CVE-2023-22515: Vulnerabilidad de día cero en Atlassian Confluence Data Center and Server explotada en la realidad
A critical zero-day vulnerability in Atlassian Confluence Data Center and Server has been exploited in the wild in a limited number of cases. Organizations should patch or apply the mitigation steps as soon as possible....
CVE-2023-40044, CVE-2023-42657: Progress Software coloca parches en múltiples vulnerabilidades en WS_FTP Server
Progress Software patches multiple flaws in its WS_FTP Server product, including a pair of critical flaws, one with a maximum CVSS rating of 10...
CVE-2023-41064, CVE-2023-4863, CVE-2023-5129: Preguntas frecuentes sobre las vulnerabilidades de día cero de ImageIO y WebP/libwebp
Frequently asked questions relating to vulnerabilities in Apple, Google and the open source libwebp library....
CVE-2023-29357, CVE-2023-24955: cadena de vulnerabilidades dada a conocer para vulnerabilidades de Microsoft SharePoint Server
A proof-of-concept exploit chain has been released for two vulnerabilities in Microsoft SharePoint Server that can be exploited to achieve unauthenticated remote code execution....
Martes de parches de Microsoft de septiembre de 2023 aborda 61 CVE (CVE-2023-36761)
Microsoft addresses 61 CVEs including two vulnerabilities that were exploited in the wild...
CVE-2023-20269: Vulnerabilidad de día cero en Cisco Adaptive Security Appliance y Firepower Threat Defense supuestamente explotada por grupos de ransomware
Ransomware groups including LockBit and Akira are reportedly exploiting a zero-day vulnerability in Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) appliances with VPN functionality enabled....
AA23-250A: Múltiples agentes maliciosos de estados nación explotan CVE-2022-47966 y CVE-2022-42475
A joint Cybersecurity Advisory examines the exploitation of two critical vulnerabilities by nation-state threat actors....
CVE-2023-2868: Barracuda y FBI recomiendan reemplazar dispositivos de puerta de enlace de seguridad de correo electrónico (ESG) ahora mismo
Since October 2022, attackers have been exploiting a zero-day vulnerability in Barracuda Email Security Gateway devices, and both the vendor and the FBI urge customers to replace these devices immediately....
CVE-2023-38035: Ivanti Sentry API Autenticación Bypass Zero-Day explotado en la realidad
For the third time in a month, Ivanti discloses a zero-day vulnerability in one of its products that has been exploited in the wild...
El Martes de parches de Microsoft de agosto de 2023 aborda 73 CVE (CVE-2023-38180)
Microsoft addresses 73 CVEs, including one vulnerability exploited in the wild....
AA23-215A: Principales vulnerabilidades explotadas de forma rutinaria en 2022
A joint Cybersecurity Advisory collaborated on by multiple international agencies highlights the top routinely exploited vulnerabilities of 2022....
CVE-2023-35078: Vulnerabilidad de acceso API no autenticada de Ivanti Endpoint Manager Mobile (EPMM) / MobileIron Core
Critical vulnerability in a popular mobile device management solution from Ivanti has been exploited in the wild in limited attacks...