July’s Patch Tuesday brings a midsummer wave of updates, addressing critical vulnerabilities and enhancing security across the Microsoft ecosystem. Let’s discover the highlights from Microsoft’s Patch Tuesday updates for July 2024. Microsoft Patch Tuesday’s July 2024 edition addressed 142 vulnerabilities, including five critical and 134 important severity vulnerabilities. In this month’s security updates, Microsoft has … Continue reading “Microsoft Patch Tuesday, July 2024 Security Update Review”
Cisco NX-OS Software CLI Command Injection Vulnerability (CVE-2024-20399)
Cisco has released patches to address a zero-day vulnerability exploited in April. Tracked as CVE-2024-20399, the vulnerability impacts Cisco NX-OS Software. Successful exploitation of the vulnerability could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges. Cybersecurity firm Sygnia reported the vulnerability to Cisco along with the information about … Continue reading “Cisco NX-OS Software CLI Command Injection Vulnerability (CVE-2024-20399)”
WordPress Plugins Injected Backdoor Vulnerability Impacts Multiple Sites (CVE-2024-6297)
Multiple WordPress plugins are vulnerable to a critical severity vulnerability tracked as CVE-2024-6297. The vulnerability is given a CVSS score of 10. The vulnerability impacts 13 plugins. WordPress plugins hosted on WordPress.org have been hijacked, as malicious PHP scripts have been injected into them. As per the WordPress advisory, “A malicious threat actor compromised the … Continue reading “WordPress Plugins Injected Backdoor Vulnerability Impacts Multiple Sites (CVE-2024-6297)”
Progress MOVEit Transfer Authentication Bypass Vulnerability (CVE-2024-5806)
Progress Software has released patches to address a critical severity vulnerability impacting MOVEit File Transfer. Tracked as CVE-2024-5806, the vulnerability has a CVSS score of 9.1. This is an improper authentication vulnerability that exists in the SFTP module of the MOVEit Transfer. Successful exploitation of the vulnerability may lead to an authentication bypass.
Zyxel Patches Multiple Vulnerabilities in NAS Products
Zyxel has released patches to address five vulnerabilities in two NAS products that have reached end-of-vulnerability-support. Successful exploitation of the vulnerabilities may result in command injection and remote code execution. The vulnerabilities have been given medium and critical severity ratings. Timothy Hjort from Outpost24 has discovered and reported the vulnerabilities to Zyxel. The security researcher … Continue reading “Zyxel Patches Multiple Vulnerabilities in NAS Products”
JetBrains Released Patches for Vulnerability Impacting IntelliJ IDEA (CVE-2024-37051)
JetBrains IntelliJ integrated development environment (IDE) apps are vulnerable to a critical security flaw tracked as CVE-2024-37051. The vulnerability may allow attackers to disclose GitHub access tokens to third-party sites. The vulnerability exists in the JetBrains IntelliJ-based IDEs that have the JetBrains GitHub plugin enabled and configured/in-use.
VMware vCenter Server Multiple Critical Vulnerabilities (CVE-2024-37079, CVE-2024-37080, & CVE-2024-37081)
VMware vCenter Server is vulnerable to multiple vulnerabilities that may allow attackers to elevate privileges and perform remote code execution. Tracked as CVE-2024-37079, CVE-2024-37080, & CVE-2024-37081, the vulnerabilities are given critical and important severity ratings.
Microsoft Patch Tuesday, June 2024 Security Update Review
Microsoft’s June Patch Tuesday is here, bringing fixes for vulnerabilities impacting its multiple products. This month’s release highlights the ongoing battle against cybersecurity threats, from critical updates to important fixes. Let’s dive into the crucial insights from Microsoft’s Patch Tuesday updates for June 2024. Microsoft Patch Tuesday’s June 2024 edition addressed 58 vulnerabilities, including one … Continue reading “Microsoft Patch Tuesday, June 2024 Security Update Review”
PHP CGI Argument Injection Vulnerability (CVE-2024-4577)
Security Researcher Orange Tsai recently discovered a critical argument injection vulnerability in PHP CGI that could allow attackers to execute arbitrary code without any authentication, leading to possible system compromise. The use of PHP CGI has faded over time; however, CVE-2024-4577 affects the default configuration of XAMPP. XAMPP is a popular software used by PHP … Continue reading “PHP CGI Argument Injection Vulnerability (CVE-2024-4577)”
Fortra Tripwire Enterprise Authentication Bypass Vulnerability (CVE-2024-4332)
Fortra released a security advisory to address a vulnerability impacting Tripwire Enterprise. Tracked as CVE-2024-4332, the vulnerability has been given a critical severity rating with a CVSS score of 9.8. Successful exploitation of the vulnerability could allow remote attackers to gain privileged access to the APIs.