CVE-2021-44228: Apache Log4j Vulnerability
The Log4Shell vulnerability in Apache Log4j exploited by QTFY.
The Log4Shell vulnerability in Apache Log4j exploited by QTFY.
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing…
An attacker installed the open-source Hermes AI assistant on a rented server, disabled its permission-requesting YOLO mode, and directed it at Thailand's…
A newly identified cyber attack campaign, tracked as StrikeShark by Kaspersky, is deploying a previously undocumented malware family called SharkLoader to deliver…
The organization behind Apache Hadoop and HiveServer2, which were targeted in the attack. The default NONE authentication mode in HiveServer2 was exploited.
Apache Doris was vulnerable to zero-click CI/CD attacks that allowed code execution and credential theft through pull request comments.
Cybersecurity researchers at Novee Security have identified a critical exploitable pattern in CI/CD workflows, codenamed Cordyceps, that allows unauthenticated attackers to hijack…