Vulnerabilities & Exploits

Securezoo Cybersecurity Threat Center blog posts of new vulnerabilities and exploits.

Apple fixes vulnerabilities under active exploit (CVE-2021-30663 and CVE-2021-30665)

Apple has released security updates to fix vulnerabilities in iOS 14.5.1, macOS Big Sur 11.3.1, Safari 14.1, watchOS 7.4.1, and other products under active exploit in the wild.

Apple fixes vulnerabilities under active exploit (CVE-2021-30663 and CVE-2021-30665) Read More »

Another 3 Pulse Connect Secure Critical vulnerabilities discovered

Ivanti has discovered three new Pulse Connect Secure (PCS) Critical vulnerabilities CVE-2021-22894, CVE-2021-22899 and CVE-2021-22900, nearly two weeks after reported active exploits against other PCS vulnerabilities.

Another 3 Pulse Connect Secure Critical vulnerabilities discovered Read More »

Alert: Attackers exploiting Pulse Connect Secure vulnerabilities (updated)

CISA warned attackers continue to exploit Pulse Connect Secure vulnerabilities. The alert was issued after CISA confirmed malicious activity on public and private entity networks. Additional detection methods were also added on April 30.

Alert: Attackers exploiting Pulse Connect Secure vulnerabilities (updated) Read More »

“BadAlloc” vulnerabilities impact broad range of IoT and OT devices

Security researchers from Microsoft have discovered a collection of vulnerabilities dubbed “BadAlloc” that affect a broad range of IoT and OT devices in industrial, medical and consumer sectors.

“BadAlloc” vulnerabilities impact broad range of IoT and OT devices Read More »

Samba fixes vulnerability (CVE-2021-20254) that could allow an attacker unauthorized access to files

Samba has released a software update to fix a vulnerability (CVE-2021-20254) that could allow an attacker unauthorized access to files. A remote attacker could take advantage of this bug and exploit unpatched systems.

Samba fixes vulnerability (CVE-2021-20254) that could allow an attacker unauthorized access to files Read More »

Apple security updates for iOS 14.5, macOS Big Sur 11.3 and other products (updated)

Apple has released security updates to fix vulnerabilities in iOS 14.5, macOS Big Sur 11.3, Safari 14.1, tvOS 14.5, watchOS 7.4, Xcode 12.5 and other products.

Apple security updates for iOS 14.5, macOS Big Sur 11.3 and other products (updated) Read More »

New Supernova malware analysis reveals new APT cyberattack methods against vulnerable SolarWinds infrastructure

The Cybersecurity and Infrastructure Security Agency (CISA) has published a new analysis report on Supernova malware used in a cyberattack and long term compromise of an entity’s network and SolarWinds systems.

New Supernova malware analysis reveals new APT cyberattack methods against vulnerable SolarWinds infrastructure Read More »