
5 Major Takeaways From Microsoft's July Patch Tuesday
Microsoft's July 2023 Patch Tuesday update is the largest one so far this year, weighing in at a whopping 129 bug fixes, with four of them addressing actively exploited zero-days, and nine...
Attackers Exploit Citrix Zero-Day Bug to Pwn NetScaler ADC, Gateway
Jul 20, 2023 · Citrix issued a patch for the zero-day vulnerability, tracked as CVE-2023-3519, on July 18 along with a recommendation for organizations using the affected products to apply it immediately.
Microsoft Fixes Failed Patch for Exploited Outlook Vulnerability
May 10, 2023 · CVE-2023-29324 is a remotely exploitable, zero-click vulnerability that renders the patch for the original Outlook vulnerability useless, researchers at Akamai say.
'ResumeLooters' Attackers Steal Millions of Career Records
Feb 6, 2024 · All told, the group — believed to be operating since the beginning of 2023 — stole several databases containing 2,079,027 unique emails and other records in attacks that occurred between …
Fresh MOVEit Bug Under Attack Mere Hours After Disclosure
Jun 25, 2024 · It affects versions from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, and from 2024.0.0 before 2024.0.2 of MOVEit Transfer.
Attackers Abuse PaperCut RCE Flaws to Take Over Enterprise Print …
Apr 25, 2023 · CVE-2023-27350 exists within the SetupCompleted class and results from improper access control, according to its listing on the Zero Day Initiative website.
Twilio Hackers Scarf 10K Okta Credentials in Sprawling Supply Chain …
Aug 25, 2022 · The "0ktapus" cyberattackers set up a well-planned spear-phishing effort that affected at least 130 orgs beyond Twilio and Cloudflare, including Digital Ocean, DoorDash and Mailchimp.
Verizon Employee Data Exposed in Insider Threat Incident
Feb 6, 2024 · About 63,000 Verizon employees have been affected by a breach that occurred in September 2023 but which wasn't discovered for three months.
Critical Cisco SMB Router Flaw Allows Authentication Bypass, PoC …
Jan 12, 2023 · The first bug is a critical-rated authentication bypass issue (CVE-2023-20025) that exists in the Web management interface of the devices and carries a rating of 9 out of 10 on the CVSS ...
Peloton Bugs Expose Enterprise Networks to IoT Attacks
Jul 26, 2023 · This implies that "there could be potentially more than 1,100 vulnerabilities from 2022 and 2023 alone that could theoretically be exploited to compromise this treadmill," the researchers noted...