Skip to content
inionline.net
  • Managed IT Support Services
  • Contact Us
inionline.net

Blog

Your blog category

  • Blog

    Qakbot Delivered Through CVE-2022-30190 (Follina)

    FortiGuard Labs is aware of a report that CVE-2022-30190 is exploited in the wild to deliver Qakbot malware. Currently, a patch is not available for CVE-2022-30190. Also known as Qbot and Pinkslipbot, Qakbot started off as a banking malware. In recent years, Qakbot was seen as a delivery vehicle for other malware, which often results…

    Read More Qakbot Delivered Through CVE-2022-30190 (Follina)Continue

  • Blog

    CISA to the Known Exploited Vulnerabilities Catalog

    FortiGuard Labs is aware that the Cybersecurity & Infrastructure Security Agency (CISA) added CVE-2022-28810 (Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability), CVE-2022-33891 (Apache Spark Command Injection Vulnerability) and CVE-2022-35914 (Teclib GLPI Remote Code Execution Vulnerability) to their Known Exploited Vulnerabilities catalog on March 7, 2023. The catalog lists vulnerabilities that are being actively exploited…

    Read More CISA to the Known Exploited Vulnerabilities CatalogContinue

  • Blog

    CISA to the Known Exploited Vulnerabilities Catalog

    FortiGuard Labs is aware that the Cybersecurity & Infrastructure Security Agency (CISA) added CVE-2020-5741 (Plex Media Server remote code execution vulnerability) and CVE-2021-39144 (XStream Remote Code Execution Vulnerability) to their Known Exploited Vulnerabilities (KEV) catalog on March 10, 2023. The catalog lists vulnerabilities that are being actively exploited in the wild and require federal agencies…

    Read More CISA to the Known Exploited Vulnerabilities CatalogContinue

  • Blog

    PaperCut Remote Code Execution Vulnerability Exploited in the Wild

    UPDATE 04/26/2023: Updated protection section for IPS protection.FortiGuard Labs is aware that a recently disclosed vulnerability in PaperCut MF/NG (CVE-2023-27350) is susceptible to a remote code execution attack and is currently being exploited in the wild. Various remote management and maintenance software and Truebot malware were reportedly to have been deployed to unpatched severs. As…

    Read More PaperCut Remote Code Execution Vulnerability Exploited in the WildContinue

  • Blog

    Patch Released for Critical vm2 Sandbox Escape Vulnerability

    UPDATE April 19 2023: Updated to include another sandbox vulnerability in vm2 (CVE-2023-30547).Earlier this week, an update was released for a critical sandbox escape vulnerabilities in vm2 (CVE-2023-29017 and CVE-2023-29199) , which ultimately allows for remote code execution by an attacker. vm2 is a widely used module within the Node.js library that provides a sandbox…

    Read More Patch Released for Critical vm2 Sandbox Escape VulnerabilityContinue

  • Blog

    Adobe ColdFusion Access Control Bypass

    What is the vulnerability?The Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by Improper Access Control vulnerabilities that could result in a security bypass. Exploitation of these vulnerabilities could give attacker access to the ColdFusion Administrator endpoints for further attack.What is the Vendor Solution?Adobe released patches for the security bypass flaws…

    Read More Adobe ColdFusion Access Control BypassContinue

  • Blog

    Apache OFBiz Authentication Bypass

    What is the vulnerability?There is an authentication bypass vulnerability in Apache OFBiz tracked under CVE-2023-51467 and CVE-2023-49070. Successful exploitation would let an attacker circumvent authentication processes, enabling them to remotely execute arbitrary code and access sensitive information. Apache OFBiz is an open-source business application suite for Enterprise Resource Planning (ERP) which integrates and automates many…

    Read More Apache OFBiz Authentication BypassContinue

  • Blog

    Active Exploitation of SolarView Compact Command Injection Vulnerabilities

    What is SolarView Compact?SolarView Compact is a photovoltaic (PV) power generation measurement and monitoring device developed by Contec. What is the Attack?CVE-2022-29303 is a command injection vulnerability in SolarView Compact that allows attackers to steal or modify information, destroy the system, or execute malicious programs by entering commands from the test email transmission screen.CVE-2022-40881 is…

    Read More Active Exploitation of SolarView Compact Command Injection VulnerabilitiesContinue

  • Blog

    ArcaneDoor Attack

    rnWhat is the Attack?rnCisco issued an advisory on 24th April, regarding its Adaptive Security Appliances, multifunctional devices combining firewall, VPN, and other security functions. It reported that these appliances had become the focus of state-sponsored espionage, with attackers exploiting two previously unknown vulnerabilities to infiltrate government entities worldwide. In this campaign, two backdoors were deployed:…

    Read More ArcaneDoor AttackContinue

  • Blog

    Rockwell Automation ControlLogix Communication Modules Vulnerabilities

    Post Content

    Read More Rockwell Automation ControlLogix Communication Modules VulnerabilitiesContinue

Page navigation

Previous PagePrevious 1 … 28 29 30 31 32 … 225 Next PageNext
Facebook
Privacy Policy
Background by Vecteezy

Web Design 2024 SekuritasIT

Veteran Owned and Operated

Scroll to top
  • Managed IT Support Services
  • Contact Us