Tag: hackers hijack

Ivanti warns critical EPM bug lets hackers hijack enrolled devices
News

Ivanti warns critical EPM bug lets hackers hijack enrolled devices

In its Endpoint Management software (EPM), Ivanti addressed a serious remote code execution (RCE) vulnerability that may have allowed unauthorized attackers to take control of registered devices or the core server. Ivanti EPM facilitates the management of client devices on a variety of operating systems, including Windows, macOS, Chrome OS, and Internet of Things. All supported Ivanti EPM versions are affected by the security weakness (recorded as CVE-2023-39366), which has been fixed in version 2022 Service Update 5. Low-complexity attacks that don't require privileges or user engagement can be exploited by attackers who have access to the internal network read more Ivanti warns critical EPM bug lets hackers hijack enrolled devices. Get up to date on the latest cybersecurity new...
Citrix Bleed exploit lets hackers hijack NetScaler accounts
News

Citrix Bleed exploit lets hackers hijack NetScaler accounts

The 'Citrix Bleed' vulnerability, identified as CVE-2023-4966, has a proof-of-concept (PoC) exploit available that enables attackers to obtain authentication session cookies from susceptible Citrix NetScaler ADC and NetScaler Gateway appliances. Citrix resolved CVE-2023-4966, a critical-severity remotely exploitable information disclosure vulnerability, on October 10th, albeit not much information was disclosed. Mandiant disclosed on October 17 that the vulnerability had been exploited as a zero-day attack since late August 2023. Citrix sent out a follow-up warning on Monday to NetScaler ADC and Gateway appliance managers, asking them to patch the vulnerability right away read more Citrix Bleed exploit lets hackers hijack NetScaler accounts. Get up to date on the latest cybers...