Atlassian Confluence ZeroDay

Atlassian Confluence ZeroDay

Atlassian has confirmed the critical vulnerability in Confluence Server and Data Center, and the company said there is currently no fix, but it is working on a patch. All versions…
Horde Webmail ZeroDay

Horde Webmail ZeroDay

A zero-day vulnerability in Horde Webmail enables attackers to take over the webserver and pivot to compromising an organization’s other services, according to security researchers. The flaw’s abuse relies on…
Google Dev Channel has a RCE vulnerability

Google Dev Channel has a RCE vulnerability

The WebAssembly and V8 JavaScript engine used in both the browsers of Google Chrome and Chromium recently patched critical remote code execution vulnerability. Successful exploitation of the issue could allow…
Zoom RCE bug Haunts ! Patch it

Zoom RCE bug Haunts ! Patch it

A bunch of bugs identified in Zoom that can be exploited to compromise another user over chat by sending specially crafted Extensible Messaging and Presence Protocol (XMPP) messages. Below are…
WordPress Plugin RCE Bug goes Wild

WordPress Plugin RCE Bug goes Wild

A RCE flaw tracked as  CVE-2021-25094 in the Tatsu Builder plugin for WordPress, which is deployed on roughly 100,000 websites, is being widely exploited by hackers. Even though a fix…
Azure Synapse RCE Fixed by Microsoft

Azure Synapse RCE Fixed by Microsoft

Microsoft has addressed a critical RCE flaw, tracked as CVE-2022-29972 and named SynLapse, resides in thrid party driver that used by Azure Synapse and Azure Data Factory discovered by researchers from orca…
RocketKitten Exploits VMWare RCE

RocketKitten Exploits VMWare RCE

An espionage group from Iran, tracked as Rocket Kitten has begun exploiting a recently patched critical vulnerability in VMware Workspace ONE Access/Identity Manager technology to deliver the Core Impact penetration…