Skip to content

Daily Threat Intel

Menu
  • Vulnerabilities
  • Malware
  • Breaches
  • Enterprise
  • Supply Chain
  • Emerging Threats
  • Cloud
  • About us
Menu

Tag: vulnerability

Citrix discloses critical authentication bypass flaw; two other vulnerabilities

Posted on November 9, 2022

Organizations should update as soon as possible. If past is precedent, new CVE-2022-27510 flaw could be heavily targeted [286 words]. What: A critical authentication bypass vulnerability (CVE-2022-27510) is present in multiple versions…

Share

Five useful lists and tools for identifying resources with vulnerable OpenSSL in them

Posted on October 31, 2022

The OpenSSL project team will release a new version of the OpenSSL library (version 3.0.7) on Tuesday to address a critical vulnerability in version 3.0 to 3.6 of the widely used open…

Share

ConnectWise patches critical flaw in its Recover and R1Soft Server Backup Manager technology

Posted on October 31, 2022

Vulnerability gives attackers a way to target thousands of MSPs and their downstream customers. Company urges customers to treat issue as a top priority [298 words]. What: ConnectWise has patched a critical,…

Share

Four quick things to know about the critical bug in OpenSSL that will be disclosed Nov.1

Posted on October 31, 2022

The OpenSSL project team will release a new version of the OpenSSL library (version 3.0.7) on Tuesday to address a critical vulnerability in version 3.0 to 3.6 of the widely used open…

Share

CISA Adds Patched Apple iOS/iPadOS Zero-Day to Known Exploited Vulnerabilities Catalog

Posted on October 25, 2022

CVE-2022-42827 is the eighth kernel level flaw so far this year for which Apple has released a patch only after active exploitation was underway [277 words]. What:  CISA has added a newly…

Share

Text4Shell flaw undergoing reanalysis

Posted on October 21, 2022

NIST says CVE-2022-42889 in Apache Commons Text has been modified [300 words] What: NIST has updated its entry in the National Vulnerability Database pertaining to the Text4Shell vulnerability in Apache Commons Text…

Share

Attackers actively exploiting VMware flaw that CISA deemed as posing “unacceptable risk” in May

Posted on October 21, 2022

Multiple campaigns are using CVE-2022-22954 to drop ransomware, coin miners and Mirai [299 words]. What: Multiple malicious campaigns are actively targeting a previously disclosed and now patched remote code execution vulnerability in…

Share

Vuln in GitHub Enterprise server could enable RCE on SVNBridge

Posted on October 19, 2022

Vulnerability has not been assigned a severity rating yet [242 words]. What:  A deserialization of untrusted data vulnerability (CVE-2022-23734 )exists in multiple GitHub Enterprise Server versions that could potentially let a remote attacker execute…

Share

HelpSystems releases Cobalt Strike 4.7.2 to address new RCE vulnerability

Posted on October 18, 2022

Out-of-band update addresses an issue for which IBM X-Force researchers had wanted a new CVE, but which HelpSystems says is not specific to its software [300 words] What: HelpSystems on October 17…

Share

Critical Remote Code Execution Vulnerability in Apache Commons Text

Posted on October 17, 2022

Is this the next Log4J? [297 words] What: The Apache Foundation appears to have quietly fixed a critical remote code execution (RCE) in Apache Common Text versions 1.5 through 1.9. The vulnerability…

Share

Posts pagination

Previous 1 2 3 Next
  • 12 Bugs in Microsoft’s April 2025 Update to Patch Now
  • NSA, CISA, Others Warn About Fast Flux Threat: Here’s Why
  • Max Severity Bug Affects MITRE Caldera Adversary Emulation Platform
  • FBI: Russia’s APT29 May Exploit These 24 vulnerabilities-Be Aware
  • Ivanti’s New 0-Days Now in CISA’s Exploit Catalog
©2025 Daily Threat Intel | Design: Newspaperly WordPress Theme