Vulnerabilities — Page 21

You Don't Need to Fire the Exploit to Know You're Exposed
A quieter way to test whether a vulnerability actually threatens your network: check the steps an attacker would need, not the payload itself.

Seven Security Flaws Fixed in VMware Avi Load Balancer, One Rated Critical
Broadcom has patched a critical flaw that lets attackers break into a core networking component without a password, plus six more serious bugs found by two outside researchers.

Popular AI Coding Tool Cursor Runs Malicious Files Automatically, Researcher Warns
A security firm reported the flaw seven months ago. Cursor has yet to patch it.

Eleven Old Microsoft-Signed Boot Files Could Let Hackers Slip Past Secure Boot
Researchers say the signed UEFI applications, still trusted by most PCs, can be used to load malicious code before Windows even starts.

KU Leuven Researchers Find 85 Browser Crypto Wallets Leak User Data
Academic study says the way popular wallet extensions talk to websites lets outsiders link separate crypto addresses to the same person.

SAP Patches Critical Flaws in NetWeaver, Approuter, and Commerce Cloud
Three SAP products used by thousands of businesses worldwide carried serious security holes. Patches are now available, and anyone running the affected software should move fast.

CISA flags active attacks on two Joomla add-ons that let hackers take over websites
Old flaws in the iCagenda and Balbooa Forms extensions are being used to plant malicious files on Joomla sites, and the U.S. cyber agency has given federal bodies three weeks to patch.

A Hidden Door in RabbitMQ Left Company Systems Wide Open for Two Years
A flaw in the popular messaging software handed anyone on the network a master key to company data. Patches are out. Use them now.

Two Security Flaws in RabbitMQ Could Let Attackers Steal Login Secrets and Take Over Corporate Messaging Systems
A widely used software tool that moves data between business applications has patched two vulnerabilities, one of which could hand criminals full control over the system without a password.

Hackers Are Breaking Into Websites Through Two Popular Joomla Add-Ons
Two widely used plugins for the Joomla website-building platform have critical security flaws that let criminals take full control of a site without needing a password. Patches exist, but attacks started before most site owners knew there was a problem.

US Cyber Agency Flags Two Joomla Add-On Flaws Already Being Exploited
CISA says attackers are actively abusing critical bugs in the iCagenda and Balbooa extensions, both scored a perfect 10 on the severity scale.

Australia sounds the alarm: hackers are hijacking small business websites at scale
The Australian Cyber Security Centre says a worldwide campaign is planting hidden backdoors on sites running WordPress, Joomla, Craft CMS and more, with small businesses bearing the brunt.

Zimbra Patches Critical Webmail Flaw That Lets Booby-Trapped Emails Run Code
A stored cross-site scripting bug in Zimbra's Classic Web Client can hijack a user's session the moment a rigged email is opened.

Six bugs in U-Boot bootloader open the door to hidden firmware attacks
Researchers found flaws in the open-source code that starts up millions of embedded devices, from routers to industrial kit. Fixes are out.

Six New Bugs in U-Boot Could Let Attackers Hijack Devices at Startup
Binarly researchers found flaws in the tiny program that boots routers, cameras and server chips. Two of them could let intruders run their own code before the device even wakes up.