Thousands of Zimbra mail servers backdoored in large scale attack

Categories: Exploits and vulnerabilities

Categories: News

Tags: Zimbra

Tags: ZVS

Tags: cve-2022-27925

Tags: web shell

Tags: cve-2022-37042

Tags: authentication

Tags: RCE

Researchers found that a known RCE vulnerability in Zimbra Collaboration was chained with a new authentication vulnerability to drop backdoor web shells on thousands of servers

(Read more…)

The post Thousands of Zimbra mail servers backdoored in large scale attack appeared first on Malwarebytes Labs.

Read more

Update now! VMWare patches critical vulnerabilities in several products

Credit to Author: Pieter Arntz| Date: Wed, 03 Aug 2022 13:27:47 +0000

In a critical security advisory VMWare patches multiple RCE and EoP vulnerabilities in several affected products.

The post Update now! VMWare patches critical vulnerabilities in several products appeared first on Malwarebytes Labs.

Read more

Spring4Shell: Zero-Day vulnerability CVE-2022-22965 in Spring Framework

Credit to Author: Shiv Mohan| Date: Wed, 06 Apr 2022 12:53:22 +0000

A Zero-day Remote Code Execution Vulnerability with critical severity has been identified as CVE-2022-22965 aka Spring4Shell or SpringShell…

The post Spring4Shell: Zero-Day vulnerability CVE-2022-22965 in Spring Framework appeared first on Quick Heal Blog | Latest computer security news, tips, and advice.

Read more

Update now! Many HP printers affected by three critical security vulnerabilities

Credit to Author: Pieter Arntz| Date: Thu, 24 Mar 2022 11:20:35 +0000

HP has issued two security advisories that encourage users of a multitude of printer models to update the firmware to the latest version to thwart 3 critical vulnerabilities.

The post Update now! Many HP printers affected by three critical security vulnerabilities appeared first on Malwarebytes Labs.

Read more

US charges four Chinese military members with Equifax hack

Credit to Author: Lisa Vaas| Date: Wed, 12 Feb 2020 11:48:41 +0000

The indictment suggests the hack was part of a series of major data thefts organized by Chinese military and intelligence agencies.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/2euIheG1QVA” height=”1″ width=”1″ alt=””/>

Read more

Critical Android flaws patched in February bulletin

Credit to Author: Danny Bradbury| Date: Wed, 05 Feb 2020 11:46:14 +0000

Google has patched Android bugs that include a couple of critical flaws that could let hackers run their own code on the mobile operating system.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/k2wIz5MF-3I” height=”1″ width=”1″ alt=””/>

Read more