Tag: Zero-Day Alert

Zero-Day Alert: Three Critical Ivanti CSA Vulnerabilities Actively Exploited
News

Zero-Day Alert: Three Critical Ivanti CSA Vulnerabilities Actively Exploited

Three new security flaws affecting Ivanti's Cloud Service Appliance (CSA) have been actively exploited in the wild, the company has said. The zero-day defects are being weaponized in conjunction with another flaw in CSA that the business addressed last month, the Utah-based software services provider said. If these vulnerabilities are successfully exploited, an authorized attacker with administrator credentials may be able to execute arbitrary SQL statements, circumvent security measures, and get remote code execution. A small number of users running CSA 4.6 patch 518 and earlier, according to the firm, have been known to have been taken advantage of when CVE-2024-9379, CVE-2024-9380, or CVE-2024-9381 are chained with CVE-2024-8963 read more about Three Critical Ivanti CSA Vulner...
Zero-Day Alert Update Chrome Now to Fix New Actively Exploited Vulnerability
News

Zero-Day Alert Update Chrome Now to Fix New Actively Exploited Vulnerability

Updates for Google's Chrome browser, which addresses four security flaws including an active zero-day vulnerability, were made available on Tuesday. Threat actors may be able to use the problem, which is tracked as CVE-2024-0519, to cause a crash by taking advantage of an out-of-bounds memory access in the V8 JavaScript and WebAssembly engine. According to MITRE's Common Weakness Enumeration (CWE), an attacker may be able to obtain secret values, such as memory addresses, by reading out-of-bounds memory. These values can then be used to get around security measures like ASLR and increase the likelihood of successfully exploiting a different danger to achieve code execution read more Zero-Day Alert Update Chrome Now to Fix New Actively Exploited Vulnerability. Get up to date o...