CVE-2023-22518: vulnerabilidad crítica de autorización inadecuada en Confluence Data Center and Server de Atlassian
Atlassian warns of public vulnerability details for a critical flaw in Confluence Data Center and Server, as its CISO urges organizations to apply patches immediately.
CVE-2023-46747: vulnerabilidad crítica de evasión de autenticación en F5 BIG-IP
A critical authentication bypass vulnerability in F5’s BIG-IP could allow remote, unauthenticated attackers to execute system commands. Organizations are encouraged to apply patches as soon as possible.
La actualización de parche crítico de Oracle para octubre de 2023 aborda 176 CVE
Oracle addresses 176 CVEs in its fourth quarterly update of 2023 with 387 patches, including 46 critical updates.
CVE-2023-4966: divulgación de información de Citrix NetScaler ADC y NetScaler Gateway explotada en la realidad
A critical information disclosure vulnerability in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway has been exploited in the wild as a zero-day vulnerability. Se insta a las organizaciones a aplicar parches de inmediato.
CVE-2023-20198: Vulnerabilidad de día cero en Cisco IOS XE explotada en la realidad
A maximum severity CVSS 10 zero-day vulnerability in Cisco IOS XE has been exploited in the wild. Organizations should apply the mitigation steps from Cisco as soon as possible until patches are released.
Martes de parches de Microsoft de octubre de 2023 aborda 103 CVE (CVE-2023-36563, CVE-2023-41763)
Microsoft addresses 103 CVEs including two vulnerabilities that were exploited in the wild.
CVE-2023-38545, CVE-2023-38546: preguntas frecuentes sobre nuevas vulnerabilidades
Frequently asked questions relating to two vulnerabilities patched in curl version 8.4.0
Estafas de MrBeast: cuentas verificadas, DeepFakes usados en suplantaciones de identidad para promover obsequios falsos en YouTube y TikTok
MrBeast, the most popular YouTube creator as of October 2023, has been impersonated in a variety of scams on YouTube and TikTok, including a recent deepfake promoting a free iPhone giveaway
CVE-2023-22515: Vulnerabilidad de día cero en Atlassian Confluence Data Center and Server explotada en la realidad
A critical zero-day vulnerability in Atlassian Confluence Data Center and Server has been exploited in the wild in a limited number of cases. Organizations should patch or apply the mitigation steps as soon as possible.
CVE-2023-40044, CVE-2023-42657: Progress Software coloca parches en múltiples vulnerabilidades en WS_FTP Server
Progress Software patches multiple flaws in its WS_FTP Server product, including a pair of critical flaws, one with a maximum CVSS rating of 10
CVE-2023-41064, CVE-2023-4863, CVE-2023-5129: Preguntas frecuentes sobre las vulnerabilidades de día cero de ImageIO y WebP/libwebp
Frequently asked questions relating to vulnerabilities in Apple, Google and the open source libwebp library.
CVE-2023-29357, CVE-2023-24955: cadena de vulnerabilidades dada a conocer para vulnerabilidades de Microsoft SharePoint Server
A proof-of-concept exploit chain has been released for two vulnerabilities in Microsoft SharePoint Server that can be exploited to achieve unauthenticated remote code execution.