Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > vulnerability
#vulnerability

Critical vulnerabilities in Oracle WebLogic Server and Mitel MiCollab, CISA warns

7 January 2025  |  securebulletin.com  |  Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding critical vulnerabilities in Oracle WebLogic Server and Mitel MiCollab systems that are currently being exploited...

>> read more

DoS vulnerability CVE-2024-56332 in Next.js, update now

4 January 2025  |  securebulletin.com  |  Vulnerability

Next.js, a popular React framework, has recently addressed a critical denial-of-service (DoS) vulnerability identified as CVE-2024-56332. This security flaw was discovered in the server actions feature of Next.js,...

>> read more

Glutton: a new PHP backdoor

2 January 2025  |  securebulletin.com  |  Spyware

On April 29, 2024, XLab’s threat analysis system detected unusual activities linked to a new malware named Glutton, designed to stealthily infiltrate popular PHP frameworks. This malware was...

>> read more

Urgent: update your .NET installer link, new Microsoft issue

30 December 2024  |  securebulletin.com  |  Vulnerability

Microsoft has issued an urgent warning to .NET developers regarding the imminent shutdown of two critical domains used for installing .NET components: dotnetcli.azureedge.net and dotnetbuilds.azureedge.net. This action is...

>> read more

Curl vulnerability exposes user credentials in redirects

16 December 2024  |  securebulletin.com  |  Vulnerability

A recently discovered vulnerability in cURL, identified as CVE-2024-11053, poses a significant risk by potentially exposing user credentials during HTTP redirects. This flaw affects various applications that utilize...

>> read more

Cryptojacking: protecting Docker and Kubernetes environments from new attacks

15 December 2024  |  securebulletin.com  |  Malware

Cryptojacking—the unauthorized use of systems to mine cryptocurrency—has seen a troubling surge, with attackers increasingly exploiting misconfigured Docker and Kubernetes environments. This alarming trend targets high-performance cloud infrastructures,...

>> read more

QNAP NAS vulnerabilities

9 December 2024  |  dark6  |  Vulnerability

QNAP NAS systems, widely used for data storage, have been flagged for several critical vulnerabilities that pose significant risks to users and organizations. Here’s what you need to...

>> read more

Apache Tomcat vulnerability (CVE-2024-38286)

24 September 2024  |  dark6  |  Vulnerability

A severe vulnerability has emerged in Apache Tomcat, a widely used Java application server. Identified as CVE-2024-38286, this flaw poses a serious risk to organizations that rely on...

>> read more