ZOHO Zero Day Vulnerability

Zoho has released a security patch to address an authentication bypass vulnerability, tracked as CVE-2021-40539, in its Manage Engine AD Self-Service Plus. The vulnerability is already exploited in attacks in…
ActiveX Control RCE

ActiveX Control RCE

Microsoft said it has identified a limited number of attacks targeting a remote code execution vulnerability in MSHTML that affects Microsoft Windows tracked as CVE-2021-40444. An attacker could craft a…
TensorFlow leaves YAML

TensorFlow leaves YAML

TensorFlow, a preferred Python- located AI and also expert system task cultivated through Google has actually fallen support for YAML, to spot an important code execution weakness. YAMLl is actually…
Atlassian Confluence Exploit

Atlassian Confluence Exploit

Threat actors were spotted exploiting the CVE-2021-26084 vulnerability in Atlassian’s Confluence enterprise collaboration product. Atlassian released  security patches to address the critical flaw earlier last week. The flaw is an OGNL injection issue that…

OpenSSL Bug Fix in QNAP & Synology

NAS maker QNAP is investigating and working on security updates to address RCE and DoS vulnerabilities patched by OpenSSL last week. The security flaws tracked as CVE-2021-3711 and CVE-2021-3712, impact…
Fortinet Command Injection Vulnerability

Fortinet Command Injection Vulnerability

An authenticated attacker could execute arbitrary commands as the root user on the underlying system via the SAML server configuration page. The vulnerability impacts Fortinet FortiWeb versions 6.3.11 and earlier, an authenticated…
Another RCE in Print Spooler Mayhem awaits

Another RCE in Print Spooler Mayhem awaits

Microsoft acknowledged yet another remote code execution vulnerability in the Windows Print Spooler component, after a day of releasing arch tuesday updates adding that it's working to remediate the issue…