Arris router vulnerability could lead to complete takeover

Categories: Exploits and vulnerabilities

Categories: News

Tags: Yerodin Richards

Tags: Arris

Tags: routre

Tags: CVE-2022-45701

Tags: default credentials

A security researcher found an authenticated remote code execution vulnerability in very wide-spread Arris router models.

(Read more…)

The post Arris router vulnerability could lead to complete takeover appeared first on Malwarebytes Labs.

Read more

Update now! February’s Patch Tuesday tackles three zero-days

Categories: Exploits and vulnerabilities

Categories: News

Tags: patch Tuesday

Tags: Microsoft

Tags: Apple

Tags: Adobe

Tags: SAP

Tags: Citrix

Tags: Cisco

Tags: Atlassian

Tags: Google

Tags: Mozilla

Tags: Forta

Tags: OpenSSH

Tags: CVE-2023-21823

Tags: CVE-2023-21715

Tags: OneNote

Tags: CVE-2023-23376

Tags: CVE-2023-21706

Tags: CVE-2023-21707

Tags: CVE-2023-21529

Tags: CVE-2023-21716

Tags: CVE-2023-23378

Tags: CVE-2023-22501

Tags: CVE-2023-24486

Tags: CVE-2023-24484

Tags: CVE-2023-24484

Tags: CVE-2023-24483

Tags: CVE-2023-25136

Tags: GoAnywhere

Microsoft has released updates to patch three zero-days and lots of other vulnerabilities and so have several other vendors

(Read more…)

The post Update now! February’s Patch Tuesday tackles three zero-days appeared first on Malwarebytes Labs.

Read more

Update now! Apple patches vulnerabilities in MacOS and iOS

Categories: Apple

Categories: Exploits and vulnerabilities

Tags: Apple

Tags: macOS Ventura

Tags: 13.2.1

Tags: iOS

Tags: iPadOS

Tags: 16.3.1

Tags: CVE-2023-23514

Tags: CVE-2023-23522

Tags: CVE-2023-23529

Tags: use after free

Tags: type confusion

Apple has released patches for macOS Ventura, iPadOs, and iOS. Among the patched vulnerabilities is a WebKit vulnerability which may have been exploited in the wild.

(Read more…)

The post Update now! Apple patches vulnerabilities in MacOS and iOS appeared first on Malwarebytes Labs.

Read more

[update]Two year old vulnerability used in ransomware attack against VMware ESXi

Categories: Exploits and vulnerabilities

Categories: News

Categories: Ransomware

Tags: VMware

Tags: ESXi

Tags: Nevada

Tags: ransomware

Tags: Linux

Tags: CVE-2021-21974

Over the weekend, several CERTs warned about ongoing ransomware attacks against unpatched VMware ESXi virtual machines.

(Read more…)

The post [update]Two year old vulnerability used in ransomware attack against VMware ESXi appeared first on Malwarebytes Labs.

Read more

Two year old vulnerability used in ransomware attack against VMware ESXi

Categories: Exploits and vulnerabilities

Categories: News

Categories: Ransomware

Tags: VMware

Tags: ESXi

Tags: Nevada

Tags: ransomware

Tags: Linux

Tags: CVE-2021-21974

Over the weekend, several CERTs warned about ongoing ransomware attacks against unpatched VMware ESXi virtual machines.

(Read more…)

The post Two year old vulnerability used in ransomware attack against VMware ESXi appeared first on Malwarebytes Labs.

Read more

Update vRealize now! VMware patches critical RCE vulnerabilities

Categories: Exploits and vulnerabilities

Categories: News

Tags: vRealize

Tags: VMware

Tags: CVE-2022-31706

Tags: CVE-2022-31704

Tags: CVE-2022-31702

Tags: path traversal

Tags: directory traversal

Tags: broken access control

VMware has issued a security advisory for vRealize Log Insight that covers four vulnerabilities, including two critical RCEs

(Read more…)

The post Update vRealize now! VMware patches critical RCE vulnerabilities appeared first on Malwarebytes Labs.

Read more

Own an older iPhone? Check you’re on the latest version to avoid this bug

Categories: Apple

Categories: Exploits and vulnerabilities

Categories: News

Tags: iOS 12.5.7

Tags: CVE-2022-42856

Tags: type confusion

Tags: WebKit

Apple has now released security content for iOS 12.5.7 which includes a patch for an actively exploited vulnerability in WebKit and many other updates.

(Read more…)

The post Own an older iPhone? Check you’re on the latest version to avoid this bug appeared first on Malwarebytes Labs.

Read more