Vulnerabilities & Exploits

Securezoo Cybersecurity Threat Center blog posts of new vulnerabilities and exploits.

Researchers discover Critical RCE 0-day “Log4Shell” vulnerability (CVE-2021-44228) in Apache Log4j logging utility (update)

Researchers have discovered a Critical 0-day vulnerability (CVE-2021-44228) in Apache Log4j logging utility that can result in remote code execution (RCE). In addition, CISA and Microsoft also issue new guidance for log4j vulnerability remediation.

Researchers discover Critical RCE 0-day “Log4Shell” vulnerability (CVE-2021-44228) in Apache Log4j logging utility (update) Read More »

Google releases Chrome 96 security update (96.0.4664.110) with fix for High risk zero-day exploited in the wild

Google has released Chrome 96 security update (96.0.4664.110) for Windows, Mac and Linux with a fix for one High risk vulnerability exploited in the wild.

Google releases Chrome 96 security update (96.0.4664.110) with fix for High risk zero-day exploited in the wild Read More »

Apple releases security updates for iOS 15.2, macOS Big Sur 11.6.2, macOS Monterey 12.1 and other products

Apple has released security updates for iOS 15.2, macOS Big Sur 11.6.2, macOS Monterey 12.1, and other Apple products.

Apple releases security updates for iOS 15.2, macOS Big Sur 11.6.2, macOS Monterey 12.1 and other products Read More »

Mozilla releases Firefox 95 with RLBox security technology and fixes for 6 High severity vulnerabilities

The Mozilla Foundation has patched six High risk vulnerabilities in Firefox 95, as well as added a new security feature, RLBox, that hardens Firefox against third party library vulnerabilities.

Mozilla releases Firefox 95 with RLBox security technology and fixes for 6 High severity vulnerabilities Read More »

CISA and FBI alert: Attackers actively exploiting vulnerability in Zoho ManageEngine ServiceDesk Plus

The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) issued a joint advisory warning attackers are actively exploiting a vulnerability CVE-2021-44077 in Zoho ManageEngine ServiceDesk Plus.

CISA and FBI alert: Attackers actively exploiting vulnerability in Zoho ManageEngine ServiceDesk Plus Read More »

Windows Mobile Device Management 0-day vulnerability could lead to local privilege escalation

A security researcher has discovered a zero-day vulnerability CVE-2021-24084 in Windows Mobile Device Management that could allow information disclosure and local privilege escalation (LPE).

Windows Mobile Device Management 0-day vulnerability could lead to local privilege escalation Read More »