Security flaw CVE-2023-49105 in ownCloud is being actively exploited, allowing attackers to access and manipulate files without authentication if the username is known.
Browsing Category
Cybersecurity
275 posts
Boston Scientific: Network Outage The Result Of ‘Cybersecurity Incident’ – FOX 9 Minneapolis-St. Paul
Boston Scientific reports a network outage resulting from a cybersecurity incident, impacting operations. Details are still emerging as investigations continue.
CVE-2022-0995: Linux Kernel Out-of-Bounds Write Vulnerability Actively Exploited (CISA KEV)
A critical Linux Kernel out-of-bounds write vulnerability, CVE-2022-0995, is actively being exploited, posing risks of privilege escalation and system crashes.
CVE-2015-5287: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability Actively Exploited (CISA KEV)
CISA lists a Red Hat ABRT privilege-escalation flaw as actively exploited, raising its priority for systems accessible to local users.
CVE-2015-3246: Red Hat Libuser Race Condition Vulnerability Actively Exploited (CISA KEV)
CISA says attackers are exploiting a Red Hat libuser flaw that can corrupt /etc/passwd and lead to service disruption or higher privileges.
CVE-2021-23758: Ajax.NET Professional Deserialization Of Untrusted Data Vulnerability Actively Exploited (CISA KEV)
Security researchers confirm active exploitation of CVE-2021-23758, a deserialization vulnerability in Ajax.NET Professional enabling remote code execution.
When Str.lower() Is A Security Vulnerability In Python – Seth Larson
Security researcher Seth Larson highlights a vulnerability in Python’s str.lower() method that could lead to security exploits, raising concerns for developers.
CVE-2026-60004: Gitea Code Injection Vulnerability Actively Exploited (CISA KEV)
A critical code injection flaw in Gitea is actively exploited, allowing attackers with repository write access to execute malicious code, according to CISA KEV.
SeL4 Security Proofs Now Complete On AArch64
The formal security proofs for the seL4 microkernel on the AArch64 platform are now finalized, marking a significant milestone in verified systems security.
CVE-2026-21962: Oracle HTTP Server And Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability Actively Exploited (CISA KEV)
A new vulnerability in Oracle HTTP Server and WebLogic Server proxy plug-ins is actively exploited, risking unauthorized data access and modification.