Remove vulnerabilities-lab
article thumbnail

NSFOCUS Research Labs Acknowledged by MSRC for Reporting Azure Database Service RCE Vulnerability

Security Boulevard

Overview NSFOCUS received acknowledgments from the Microsoft Security Response Center (MSRC) for reporting Azure Database Service RCE Vulnerability. The post NSFOCUS Research Labs Acknowledged by MSRC for Reporting Azure Database Service RCE Vulnerability appeared first on Security Boulevard.

article thumbnail

Rhino Security Labs Uncovers EXOS Vulnerabilities, Exposing Thousands of Devices

Penetration Testing

During an external network penetration test, David Yesland of Rhino Security Labs unearthed a quartet of vulnerabilities within the Extreme Operating System (EXOS) of ExtremeNetworks.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Three Actively Exploited SAP Vulnerabilities Identified by Onapsis Research Labs: What You Need to Know

Security Boulevard

Three Actively Exploited SAP Vulnerabilities Identified by Onapsis Research Labs: What You Need to Know. The Onapsis Research Labs continuously monitors the evolving threat landscape in order to better understand what is being used to target business applications like SAP and Oracle. maaya.alagappan. Thu, 06/09/2022 - 15:20.

Risk 52
article thumbnail

Critical Vulnerability in libwebp Library

Schneier on Security

Rather than Apple, Google, and Citizen Lab coordinating and accurately reporting the common origin of the vulnerability, they chose to use a separate CVE designation, the researchers said.

283
283
article thumbnail

Salt Labs exposes a new vulnerability in popular OAuth framework, used in hundreds of online services

Security Boulevard

The vulnerability in the expo-auth-session library warranted a CVE assignment – CVE-2023-28131. The security gaps Salt Labs identified made services using this framework susceptible to credentials leakage, allowing: Full account takeover, leading to identity theft, financial fraud, access to credit cards and more.

Mobile 52
article thumbnail

Patch Tuesday, May 2024 Edition

Krebs on Security

Microsoft today released updates to fix more than 60 security holes in Windows computers and supported software, including two “zero-day” vulnerabilities in Windows that are already being exploited in active attacks.

article thumbnail

Adobe, Apple, Google & Microsoft Patch 0-Day Bugs

Krebs on Security

Microsoft today issued software updates to fix at least five dozen security holes in Windows and supported software, including patches for two zero-day vulnerabilities that are already being exploited. Citizen Lab says the bug it discovered was being exploited to install spyware made by the Israeli cyber surveillance company NSO Group.

Spyware 238