Critical GitLab flaw (CVE-2023-7028) lets hackers hijack accounts via email trick—no login needed. Learn how it works and how to stay protected.
The critical CVE-2023-46604 flaw in Apache ActiveMQ allows remote code execution, exploited to deploy malware like the Kinsing crypto miner.
Two Ivanti VPN zero-days enable remote code execution; Volexity links the attacks to UTA0178 and urges urgent patching and forensic investigation.
Log4Shell (CVE-2021-44228) is a critical flaw in Log4j 2 allowing remote code execution, affecting millions of systems worldwide.
CVE-2023-22518 allows remote attackers to reset Confluence servers and deploy ransomware; patching and backups are critical for defense.
Zerologon (CVE-2020-1472) is a critical flaw allowing attackers to gain domain admin access via Netlogon by exploiting weak AES encryption.
Read the full "Cloud Snooper Threat Report" PDF to learn more about this threat.
CVE-2023-22515 is a critical Confluence flaw allowing remote attackers to create admin accounts; patching is urgent to prevent exploitation.
The "Looney Tunables" CVE (CVE-2023-4911) in GLIBC 2.34 allows local privilege escalation via a buffer overflow in the "GLIBC_TUNABLES" variable.
Encrypted Client Hello (ECH) in TLS 1.3 enhances privacy by concealing the client's destination, but raises challenges in security, compliance, and regulation.