Exploits and vulnerabilities

MalwareBytesSecurity

Intel CPU vulnerabilities fixed. But should you update?

Categories: Exploits and vulnerabilities

Categories: News

Tags: CVE-2022-21123

Tags: CVE-2022-21125

Tags: CVE-2022-21127

Tags: CVE-2022-21166

Tags: Intel

Tags: VMs

Tags: microcode

Microsoft has released out of band updates for information disclosure vulnerabilities in Intel CPUs, but who needs them?

(Read more…)

The post Intel CPU vulnerabilities fixed. But should you update? appeared first on Malwarebytes Labs.

Read More
MalwareBytesSecurity

Update now! February’s Patch Tuesday tackles three zero-days

Categories: Exploits and vulnerabilities

Categories: News

Tags: patch Tuesday

Tags: Microsoft

Tags: Apple

Tags: Adobe

Tags: SAP

Tags: Citrix

Tags: Cisco

Tags: Atlassian

Tags: Google

Tags: Mozilla

Tags: Forta

Tags: OpenSSH

Tags: CVE-2023-21823

Tags: CVE-2023-21715

Tags: OneNote

Tags: CVE-2023-23376

Tags: CVE-2023-21706

Tags: CVE-2023-21707

Tags: CVE-2023-21529

Tags: CVE-2023-21716

Tags: CVE-2023-23378

Tags: CVE-2023-22501

Tags: CVE-2023-24486

Tags: CVE-2023-24484

Tags: CVE-2023-24484

Tags: CVE-2023-24483

Tags: CVE-2023-25136

Tags: GoAnywhere

Microsoft has released updates to patch three zero-days and lots of other vulnerabilities and so have several other vendors

(Read more…)

The post Update now! February’s Patch Tuesday tackles three zero-days appeared first on Malwarebytes Labs.

Read More
MalwareBytesSecurity

Update now! Apple patches vulnerabilities in MacOS and iOS

Categories: Apple

Categories: Exploits and vulnerabilities

Tags: Apple

Tags: macOS Ventura

Tags: 13.2.1

Tags: iOS

Tags: iPadOS

Tags: 16.3.1

Tags: CVE-2023-23514

Tags: CVE-2023-23522

Tags: CVE-2023-23529

Tags: use after free

Tags: type confusion

Apple has released patches for macOS Ventura, iPadOs, and iOS. Among the patched vulnerabilities is a WebKit vulnerability which may have been exploited in the wild.

(Read more…)

The post Update now! Apple patches vulnerabilities in MacOS and iOS appeared first on Malwarebytes Labs.

Read More
MalwareBytesSecurity

[update]Two year old vulnerability used in ransomware attack against VMware ESXi

Categories: Exploits and vulnerabilities

Categories: News

Categories: Ransomware

Tags: VMware

Tags: ESXi

Tags: Nevada

Tags: ransomware

Tags: Linux

Tags: CVE-2021-21974

Over the weekend, several CERTs warned about ongoing ransomware attacks against unpatched VMware ESXi virtual machines.

(Read more…)

The post [update]Two year old vulnerability used in ransomware attack against VMware ESXi appeared first on Malwarebytes Labs.

Read More
MalwareBytesSecurity

Two year old vulnerability used in ransomware attack against VMware ESXi

Categories: Exploits and vulnerabilities

Categories: News

Categories: Ransomware

Tags: VMware

Tags: ESXi

Tags: Nevada

Tags: ransomware

Tags: Linux

Tags: CVE-2021-21974

Over the weekend, several CERTs warned about ongoing ransomware attacks against unpatched VMware ESXi virtual machines.

(Read more…)

The post Two year old vulnerability used in ransomware attack against VMware ESXi appeared first on Malwarebytes Labs.

Read More
MalwareBytesSecurity

Update vRealize now! VMware patches critical RCE vulnerabilities

Categories: Exploits and vulnerabilities

Categories: News

Tags: vRealize

Tags: VMware

Tags: CVE-2022-31706

Tags: CVE-2022-31704

Tags: CVE-2022-31702

Tags: path traversal

Tags: directory traversal

Tags: broken access control

VMware has issued a security advisory for vRealize Log Insight that covers four vulnerabilities, including two critical RCEs

(Read more…)

The post Update vRealize now! VMware patches critical RCE vulnerabilities appeared first on Malwarebytes Labs.

Read More