Tag: cyberattackers

13-Year-Old Redis Flaw Exposed: CVSS 10.0 Vulnerability Lets Attackers Run Code Remotely
News

13-Year-Old Redis Flaw Exposed: CVSS 10.0 Vulnerability Lets Attackers Run Code Remotely

Redis has revealed information about a maximum-severity security vulnerability in its in-memory database software that, in some cases, might lead to remote code execution. The vulnerability, known as RediShell and tagged as CVE-2025-49844, has a CVSS score of 10.0. A GitHub alert for the vulnerability states that a specially designed Lua script might be used by an authenticated user to control the garbage collector, cause a use-after-free, and possibly result in remote code execution. The issue is present in all Redis versions that use Lua scripting. However, in order for exploitation to succeed, an attacker must first obtain authenticated access to a Redis instance. For this reason, it is essential that users secure their Redis instances with robust authentication and avoid leav...
Telerik Report Server Flaw Could Let Attackers Create Rogue Admin Accounts
News

Telerik Report Server Flaw Could Let Attackers Create Rogue Admin Accounts

Updates have been released by Progress Software to fix a serious security vulnerability affecting the Telerik Report Server. This vulnerability might allow a remote attacker to circumvent authentication and create rogue administrator users. With a maximum score of 10.0, the issue, identified as CVE-2024-4358, has a CVSS score of 9.8. An unauthenticated attacker can access Telerik Report Server restricted functionality using an authentication bypass vulnerability in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, the company stated in an alert. In addition to upgrading to the most recent version, Progress Software advises users to check the users list read more about Telerik Report Server Flaw Could Let Attackers Create Rogue Admin Accounts. Ge...
Microsoft Edge Bug Could Have Allowed Attackers to Silently Install Malicious Extensions
News

Microsoft Edge Bug Could Have Allowed Attackers to Silently Install Malicious Extensions

A security vulnerability in the Microsoft Edge web browser that has since been fixed might have been leveraged to install malicious extensions and perform other nefarious tasks on users' computers. According to security researcher Oleg Zaytsev of Guardio Labs, this vulnerability may have given an attacker the ability to install more browser extensions with extensive permissions without the user's knowledge by using a private API that was first meant for marketing purposes. Following responsible disclosure in November 2023, Microsoft fixed the issue in Edge stable version 121.0.2277.83, which was released on January 25, 2024. The issue is tracked as CVE-2024-21388 (CVSS score: 6.5). The creator of Windows gave Zaytsev and Jun Kokatsu credit for bringing up the problem. Microsoft n...
Ivanti warns critical EPM bug lets hackers hijack enrolled devices
News

Ivanti warns critical EPM bug lets hackers hijack enrolled devices

In its Endpoint Management software (EPM), Ivanti addressed a serious remote code execution (RCE) vulnerability that may have allowed unauthorized attackers to take control of registered devices or the core server. Ivanti EPM facilitates the management of client devices on a variety of operating systems, including Windows, macOS, Chrome OS, and Internet of Things. All supported Ivanti EPM versions are affected by the security weakness (recorded as CVE-2023-39366), which has been fixed in version 2022 Service Update 5. Low-complexity attacks that don't require privileges or user engagement can be exploited by attackers who have access to the internal network read more Ivanti warns critical EPM bug lets hackers hijack enrolled devices. Get up to date on the latest cybersecurity new...
New Terrapin Flaw Could Let Attackers Downgrade SSH Protocol Security
News

New Terrapin Flaw Could Let Attackers Downgrade SSH Protocol Security

Ruhr University Bochum security researchers have found a flaw in the Secure Shell (SSH) cryptographic network protocol that might let an attacker compromise the integrity of the secure channel and reduce the security of the connection. It has been stated that Terrapin (CVE-2023-48795, CVSS score: 5.9) is the "first ever practically exploitable prefix truncation attack." Researchers Fabian Bäumer, Marcus Brinkmann, and Jörg Schwenk stated that "an attacker can remove an arbitrary amount of messages sent by the client or server at the beginning of the secure channel without the client or server noticing it read more New Terrapin Flaw Could Let Attackers Downgrade SSH Protocol Security. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with ...
Design Flaw in Google Workspace Could Let Attackers Gain Unauthorized Access
News

Design Flaw in Google Workspace Could Let Attackers Gain Unauthorized Access

A "severe design flaw" in Google Workspace's domain-wide delegation (DWD) feature has been identified by cybersecurity researchers. This flaw could be used by threat actors to facilitate privilege escalation and gain unauthorized access to Workspace APIs without the need for super admin privileges. In a technical report shared with The Hacker News, cybersecurity firm Hunters stated that "such exploitation could result in theft of emails from Gmail, data exfiltration from Google Drive, or other unauthorized actions within Google Workspace APIs on all of the identities in the target domain." The design flaw, which is still active today, has been given the codename DeleFriend because it allows users to modify delegations that are already in place in Google Workspace read more Design Fl...