Follow Cyber Kendra on Google News! | WhatsApp | Telegram

Add as a preferred source on Google
Vulnerability

Downfall Flaw: New Data Vulnerability in Intel’s Chips

Intel has recently addressed a processor vulnerability called " Downfall ", which has affected several chip models from 2015 onwards.  Thi…

MOVEit vulnerability: U.S. operation reports data leakage for up to 11 million people

US service provider Maximus , specializing in health and social services, is the latest victim of a critical vulnerability in the MOVEit Transfer pro…

Zenbleed - A Serious Leak Threat to AMD Zen 2 Processors

Tavis Ormandy, a researcher with Google Information Security, has discovered a serious silicon-level bug dubbed Zenbleed that can be exploited by ro…

Another Unauthenticated SQLi Flaw Patched in MOVEit Transfer Software

Progress Software, the creators of the renowned MOVEit Transfer, a popular secure file transfer software, has recently identified and patched a criti…

Exploit Released for Critical MOVEit Transfer RCE Vulnerability

On May 31, 2023, Progress Software Corporation released a security advisory for its MOVEit Transfer application. The advisory centered on a severe SQ…

Multiple SQL Injection Vulnerabilities in MOVEit Transfer with Fresh Security Patches

Progress Software, the creator of the MOVEit Transfer application, has released patches aimed at fixing newly discovered SQL injection vulnerabilitie…

OpenAI Fixed Account Takeover Bug in ChatGPT

Security researcher, Nagali found a critical account takeover vulnerability in the OpenAI ChatGPT application that allowed an attacker to take over s…

PoC Exploit Released for VMware RCE Bug

Security researcher from Horizon3's Attack Team has released the technical details and exploit code for VMware vRealize Log Insight appliances. …

Citrix Warns for New Zeroday Vulnerability Exploited in Wild

After Fortinet issued an emergency patch for critical security vulnerabilities in its FortiOS SSL-VPN product. Now, today Citrix released another em…

Fortinet Warns for New Pre-auth RCE Vulnerability Exploited in Wild

On Monday, Fortinet issued an emergency patch for critical security vulnerabilities in its FortiOS SSL-VPN product.  The vulnerability is now tracked…

Google Researcher Found Critical RCE in Visual Studio Code

A security researcher from Google discovered critical remote code execution flaws in the   Visual Studio Code , that allow an attacker to fully take …

Twitter Fix Session Validation Bug on Password Reset

Twitter has just fixed the password reset bug that allowed Twitter accounts to stay logged in from multiple devices after a voluntary password reset…

Dirty Cred : New Privilege Escalation Vulnerability in Linux

A new Linux kernel exploitation called Dirty Cred was revealed at last week’s Black Hat security conference.  The flaw which is identified as CVE-202…

ElectroVolt- Hacking Discord, Microsoft Teams, and Other Electron Apps

Security researchers discovered a series of vulnerabilities in twenty commonly used Electron applications and gained Remote Code Execution within app…

ÆPIC Leak — Flaws in Intel CPU that Leaks Sensitive Data

A couple of researchers from Sapienza University of Rome and Graz University of Technology have discovered a new vulnerability dubbed " ÆPIC Lea…

RCE Vulnerability in Audio Decoders of Qualcomm and MediaTek Chips

Check Point Research has identified vulnerabilities in the ALAC format which is used by the largest mobile chip manufacturers, Qualcomm and MediaTek.…

Nginx Release Advisory about Nginx 0day Claims

It all started on 9th April, when a Twitter account connected to a group called “BlueHornet” tweeted about an experimental exploit for NGINX 1.18, cl…

VMware Patch Critical RCE Affecting Workspace ONE Access and Identity Manager

VMware released a critical advisory addressing security vulnerabilities found and resolved in VMware’s Workspace ONE Access, VMware Identity Manager…

Spring4Shell: Spring Confirmed the RCE in Spring Framework, Advisory Released

Update:  Apache Tomcat releases versions 10.0.20, 9.0.62, and 8.5.78 as part of the mitigation effort. Manual Workarounds for Apache Tomcat upgrade…

SpringShell: Spring Core RCE 0-day Vulnerability

Update as of 31st March: Spring has Confirmed the RCE in Spring Framework . The team has just published the statement along with the mitigation guide…