#patch
22 stories taggedpatch.

Microsoft Pushes 22 Security Fixes, Six Rated Maximum Severity
A batch of patches covers Microsoft's cloud and identity products, with six flaws scoring a perfect 10 out of 10 on the severity scale. Most fixes apply automatically, but one Defender vulnerability is still waiting for a patch.

Citrix Patches Critical Login-Bypass Flaw in NetScaler, Attacks Expected Soon
A security hole rated 9.3 out of 10 lets criminals walk straight past the login screen on widely used corporate network gear. Patches are out now, and researchers say exploitation is a matter of when, not if.

$58 Certificate, Four Flaws: Researchers Show How SCCM Can Hand Attackers the Keys to an Entire Company
A security research team chained together four weaknesses in Microsoft's enterprise device-management software to reach full system control, starting with nothing more than a standard company login.

SonicWall Patches Critical Flaws in a Security Platform It Already Retired
Two vulnerabilities scored near-perfect danger ratings and could let criminals break into systems without a password. One of the affected products was officially shut down last October.

Zoom Had a Flaw That Let Hackers Take Over Your Computer During a Meeting, Without You Clicking Anything
A vulnerability in Zoom's annotation feature gave attackers a direct path to run code on any participant's machine. Patches are out now.

Google Patches 41 Security Flaws in Chrome 151, Six Rated Critical
The latest Chrome update fixes a cluster of memory-safety bugs that could let attackers crash your browser or run malicious code on your device. Here is what happened and what you should do.

Hackers Are Actively Exploiting a Critical Flaw in JetBrains TeamCity
A software tool used by thousands of development teams worldwide has a severe security hole that attackers are already using. The US government is telling federal agencies they have three days to fix it.

Broadcom Patches Critical 'VM Escape' Flaw in VMware ESXi, Plus Four More Vulnerabilities
Five security flaws, three rated critical, have been fixed across VMware's most widely-used virtualisation products. One lets an attacker break out of a contained virtual machine and reach the underlying server it runs on.

OpenAI Patches ChatGPT Flaw That Let Attackers Plant an Invisible AI Agent Inside a Company
A vulnerability called AgentForger meant a criminal could quietly create a rogue AI assistant inside a victim organisation, give it instructions, and control it from the outside.

A Browser Extension Installed 300 Million Times Had a Flaw That Let Attackers Steal Your WhatsApp Messages
A security hole in Adobe's widely used browser extension meant that simply visiting the wrong website could hand criminals your private messages and contacts.

Zimbra Patches Six Security Flaws, Including a Bug That Lets Strangers Run Commands on Your Email Server
The business email platform Zimbra has released a batch of fixes covering a serious command-injection flaw and five other vulnerabilities. No attacks in the wild have been confirmed, but the company is urging every customer to update immediately.

A Flaw in WordPress's Core Code Lets Criminals Take Over Websites Without Logging In
A newly discovered vulnerability in WordPress versions 6.9 and 7.0 lets attackers run their own commands on any affected site with no password required. Patches are out now.

Zoom patches a flaw that could hand strangers full control of your account
A critical bug in Zoom's Windows software let attackers take over accounts without a password, a click, or any help from the victim. Zoom found it first and patched it. Here is what you need to know.

Splunk and Zoom Fix Security Flaws That Could Let Hackers Take Over Accounts
Both companies pushed out patches this week. One Zoom flaw scores a near-perfect danger rating and could let a criminal break into accounts without knowing a password.

Four Security Firms Patch Serious Flaws in Their Own Products
Tenable, ESET, Tanium, and Trend Micro have all pushed out fixes this month for high- and critical-severity vulnerabilities in tools that businesses rely on to stay secure.