Browsing tag

vulnerability

Newly discovered Sudo bug lets unauthorized users gain root access

“Sudoing” lately? Linux or any Unix-based platform users are well aware of the Sudo command. In Unix and Linux, the Sudo keyword lets users gain special privileges to execute certain commands, which normally they cannot execute. Sudo command is perhaps one of the most significant of all commands in the Linux/Unix framework and if misused, […]

Millions of HP laptops and desktops are easy targets for hackers: new vulnerabilities are reported

New hardware and software security flaws seem to appear on a daily basis. This time, web application security experts from security firm SafeBreach Labs, specializing in cyberattack simulation, report the finding of a critical vulnerability in Open Hardware Monitor, a free open source tool to monitor temperature, fans speed and voltage in computer hardware components. […]

Multiple Vulnerabilities Found in Satellite Internet Access Terminal Let Hackers Intercept the GPS Traffic

Researchers from CERT/CC discovered multiple vulnerabilities in Satcom terminal Cobham EXPLORER 710 that affects both firmware and device. The vulnerabilities allow hackers to perform several attacks such as intercept the traffic, remotely execute the command, implant and hide a backdoor, DoS Attack, exfiltrate the sensitive data and more Cobham EXPLORER 710 is a satellite telecommunication […]

Critical vulnerability found in Joomla! Update as soon as possible

A vulnerability testing specialist just revealed a zero-day vulnerability in versions of Joomla, the popular content management system (CMS) launched between September 2012 and December 2015. The vulnerability could reportedly pose a severe risk to thousands of websites worldwide. This flaw may seem too old, but in the case of Joomla! this might be irrelevant, […]

RCE Vulnerability in D-Link Routers Let Hackers Access the Router Admin Page Without Credentials

Security researchers disclosed a new unauthenticated command injection vulnerability in some of the D-link routers. The vulnerability can be tracked as CVE-2019-16920 and rated as critical. Successful exploitation of the vulnerability results in Remote Code Execution, an attacker can trigger the vulnerability remotely to access the router login page without authentication. D-link Routers Affected The […]

Critical Foxit PDF Reader Vulnerabilities: Update as soon as possible

A team of web application security experts has discovered multiple security vulnerabilities in Foxit PDF Reader, one of the most popular PDF reader tools and the main competitor of Adobe Reader. The flaws found include remote code execution errors considered highly serious. The researchers, led by Aleksandar Nikolic of Cisco Talos, discovered this set of […]

New Android Zero-day Vulnerability Let Hackers Take Full Control the Samsung, Pixel, Huawei, Xiaomi, Moto Mobiles

Researchers from Google project zero uncovered a critical zero-day vulnerability that affected at least 18 Android models including Samsung, Moto, Huawei, Pixel, Xiaomi and more. Some of the depth pieces of evidence show that the vulnerability is being exploited in wide and gives complete access to the Vulnerable Android devices. An Android zero-day exploit that […]

9 Android Zero-day Vulnerabilities Affects Billions of Android Devices – Hackers Perform DOS, RCE, Make, Deny & Spoof Calls

Exclusive research found 9 critical system-level Android VoIP Zero-day vulnerabilities that allow attackers to perform malicious operations, including denying voice calls, caller ID spoofing, unauthorized call operations, DOS attack, and remote code execution. A Team of academics and researchers from OPPO ZIWU Cyber Security Lab, Chinese University of Hong Kong and Singapore Management University uncovered […]

Critical vulnerability affecting cloud servers: thousands of servers infected

Because of the advantages it offers, cloud computing is considered a much safer environment for information stored on these servers. However, vulnerability testing specialists have discovered a security flaw in a cloud management system used by thousands of providers of these services that could expose information from thousands of system administrators. The vulnerability is present […]

Critical root access vulnerability on Cisco devices alert! Patch immediately

Cisco has just released a new set of security updates for the Cisco IOS Software IOx application. According to ethical hacking specialists, these updates fix a vulnerability that, if exploited, would allow remote threat actors without authentication to access the guest operating system (Guest OS) as a root user. The flaw, tracked as CVE-2019-12648, exists […]

Zero-day vulnerability in vBulletin exploited by hackers; thousands of websites affected

Regardless of its usage, any software implementation can present serious security errors. A researcher in vulnerability testing that remains anonymous for the time has revealed details about zero-day vulnerability in vBulletin, the most widely used Internet forum creation software nowadays. The problem is that it appears that the person in charge of publishing this information […]

XSRF vulnerability in phpMyAdmin; there is no patch to fix this flaw so far

Vulnerability testing specialists have reported the presence of an unpatched zero-day vulnerability in the software of phpMyAdmin, one of the world’s most widely used MySQL and MariaDB database management applications. In addition to reporting the vulnerability, the experts published some details of the proof-of-concept for its exploitation. As mentioned before, phpMyAdmin is a free and […]

Warning: Researcher Drops phpMyAdmin Zero-Day Affecting All Versions

A cybersecurity researcher recently published details and proof-of-concept for an unpatched zero-day vulnerability in phpMyAdmin—one of the most popular applications for managing the MySQL and MariaDB databases. phpMyAdmin is a free and open source administration tool for MySQL and MariaDB that’s widely used to manage the database for websites created with WordPress, Joomla, and many […]

Secure your D-Link & Comba routers’ passwords; critical vulnerability found

Web application security specialists have discovered a set of vulnerabilities in D-Link and Comba WiFi routers that, if exploited, could leak the passwords of the owners. The researchers, from security firm Trustwave, discovered these five flaws, which could be considered critical.   Experts discovered two flaws in the firmware of D-Link DSL-2875AL and DSL-2877AL wireless routers. […]

Experts found new critical vulnerabilities affecting Intel CPUs

A new method for extracting information from an Internet CPU keeps system administrators concerned. Cybersecurity specialists reported the finding of a new side channel vulnerability on these devices; unlike other similar flaws, this one can be exploited remotely over the network, so hackers do not require physical access to the device or the installation of […]

Latest Microsoft Updates Patch 4 Critical Flaws In Windows RDP Client

Get your update caps on. Microsoft today released its monthly Patch Tuesday update for September 2019, patching a total of 79 security vulnerabilities in its software, of which 17 are rated critical, 61 as important, and one moderate in severity. Two of the security vulnerabilities patched by the tech giant this month are listed as […]