exploited

14 Articles
Craft CMS zero-day exploited to compromise hundreds of vulnerable servers
Tech

Craft CMS zero-day exploited to compromise hundreds of vulnerable servers

Researchers discovered two critical-severity zero-days in Craft CMS Criminals are allegedly chaining them together to gain access Some 300 sites already fell victim...

WordPress plugin auth bypass exploited almost immediately after disclosure
Tech

WordPress plugin auth bypass exploited almost immediately after disclosure

A bug in OttoKit allows threat actors to create new admin accounts The bug can lead to full website takeover More than 100,000...

CrushFTP vulnerability exploited in the wild, added to CISA KEV database
Tech

CrushFTP vulnerability exploited in the wild, added to CISA KEV database

A critical flaw was discovered in file transfer tool CrushFTP Experts claim the issue was being abused in the wild CISA added the...

Actively exploited vulnerabilities patched on Android in latest security update
Tech

Actively exploited vulnerabilities patched on Android in latest security update

Google’s new advisory details 62 vulnerabilities Some of them are deemed critical, and for some no user interaction is required At least two...

Key trusted Microsoft platform exploited to enable malware, experts warn
Tech

Key trusted Microsoft platform exploited to enable malware, experts warn

Trusted Signing, a Microsoft certificate-signing service, is being abused by criminals, researchers are saying The criminals are signing malware with short-lived, three-day certificates...

Cisco smart licensing system sees critical security flaws exploited
Tech

Cisco smart licensing system sees critical security flaws exploited

Security researchers claim two Cisco Smart Licensing Utility bugs are being abused in the wild One of the bugs is a hardcoded admin...

An unpatched Windows zero-day flaw has been exploited by 11 nation-state attackers
Tech

An unpatched Windows zero-day flaw has been exploited by 11 nation-state attackers

Trend Micro warns of an old Windows zero-day still in use today Many nation-states are abusing the bug to run espionage campaigns Microsoft...

Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
Tech

Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers

Apple has released new updates that fix a known vulnerability The flaw might have been exploited in the wild The latest update also...

One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
Tech

One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years

A security vulnerability in Microsoft Exchange servers remains largely unpatched A fix was issued four years ago, but some users clearly didn’t update...