Security news that informs and inspires


92 results for tag Vulnerability:

Exploitation of Recently Patched VMware Bug Started in 2021

Threat actors exploited a critical-severity VMware flaw for almost two years before patches were released in October.

Exploit, Vulnerability

Lace Tempest Seen Exploiting SysAid Zero Day

A path traversal zero day (CVE-2023-47246) in the SysAid on-premises product is under active attack by the ace Tempest threat group.

Vulnerability, Ransomware

Atlassian CISO Warns of Critical Confluence Flaw

Further details for the vulnerability were not specified, but the bug is rated 9.1 out of 10 on the CVSS v3 scale, and Atlassian is underscoring its potential impact for customers.


Winter Vivern APT Targets Zero Day in Roundcube

The Winter Vivern APT group has been targeting a zero day XSS vulnerability in the Roundcube webmail server in recent weeks.

APT, Vulnerability

CISA Pushes Organizations to Patch Known Confluence Bug

CISA and the FBI are urging network administrators to apply patches for the Atlassian Confluence bug (CVE-2023-22515) immediately.