xz-utils backdoor: CVE-2024-3094 urgent advisory
A malicious backdoor discovered in xz 5.6.0/5.6.1 can allow unauthorized access over SSH.
The pulse of your infrastructure. The screen for threats.
Ubuntu Server, Windows Server, Proxmox VE, Plesk, FortiGate / FortiOS and 6 more platforms — vulnerabilities, critical patches and release news on a single screen: verified and actionable.
A malicious backdoor discovered in xz 5.6.0/5.6.1 can allow unauthorized access over SSH.
Patch the Hyper-V vulnerability that allows escape from a guest virtual machine to the host operating system.
MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.
A buffer overflow in the dynamic loader allows obtaining root privileges via GLIBC_TUNABLES.
The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected.
A vulnerability in the Common Log File System driver was actively used in Nokoyanya ransomware operations.
A bug in the pipe mechanism allows overwriting of read-only files and can lead to root privileges.
The notorious vulnerability in the Print Spooler service; kept permanently under control on Domain Controllers with Point and Print restrictions.
The legendary CVSS 10.0 vulnerability enabling impersonation of a Domain Controller — enforcement mode active.
Researchers used AI to examine over 3,700 dream and waking-life reports and identified recurring ways memories, people and places recombine. The findi...
The government has separated digital transformation from procurement and given AI a Cabinet-level role. That fragmentation risks inconsistent strategy...
Beta releases @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4 were tampered with to include a module that decrypts a...
Vulnerabilities and release notes for the platforms you follow, in one email every morning. You choose which platforms to track, and you can leave at any time.
Already subscribed? Manage your preferences