Security Online

WorkflowKit Race Vulnerability (CVE-2024-27821): Researcher Reveals Exploit that Let Malicious Apps Hijack Shortcuts

This vulnerability, dubbed the “WorkflowKit Race Vulnerability,” targets the extraction and signing processes of shortcuts within WorkflowKit, potentially allowing a malicious app to intercept and modify shortcut files during import.

CVE-2024-42450 (CVSS 10): Versa Networks Addresses Critical Vulnerability in Versa Director

Versa Networks has issued a security advisory addressing a critical vulnerability (CVE-2024-42450) affecting its Versa Director software. The vulnerability, carries a CVSS score of 10, could allow unauthenticated attackers to access sensitive data.

CVE-2024-10220: Kubernetes Vulnerability Allows Arbitrary Command Execution

A high-severity vulnerability has been discovered in Kubernetes, potentially allowing attackers to execute arbitrary commands outside of container boundaries. It is tracked as CVE-2024-10220 and assigned a CVSS score of 8.1.

CVE-2024-51503: Trend Micro Deep Security Agent RCE Vulnerability Fixed

A recently discovered vulnerability in the Trend Micro Deep Security 20 Agent could have allowed attackers to execute arbitrary code on affected machines. The vulnerability, identified as CVE-2024-51503, has been addressed in the latest update.

CVE-2024-47533 (CVSS 9.8): Cobbler Vulnerability Exposes Linux Servers to Compromise

A critical vulnerability has been discovered in Cobbler, a popular Linux installation server used for network-based deployments. The vulnerability is tracked as CVE-2024-47533 and assigned a CVSS score of 9.8.

CVE-2024-21287: Critical Zero-Day Exploited in Oracle Agile PLM

Oracle has issued an urgent security alert regarding a critical vulnerability in its Agile PLM software, tracked as CVE-2024-21287. This flaw allows attackers to remotely access sensitive files without any authentication.

CVE-2024-21697: High Severity Flaw in Sourcetree Enables Remote Code Execution

Atlassian has issued a security advisory warning of a critical remote code execution (RCE) vulnerability in its popular Sourcetree software for Mac and Windows. It is tracked as CVE-2024-21697 and scores an 8.8 on the CVSS scale.

Google Chrome Patches High-Severity Flaw CVE-2024-11395 in Latest Stable Release

Google has released a new stable version of its Chrome browser for desktop, addressing three security vulnerabilities. The update, versions 131.0.6778.85/.86 for Windows and Mac and 131.0.6778.85 for Linux, is rolling out to users.

CISA Warns of Actively Exploited Vulnerabilities in Kemp LoadMaster and Palo Alto Networks PAN-OS

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about three actively exploited vulnerabilities affecting popular networking and security products.

LibreNMS Vulnerability (CVE-2024-51092): Mitigating the Risk of Server Compromise

A recent security advisory from the LibreNMS project has revealed a severe vulnerability (CVE-2024-51092) affecting versions up to 24.9.1 of the widely-used network monitoring platform. The flaw is rated a critical 9.1 on the CVSS scale.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags