Emergency patch issued for Ivanti Connect Secure VPN flaw under attack – Go Health Pro

Emergency patch issued for Ivanti Connect Secure VPN flaw under attack – Go Health Pro

An unpatched vulnerability in the Ivanti Connect Secure VPN has been under active attack. Researchers with Google’s Mandiant Cloud security team said that one or more threat actors are currently exploiting CVE-2025-0282 for remote takeover attacks on targeted networks. The flaw, originally exploited as a zero-day vulnerability, has since been given an emergency patch and … Read more

CVSS 10.0 Flaw Enables RCE via Unsafe Serialization – Go Health Pro

CVSS 10.0 Flaw Enables RCE via Unsafe Serialization – Go Health Pro

Dec 27, 2024Ravie LakshmananVulnerability / Software Security The Apache Software Foundation (ASF) has released patches to address a maximum severity vulnerability in the MINA Java network application framework that could result in remote code execution under specific conditions. Tracked as CVE-2024-52046, the vulnerability carries a CVSS score of 10.0. It affects versions 2.0.X, 2.1.X, and … Read more

Researchers uncover AMD chip flaw threatening cloud data – Go Health Pro

Researchers uncover AMD chip flaw threatening cloud data – Go Health Pro

Security researchers have identified a vulnerability in AMD processors that they have dubbed badRAM and which could allow threat actors with physical access to cloud computing environments to bypass encryption protections, reports The Record, a news site by cybersecurity firm Recorded Future. The flaw circumvents AMD’s Secure Encrypted Virtualization, which encrypts virtual machine memory to … Read more

Critical Flaw in ProjectSend Under Active Exploitation Against Public-Facing Servers – Go Health Pro

Critical Flaw in ProjectSend Under Active Exploitation Against Public-Facing Servers – Go Health Pro

Nov 27, 2024Ravie LakshmananVulnerability / Software Security A critical security flaw impacting the ProjectSend open-source file-sharing application has likely come under active exploitation in the wild, according to findings from VulnCheck. The vulnerability, originally patched over a year-and-a-half ago as part of a commit pushed in May 2023 , was not officially made available until … Read more

CISA Urges Agencies to Patch Critical “Array Networks” Flaw Amid Active Attacks – Go Health Pro

CISA Urges Agencies to Patch Critical “Array Networks” Flaw Amid Active Attacks – Go Health Pro

Nov 26, 2024Ravie LakshmananVulnerability / Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched critical security flaw impacting Array Networks AG and vxAG secure access gateways to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2023-28461 (CVSS score: 9.8), … Read more

x