Zephyrnet Logo

Tag: command injection

Various Botnets Pummel Year-Old TP-Link Flaw in IoT Attacks

A number of botnets are pummeling a nearly year-old command-injection vulnerability in a TP-Link routers to compromise the devices for IoT-driven distributed denial of...

Top News

Twin Max-Severity Bugs Open Fortinet’s SIEM to Code Execution

Two critical vulnerabilities in Fortinet's FortiSIEM product have been assigned provisional CVSS scores of 10. However, details about the bugs remain scant.What is known...

Adapting Security to Protect AI/ML Systems

Artificial intelligence (AI) isn't just the latest buzzword in business; it's rapidly reshaping industries and redefining business processes. Yet as companies race to integrate...

Danish Energy Attacks Portend Targeting More Critical Infrastructure

In May, 22 Danish energy sector organizations were compromised in an onslaught of attacks partially linked with Russia's Sandworm APT.A new report from the...

Firmware Vulnerabilities You Don’t Want in Your Product

Firmware vulnerabilities refer to security weaknesses or flaws found in the firmware of a device. Firmware is a type of software that is...

This Week In Security: Apple’s 0-day, Microsoft’s Mess, And More

First up, Apple issued an emergency patch, then yanked, and re-issued it. The problem was a Remote Code Execution (RCE) vulnerability in WebKit —...

Ghostscript bug could allow rogue documents to run system commands

by Paul Ducklin Even if you haven’t heard of the venerable Ghostscript project, you may very well have used it...

WordPress plugin lets users become admins – Patch early, patch often!

by Paul Ducklin If you run a WordPress site with the Ultimate Members plugin installed, make sure you’ve updated it...

S3 Ep140: So you think you know ransomware?

by Paul Ducklin LISTEN AND LEARN Gee Whizz BASIC (probably). Think you know ransomware? Megaupload, 11 years on. ASUS warns of...

ASUS warns router customers: Patch now, or block all inbound requests

by Paul Ducklin ASUS is a well-known maker of popular electronics products, ranging from laptops and phones to home routers...

MOVEit mayhem 3: “Disable HTTP and HTTPS traffic immediately”

by Paul Ducklin Yet more MOVEit mayhem! “Disable HTTP and HTTPS traffic to MOVEit Transfer,” says Progress Software, and the timeframe...

MOVEit zero-day exploit used by data breach gangs: The how, the why, and what to do…

by Paul Ducklin Last week, Progress Software Corporation, which sells software and services for user interface development, devops, file management...

Unpatched Wemo Smart Plug Bug Opens Countless Networks to Cyberattacks

The Wemo Mini Smart Plug V2, which allows users to remotely control anything plugged into it via a mobile app, has a security vulnerability...

Latest Intelligence

spot_img
spot_img

Chat with us

Hi there! How can I help you?