Expressway Series that might allow an attacker to do arbitrary…

11 months ago

Active Scan Alert: Over 28,000 Ivanti Instances Exposed to Internet

Ivanti has disclosed two new zero-day vulnerabilities assigned with CVE-2024-21888 and CVE-2024-21893 in the products Ivanti Connect Secure and Ivanti…

11 months ago

TeamCity Authentication Bypass Flaw Let Attackers Gain Admin Control

A critical security vulnerability was detected in TeamCity On-Premises, tagged as CVE-2024-23917, with a CVSS score of 9.8. An unauthenticated attacker…

11 months ago

Multiple Container Flaws Allow Attackers to Access the Host OS

Four new vulnerabilities have been identified in containers that could allow a threat actor to escape the container and gain…

11 months ago

What is SaaS Sprawl? Guide to Combating SaaS Security Risks

When we talk about the cloud, it's not just a matter of data drifting weightlessly in some digital ether. The…

11 months ago

Ivanti discloses 2 New zero-days, one already under exploitation

Two new zero-day vulnerabilities have been discovered in Ivanti Connect Secure and Ivanti Policy Secure products that are assigned with…

11 months ago

Mercedes-Benz Source Code Leaked via mishandled GitHub token

Mercedes-Benz has been reported to have leaked its source code due to a GitHub token leak from an organization employee.…

12 months ago

45K+ Exposed Jenkins Instances Vulnerable to RCE Attacks

It was previously reported that Jenkins was discovered with a new critical vulnerability, which was associated with unauthenticated arbitrary file…

12 months ago