Apache SSRF bug Exploited

Threat actors are exploiting a recently addressed server-side request forgery (SSRF) vulnerability, tracked as CVE-2021-40438, in Apache HTTP servers. This flaw can be exploited against httpd web servers that have…

Imunify 360 Bug Could Deserialize PHP

A severe PHP deserialization vulnerability leading to code execution has been patched in Imunify360.  Imunify360 is a security platform for web-hosting servers that allows users to configure various settings for…

Exploit-as-a-service New Model in to Limelight

Cybercriminals are started leasing our rather than just selling zero-day vulnerabilities under a potential ‘exploit-as-a-service’ model for the first time This approach would allow more capable threat actors to ‘rent out’ zero-day…
Intune Bugs Certain Mobile Devices

Intune Bugs Certain Mobile Devices

Microsoft Intune is a cloud service that allows admins to manage Windows, macOS, iOS/iPadOS, and Android applications and devices in their enterprise environment. Microsoft says some Samsung Galaxy devices will be…
AWS API Gateway Exploited

AWS API Gateway Exploited

AWS API Gateway is a popular managed service for developers to write, manage, and secure their APIs in a Web environment. A space between characters and a few random letters,able…