The Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of two new vulnerabilities to its Known Exploited Vulnerabilities Catalog.
These vulnerabilities in widely used technologies are actively exploited by malicious actors, posing significant risks to federal and private...
Cisco has issued a critical security advisory concerning multiple vulnerabilities in its ATA 190 Series Analog Telephone Adapters.
These vulnerabilities could potentially allow remote attackers to execute arbitrary code, posing significant risks to affected devices.
The vulnerabilities impact both...
In a recent security advisory, Cisco has disclosed multiple vulnerabilities affecting its Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers.
Additionally, Cisco has issued a security advisory regarding a critical vulnerability in its Nexus Dashboard...
A critical vulnerability has been identified in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software, posing significant risks to network stability and security.
This flaw allows unauthenticated, remote attackers to exhaust the UDP packet memory of...
Cisco has disclosed a critical vulnerability in the JSON-RPC API feature used by the web-based management interfaces of several products, including Cisco Crosswork Network Services Orchestrator (NSO), Cisco Optical Site Manager, and Cisco RV340 Dual WAN Gigabit VPN Routers....
Cisco Systems has issued a critical security advisory for a vulnerability in the Cisco Meraki Systems Manager (SM) Agent for Windows.
The flaw, identified as CVE-2024-20430, allows authenticated local attackers to execute arbitrary code with elevated privileges. With a...
Cisco has announced its intent to acquire Robust Intelligence, a leader in AI application security. This acquisition aligns with Cisco's commitment to enhancing IT infrastructure and security in the face of AI's transformative potential, as highlighted by the 2024...
Cisco has identified a critical vulnerability in the iPXE boot function of its IOS XR software. This vulnerability stems from insufficient image verification during the iPXE boot process, which could allow an authenticated, local attacker to install an unverified...
Cisco recently disclosed that its RV340 and RV345 Dual WAN Gigabit VPN Routers have a significant flaw in the upload module. This flaw could allow a remote, authenticated attacker to run arbitrary code on an impacted device.
With a CVSS base...
A novel information-stealing campaign detailing the attackers' tactics, techniques, and procedures (TTPs) throughout the attack lifecycle, where the Mitre ATT&CK framework is used to classify these TTPs and identify potential detection points.
By examining the campaign's behavior and communication with...