Blog

Latest articles from SOCRadar

Critical and High Vulnerabilities in Citrix ADC and Citrix Gateway (CVE-2023-3519, CVE-2023-3466, CVE-2023-3467)
November 16, 2023

Citrix Hypervisor Security Update: Addressing CVE-2023-23583 and CVE-2023-46835 Vulnerabilities

In the dynamic field of cybersecurity, staying abreast of new vulnerabilities is crucial. The recent discovery of two significant vulnerabilities in the Citrix Hypervisor, a widely used virtualization management tool, underscores this necessity. This blog… Continue Reading

October 26, 2023

KillNet Announces Launch of A New DDoS Service

During the cyberwarfare caused by the Israel-Palestine conflict and Russia's invasion of Ukraine in cybersecurity, it's paramount to stay updated on the latest threats to be alerted. Recently, KillNet, a Russian-speaking group that took a pro-Palestinian… Continue Reading

SolarWinds Releases Crucial Fixes for ARM Security Vulnerabilities (CVE-2023-35182, CVE-2023-35185, and CVE-2023-35187)
October 20, 2023

SolarWinds Releases Crucial Fixes for ARM Security Vulnerabilities (CVE-2023-35182, CVE-2023-35185, and CVE-2023-35187)

In the ever-evolving landscape of cybersecurity, staying ahead of threats is paramount for security professionals. Recently, SolarWinds Access Rights Manager (ARM), a comprehensive access management solution, has been the focus due to multiple discovered vulnerabilities.… Continue Reading

October 13, 2023

The Perils of Search Engines: A Recent Tech Scam Alert

Search engines like Google have become our primary navigators in the vast world of the internet. However, with its vastness comes vulnerability. Even the giants aren't immune to occasional slip-ups, as evidenced by a recent… Continue Reading

CVE-2023-22515: The Confluence Data Center and Server Vulnerability
October 4, 2023

CVE-2023-22515: The Confluence Data Center and Server Vulnerability

[Update] November 13, 2023: New ‘Effluence’ Backdoor Targets Confluence Data Center and Server Upon Exploiting CVE-2023-22515 and CVE-2023-22518 [Update] October 12, 2023: See subheadings: "Storm-0062 APT Exploits Confluence Vulnerability (CVE-2023-22515)" & "Nuclei Template for CVE-2023-22515… Continue Reading

CISA Flags Active Exploitation of Mali GPU Drivers Vulnerability: CVE-2023-4211
October 3, 2023

CISA Flags Active Exploitation of Mali GPU Drivers Vulnerability: CVE-2023-4211

In the ever-evolving cybersecurity landscape, adding a vulnerability to CISA's Known Exploited Vulnerabilities Catalog stands as a significant alarm bell. Recently, a critical vulnerability affecting Mali GPU drivers caught CISA's attention, emphasizing the active exploitation… Continue Reading

September 29, 2023

WS_FTP Server Critical Vulnerabilities: What You Need to Know (CVE-2023-40044, CVE-2023-42657)

In the ever-changing landscape of cybersecurity, staying updated with current vulnerabilities is crucial. The recent issues discovered in WS_FTP Server underscore this fact. In this article, we explore the details of these vulnerabilities, their possible… Continue Reading

Microsoft SharePoint Server Elevation of Privilege Vulnerability Exploit (CVE-2023-29357)
September 27, 2023

Microsoft SharePoint Server Elevation of Privilege Vulnerability Exploit (CVE-2023-29357)

 [Update] September 29, 2023: See the subheading: “Proof-of-Concept Exploit Is Available for SharePoint Server Vulnerability (CVE-2023-29357).” In June 2023, Microsoft released a patch for a critical elevation of privilege vulnerability in SharePoint, identified as CVE-2023-29357.… Continue Reading

Critical RCE Flaw Fixed in New Versions of GitLab
September 20, 2023

GitLab’s Critical Security Update: What You Need to Know (CVE-2023-5009)

GitLab is a widely-used DevOps platform that allows for code hosting, continuous integration, and other collaborative features for both Community and Enterprise users. A new critical security release has just been rolled out for GitLab… Continue Reading

Over 1,000 Zimbra Servers Compromised by Auth Bypass Vulnerability
August 25, 2023

A One-Click Security Vulnerability in Zimbra Collaboration Suite: CVE-2023-41106

In the realm of digital communication and collaboration, Zimbra Collaboration Suite has been a trusted ally for many. However, a shadow has been cast over its security recently. A one-click security vulnerability, capable of granting… Continue Reading

Juniper Networks Released Fixes For Critical Vulnerabilities
August 22, 2023

Exploiting Multiple J-Web Vulnerabilities to Enable Unauthenticated Remote Code Execution in Juniper OS (CVE-2023-36844 through CVE-2023-36847)

Published on August 17, 2023, a significant security bulletin from Juniper Networks sheds light on a collection of vulnerabilities embedded in the J-Web component of Junos OS. While each vulnerability might seem innocuous with an… Continue Reading

Securing the Digital Gateways: The Ivanti Sentry Vulnerability (CVE-2023-38035)
August 21, 2023

Securing the Digital Gateways: The Ivanti Sentry Vulnerability (CVE-2023-38035)

[Update] August 25, 2023: See the subheadings: "Proof-of-Concept (PoC) Exploit Available for the Ivanti Sentry Zero-Day," and "CISA Warns for Active Exploitation of CVE-2023-38035." In the ever-evolving realm of cybersecurity, vulnerabilities continue to emerge, reminding… Continue Reading

Cisco Releases Patches for Vulnerabilities in Multiple Products
August 17, 2023

What You Need to Know About Cisco Unified Communications Manager SQL Injection Vulnerability (CVE-2023-20211)

In today’s connected world, efficient tools like the Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could be integral to businesses. But what happens when these… Continue Reading

August 16, 2023

The Rising Anxiety Over LinkedIn Account Takeover Claims

In an age dominated by the digital, online platforms like LinkedIn have become vital components of our professional identities. But as we increasingly rely on these tools, concerns about their security inevitably rise. Recently, murmurs… Continue Reading

Complex RCE Vulnerability (CVE-2023-39143) in PaperCut Application Servers
August 7, 2023

Complex RCE Vulnerability (CVE-2023-39143) in PaperCut Application Servers

PaperCut NG and PaperCut MF are extensively utilized software solutions for print management servers. CVE-2023-39143 refers to path traversal vulnerabilities found in PaperCut NG and PaperCut MF versions released prior to v22.1.3. These vulnerabilities could… Continue Reading

July 26, 2023

The Phishing Risks of Twitter’s Name Change to X

In today's digital playground, social media swings both ways, offering a fun-filled space for individuals to connect and share, while also serving as a dynamic B2B carousel, where businesses can showcase their talents and build… Continue Reading

Patch Available for Important LPE Vulnerability in VMware Tools
July 25, 2023

VMware Responses to the Critical CVE-2023-20891 Vulnerability Exposing CF API Admin Credentials

Virtual machines have revolutionized the world of cybersecurity, offering a myriad of benefits to cybersecurity professionals. They enable professionals to simulate real-world attack scenarios, conduct vulnerability testing, and analyze malware in a safe and controlled… Continue Reading

Zero-Days (CVE-2023-26077, CVE-2023-26078) in Atera Windows Installers
July 24, 2023

Zero-Days (CVE-2023-26077, CVE-2023-26078) in Atera Windows Installers

Recent revelations have exposed critical zero-day vulnerabilities in Atera Windows installers. Cyber attackers could potentially use these loopholes to launch privilege escalation attacks. To understand the severity of these vulnerabilities, it is crucial to unpack… Continue Reading

First-Known Targeted Open-Source Supply Chain Attacks Strike the Banking Sector
July 22, 2023

First-Known Targeted Open-Source Supply Chain Attacks Strike the Banking Sector

The cybersecurity threat landscape continues to witness new and sophisticated threats, and the banking sector is no exception. For the first time, the industry has been explicitly targeted by two distinct open-source software (OSS) supply… Continue Reading

July 20, 2023

Fixed Critical Severity Vulnerabilities (CVE-2022-45788) in Schneider Electric EcoStruxure Products, Modicon PLCs, and PACs

In the realm of industrial control systems (ICS), vulnerabilities pose significant risks to critical infrastructure sectors worldwide. There are recently fixed critical severity vulnerabilities discovered in Schneider Electric's EcoStruxure Products, Modicon PLCs, and Programmable Automation… Continue Reading

SOCRadar helps you visualize digital risk, and reduce your company's attack surface
Request Demo