Update now! Apple patches a raft of vulnerabilities

Categories: Exploits and vulnerabilities

Categories: News

Tags: iLeakage

Tags: side-channel

Tags: Safari

Tags: CVE-2023-40413

Tags: CVE-2023-40416

Tags: CVE-2023-40423

Tags: CVE-2023-42487

Tags: CVE-2023-42841

Tags: CVE-2023-41982

Tags: CVE-2023-41997

Tags: CVE-2023-41988

Tags: CVE-2023-40447

Tags: CVE-2023-42852

Tags: CVE-2023-32434

Tags: CVE-2023-41989

Tags: CVE-2023-38403

Tags: CVE-2023-42856

Tags: CVE-2023-40404

Tags: CVE-2023-41977

Tags: Vim

Apple has released security updates for its phones, iPads, Macs, watches and TVs.

(Read more…)

The post Update now! Apple patches a raft of vulnerabilities appeared first on Malwarebytes Labs.

Read more

Update vCenter Server now! VMWare fixes critical vulnerability

Categories: Business

Categories: Exploits and vulnerabilities

Categories: News

Tags: VMWare

Tags: vCenter Server

Tags: CVE-2023-34056

Tags: CVE-2023-34048

Tags: DCE/RPC

Tags: out of bounds write

Tags: information disclosure

Tags: remote code execution

VMWare has issued an update to address out-of-bounds write and information disclosure vulnerabilities in its server management software, vCenter Server.

(Read more…)

The post Update vCenter Server now! VMWare fixes critical vulnerability appeared first on Malwarebytes Labs.

Read more

Cisco IOS XE vulnerability widely exploited in the wild

Categories: Exploits and vulnerabilities

Categories: News

Tags: Cisco

Tags: IOS X

Tags: remote management

Tags: vulnerability

Tags: CVE-2023-20198

Tags: webUI

Tags: http server

Tags: http secure-server

Researchers have found that a recently disclosed vulnerability in Cisco IOS XE has already rendered thousands of compromised devices.

(Read more…)

The post Cisco IOS XE vulnerability widely exploited in the wild appeared first on Malwarebytes Labs.

Read more

Update now! Atlassian Confluence vulnerability is being actively exploited

Categories: Exploits and vulnerabilities

Categories: News

Microsoft Threat Intelligence has revealed that it has been tracking the active exploitation of a vulnerability in Atlassian Confluence software since September 14, 2023.

(Read more…)

The post Update now! Atlassian Confluence vulnerability is being actively exploited appeared first on Malwarebytes Labs.

Read more

CISA catalog passes 1,000 known-to-be-exploited vulnerabilities. Celebration time, or is it?

Categories: Exploits and vulnerabilities

Categories: News

Tags: CISA

Tags: KEV

Tags: catalog

Tags: vulnerabilities

Tags: prioritize

The CISA Known Exploited Vulnerabilities catalog has grown to cover more than 1,000 vulnerabilities since its launch in November 2021.

(Read more…)

The post CISA catalog passes 1,000 known-to-be-exploited vulnerabilities. Celebration time, or is it? appeared first on Malwarebytes Labs.

Read more

Update now! Apple patches vulnerabilities on iPhone and iPad

Categories: Exploits and vulnerabilities

Categories: News

Tags: Apple

Tags: iOS

Tags: iPad

Tags: 17.0.3

Tags: CVE-2023-42824

Tags: CVE-2023-5217

Apple has issued an emergency update to patch two vulnerabilities, including an actively exploited one.

(Read more…)

The post Update now! Apple patches vulnerabilities on iPhone and iPad appeared first on Malwarebytes Labs.

Read more

Pegasus spyware and how it exploited a WebP vulnerability

Categories: Android

Categories: Apple

Categories: Exploits and vulnerabilities

Tags: Pegasus

Tags: spyware

Tags: nso

Tags: webp

Tags: libwebp

Tags: buffer overflow

The company behind the infamous Pegasus spyware used a vulnerability in almost every browser to plant their malware on victim’s devices.

(Read more…)

The post Pegasus spyware and how it exploited a WebP vulnerability appeared first on Malwarebytes Labs.

Read more