IoT Security Unpatched Akuvox Smart Intercom Vulnerabilities Can Be Exploited for Spying Researchers discover a dozen serious vulnerabilities in Akuvox smart intercom, but the vendor has not released any patches. Eduard KovacsMarch 10, 2023
Vulnerabilities Serious Vulnerability Patched in Veeam Data Backup Solution A serious vulnerability in Veeam Backup & Replication may allow attackers to obtain encrypted credentials from the configuration database. Ionut ArghireMarch 10, 2023
Vulnerabilities Critical Vulnerabilities Allowed Booking.com Account Takeover Booking.com recently patched several vulnerabilities that could have been exploited to take control of a user’s account. Eduard KovacsMarch 2, 2023
Supply Chain Security Top 10 Security, Operational Risks From Open Source Code Endor Labs has introduced an OWASP-style listing of the most important or impactful risks inherent in the use of open source software (OSS). Kevin TownsendMarch 1, 2023
Vulnerabilities Fortinet Shares Clarifications on Exploitation of FortiNAC Vulnerability Fortinet provides clarifications following ‘sensationalized reports’ related to exploitation attempts targeting the FortiNAC vulnerability CVE-2022-39952 Eduard KovacsFebruary 24, 2023
Vulnerabilities Vulnerability Provided Access to Toyota Supplier Management Network Security researcher finds severe vulnerability providing system admin access to Toyota’s global supplier management network. Ionut ArghireFebruary 7, 2023
Vulnerabilities Vulnerabilities in OpenEMR Healthcare Software Expose Patient Data Vulnerabilities in open source health records management software OpenEMR could lead to patient data compromise, remote code execution (RCE). Ionut ArghireJanuary 30, 2023
Vulnerabilities BIND Updates Patch High-Severity, Remotely Exploitable DoS Flaws The latest BIND updates patch multiple remotely exploitable vulnerabilities that could lead to denial-of-service (DoS). Ionut ArghireJanuary 27, 2023
Mobile & Wireless Arm Vulnerability Leads to Code Execution, Root on Pixel 6 Phones Technical details published for an Arm Mali GPU flaw leading to arbitrary kernel code execution and root on Pixel 6. Ionut ArghireJanuary 24, 2023
Vulnerabilities Attacks Targeting Realtek SDK Vulnerability Ramping Up Security researchers have observed an uptick in attacks targeting CVE-2021-35394, an RCE vulnerability in Realtek Jungle SDK. Ionut ArghireJanuary 24, 2023
Mobile & Wireless Samsung Galaxy Store Flaws Can Lead to Unwanted App Installations, Code Execution Two vulnerabilities in Samsung’s Galaxy Store that could be exploited to install applications or execute JavaScript code by launching a web page. Ionut ArghireJanuary 23, 2023
Vulnerabilities Critical Vulnerabilities Patched in OpenText Enterprise Content Management System Several vulnerabilities have been patched in OpenText’s enterprise content management (ECM) product. Eduard KovacsJanuary 20, 2023