3,000+ Apache ActiveMQ Servers Vulnerable to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

More than 3,000 Apache ActiveMQ servers exposed to the internet are at risk due to a critical remote code execution (RCE) vulnerability identified as CVE-2023-46604. The most widely used open-source, multi-protocol, Java-based message …

Remote Desktop Manager Flaw Let Attacker Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Recent reports indicate that the Remote Desktop Manager and Devolutions Server have been affected by improper access control and Remote code execution vulnerabilities. The CVEs of these vulnerabilities have been …

Google Chrome 119 Released: Fix for 15 security Flaws – Patch Now!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released Chrome 119 to the stable channel for Windows, Mac, and Linux, along with 15 security patches. Version 119.0.6045.105 for Linux and macOS and version 119.0.6045.105/.106 for Windows …

Next Generation CVSS v4.0 Vulnerability Scoring System Released: What’s New!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FIRST, the Forum of Incident Response and Security Teams has recently unveiled the latest version of their Common Vulnerability Scoring System (CVSS). The new CVSS 4.0 is the replacement of …

Boeing Admits Cyberattack; Lockbit Claims Zero-Day Exploit Was Used to Gain Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Boeing, the aerospace industry leader, has recently reported a cyberattack on its systems. The attack primarily targeted the company’s parts and distribution business. While this breach has not affected flight …

VMware Workspace Flaw Let Attacker Redirect User to Malicious Source

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An open redirect vulnerability in the VMware Workspace ONE UEM console has been identified as CVE-2023-20886, which has a CVSS score of 8.8 and is classified as ‘Important’ in severity. By …

Iranian APT Group Utilize IIS-based Backdoors to Compromise Windows servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new threat actor who is found to be associated with Iran’s Ministry of Intelligence and Security (MOIS) IIS has been discovered to be conducting cyberespionage campaigns. Their targets are …