CVE-2023-4966: تم استغلال الكشف عن معلومات بوابة Citrix NetScaler ADC وNetScale بشكل مباشر
A critical information disclosure vulnerability in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway has been exploited in the wild as a zero-day vulnerability. Organizations are urged to patch immediately.
CVE-2023-20198: تم استغلال ثغرة Zero-Day في نظام Cisco IOS XE بشكل مباشر
A maximum severity CVSS 10 zero-day vulnerability in Cisco IOS XE has been exploited in the wild. Organizations should apply the mitigation steps from Cisco as soon as possible until patches are released.
CVE-2023-38545, CVE-2023-38546: الأسئلة المتداولة حول الثغرات الأمنية الجديدة في curl
Frequently asked questions relating to two vulnerabilities patched in curl version 8.4.0
العمليات الاحتيالية باسم MrBeast: الحسابات التي تم التحقق منها، وDeepFakes المستخدمة في انتحال الشخصية للترويج للهدايا المزيفة على YouTube وTikTok
MrBeast, the most popular YouTube creator as of October 2023, has been impersonated in a variety of scams on YouTube and TikTok, including a recent deepfake promoting a free iPhone giveaway
CVE-2023-22515: تم استغلال الثغرة الأمنية Zero-Day (المباغتة) في مركز بيانات وخادم Atlassian Confluence أثناء الاستخدام
A critical zero-day vulnerability in Atlassian Confluence Data Center and Server has been exploited in the wild in a limited number of cases. Organizations should patch or apply the mitigation steps as soon as possible.
CVE-2023-40044, CVE-2023-42657: Progress Software Patches Multiple Vulnerabilities in WS_FTP Server
Progress Software patches multiple flaws in its WS_FTP Server product, including a pair of critical flaws, one with a maximum CVSS rating of 10
CVE-2023-41064, CVE-2023-4863, CVE-2023-5129: الأسئلة المتداولة حول الثغرات الأمنية المباغتة في ImageIO وWebP/libwebp
Frequently asked questions relating to vulnerabilities in Apple, Google and the open source libwebp library.
CVE-2023-29357, CVE-2023-24955: تم إصدار سلسلة الاستغلال لثغرات Microsoft SharePoint Server الأمنية
A proof-of-concept exploit chain has been released for two vulnerabilities in Microsoft SharePoint Server that can be exploited to achieve unauthenticated remote code execution.
تحديث يوم الثلاثاء من شهر سبتمبر 2023 من Microsoft يعالج 61 ثغرة أمنية وحالة تعرض شائعة(CVE-2023-36761)
Microsoft addresses 61 CVEs including two vulnerabilities that were exploited in the wild
CVE-2023-20269: تم الإبلاغ عن استغلال ثغرة أولية مباغتة (Zero-Day) في جهاز أمان Cisco Adaptive وFirepower Threat Defense من قبل مجموعات فيروس الفيدية
Ransomware groups including LockBit and Akira are reportedly exploiting a zero-day vulnerability in Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) appliances with VPN functionality enabled.