Atlassian has confirmed the critical vulnerability in Confluence Server and Data Center, and the company said there is currently no fix, but it is working on a patch. All versions…
A zero-day vulnerability in Horde Webmail enables attackers to take over the webserver and pivot to compromising an organization’s other services, according to security researchers. The flaw’s abuse relies on…
The WebAssembly and V8 JavaScript engine used in both the browsers of Google Chrome and Chromium recently patched critical remote code execution vulnerability. Successful exploitation of the issue could allow…
A bunch of bugs identified in Zoom that can be exploited to compromise another user over chat by sending specially crafted Extensible Messaging and Presence Protocol (XMPP) messages. Below are…
A security researcher at StarLabs (Nguyễn Tiến Giang (Jang), found a fresh way to exploit a recently patched (February patch Tuesday) deserialization bug in Microsoft SharePoint and stage remote code…
A RCE flaw tracked as CVE-2021-25094 in the Tatsu Builder plugin for WordPress, which is deployed on roughly 100,000 websites, is being widely exploited by hackers. Even though a fix…
Microsoft has addressed a critical RCE flaw, tracked as CVE-2022-29972 and named SynLapse, resides in thrid party driver that used by Azure Synapse and Azure Data Factory discovered by researchers from orca…
An espionage group from Iran, tracked as Rocket Kitten has begun exploiting a recently patched critical vulnerability in VMware Workspace ONE Access/Identity Manager technology to deliver the Core Impact penetration…