• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
cisa flags 6 vulnerabilities apple, apache, adobe , d link,

CISA Flags 6 Vulnerabilities – Apple, Apache, Adobe , D-Link, Joomla Under Attack

You are here: Home / General Cyber Security News / CISA Flags 6 Vulnerabilities – Apple, Apache, Adobe , D-Link, Joomla Under Attack
January 10, 2024

The U.S. Cybersecurity and Infrastructure Security Company (CISA) has added 6 security flaws to its Identified Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

This consists of CVE-2023-27524 (CVSS rating: 8.9), a superior-severity vulnerability impacting the Apache Superset open-source knowledge visualization software package that could enable remote code execution. It was mounted in version 2.1.

Details of the issue to start with arrived to gentle in April 2023, with Horizon3.ai’s Naveen Sunkavally describing it as a “risky default configuration in Apache Superset that enables an unauthenticated attacker to acquire remote code execution, harvest credentials, and compromise details.”

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

It is really at this time not known how the vulnerability is getting exploited in the wild. Also added by CISA are five other flaws –

  • CVE-2023-38203 (CVSS score: 9.8) – Adobe ColdFusion Deserialization of Untrusted Details Vulnerability
  • CVE-2023-29300 (CVSS score: 9.8) – Adobe ColdFusion Deserialization of Untrusted Information Vulnerability
  • CVE-2023-41990 (CVSS rating: 7.8) – Apple Multiple Merchandise Code Execution Vulnerability
  • CVE-2016-20017 (CVSS rating: 9.8) – D-Website link DSL-2750B Gadgets Command Injection Vulnerability
  • CVE-2023-23752 (CVSS rating: 5.3) – Joomla! Poor Accessibility Management Vulnerability

It is really worth noting that CVE-2023-41990, patched by Apple in iOS 15.7.8 and iOS 16.3, was made use of by mysterious actors as portion of Operation Triangulation adware attacks to realize remote code execution when processing a specially crafted iMessage PDF attachment.

Federal Civilian Executive Department (FCEB) businesses have been advised to use fixes for the aforementioned bugs by January 29, 2024, to safe their networks towards lively threats.

Located this article attention-grabbing? Follow us on Twitter  and LinkedIn to read through much more unique written content we publish.


Some elements of this posting are sourced from:
thehackernews.com

Previous Post: «alert: water curupira hackers actively distributing pikabot loader malware Alert: Water Curupira Hackers Actively Distributing PikaBot Loader Malware
Next Post: Microsoft’s January 2024 Windows Update Patches 48 New Vulnerabilities microsoft's january 2024 windows update patches 48 new vulnerabilities»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Qilin Ransomware Adds “Call Lawyer” Feature to Pressure Victims for Larger Ransoms
  • Iran’s State TV Hijacked Mid-Broadcast Amid Geopolitical Tensions; $90M Stolen in Crypto Heist
  • 6 Steps to 24/7 In-House SOC Success
  • Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider
  • 67 Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developers
  • New Android Malware Surge Hits Devices via Overlays, Virtualization Fraud and NFC Theft
  • BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with MacOS Backdoor Malware
  • Secure Vibe Coding: The Complete New Guide
  • Uncover LOTS Attacks Hiding in Trusted Tools — Learn How in This Free Expert Session
  • Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign

Copyright © TheCyberSecurity.News, All Rights Reserved.