Author: Admin

Home » Archives for Admin » Page 919
Project

Vulnerability with 9.8 severity in Control Web Panel is under active exploit

Enlarge (credit: Getty Images) Malicious hackers have begun exploiting a critical vulnerability in unpatched versions of the Control Web Panel, a widely used interface for web hosting. “This is an unauthenticated RCE,” members of the Shadowserver group wrote on Twitter, using the abbreviation for remote code exploit. “Exploitation is trivial and a PoC published.” PoC...

Project

Fortinet says hackers exploited critical vulnerability to infect VPN customers

(credit: Fortinet) An unknown threat actor abused a critical vulnerability in Fortinet’s FortiOS SSL-VPN to infect government and government-related organizations with advanced custom-made malware, the company said in an autopsy report on Wednesday. Tracked as ​​CVE-2022-42475, the vulnerability is a heap-based buffer overflow that allows hackers to remotely execute malicious code. It carries a severity...

Project

Indigenous tech group asks Apache Foundation to change its name

Enlarge / A 2015 photo by Zaheda Bhorat (shared by Rich Bowen) showing many of the original Apache Software Foundation’s creators, with co-founder Jim Jagielski holding aloft the Foundation’s feather logo. The photo is part of a set aiming to recreate a similar image taken around the time of the foundation’s launch. (credit: Rich Bowen/Zaheda...

Project

FAA outage that grounded flights blamed on old tech and damaged database file

Enlarge / Travelers wait in a terminal at Reagan National Airport in Arlington, Virginia, during an FAA outage that grounded flights across the US on January 11, 2023. (credit: Getty Images | Saul Loeb) A Notice to Air Missions system outage that grounded flights across the US yesterday morning seems to have been caused by...

Project

Hundreds of SugarCRM servers infected with critical in-the-wild exploit

Enlarge For the past two weeks, hackers have been exploiting a critical vulnerability in the SugarCRM (customer relationship management) system to infect users with malware that gives them full control of their servers. The vulnerability began as a zero-day when the exploit code was posted online in late December. The person posting the exploit described...