Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a proof-of-concept (PoC) exploit called LegacyHive, targeting a Windows User Profile Service (ProfSvc) arbitrary…
SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity vulnerabilities affecting iCagenda and Balbooa Forms extensions for Joomla to…
Progress Software has instructed ShareFile customers to immediately shut down Windows servers running Storage Zone Controllers in response to a credible external…
CVE-2023-24489 is an unauthenticated vulnerability in Citrix ShareFile Storage Zones Controller that was actively exploited in 2023. CISA flagged it as exploited,…
Microsoft has dismantled a destructive Windows backdoor named GigaWiper, which combines three older malicious tools into a single platform. The malware, written…
The cybersecurity landscape is witnessing a surge in vulnerability clearinghouse announcements, but according to this analysis, most will fail because they focus…
Ubiquiti has released security updates to address multiple critical vulnerabilities across its UniFi product line, including UniFi Connect, UniFi Talk, UniFi Access,…