Cybersecurity

Critical Jenkins Vulnerability Exposes Servers to RCE Attacks – Patch ASAP!

Jan 25, 2024NewsroomVulnerability / Software Security The maintainers of the open-source continuous integration/continuous delivery and deployment (CI/CD) automation software Jenkins have resolved nine security flaws, including a critical bug that, if successfully exploited, could result in remote code execution (RCE). The issue, assigned the CVE identifier CVE-2024-23897, has been described as an arbitrary file read […]

Cybersecurity

TensorFlow CI/CD Flaw Exposed Supply Chain to Poisoning Attacks

Jan 18, 2024NewsroomSupply Chain Attacks / AI Security Continuous integration and continuous delivery (CI/CD) misconfigurations discovered in the open-source TensorFlow machine learning framework could have been exploited to orchestrate supply chain attacks. The misconfigurations could be abused by an attacker to “conduct a supply chain compromise of TensorFlow releases on GitHub and PyPi by compromising […]

Cybersecurity

CitrixBleed isn’t going away: Security experts struggle to control critical vulnerability

U.S. authorities are struggling to contain a critical vulnerability in Citrix Netscaler Application Delivery Controller and Netscaler Gateway, widely used networking appliances that help companies enable secure remote access.  Thousands of organizations worldwide use the technology, and researchers have seen attacks targeting a wide range of industries, including financial services companies, defense contractors, law firms, […]

Cybersecurity

Cisco Patches Critical Vulnerability in BroadWorks Platform

Cisco on Wednesday announced patches for a critical-severity vulnerability in the BroadWorks Application Delivery Platform and BroadWorks Xtended Services Platform. Tracked as CVE-2023-20238, the vulnerability affecting the BroadWorks calling and collaboration platform was identified in the single sign-on (SSO) implementation and could be exploited by remote, unauthenticated attackers to forge credentials and access affected systems. […]

Cybersecurity

PurFood data breach exposes personal information of 1.2 million customers

PurFoods, an American meal delivery service which provides both to individual customers as well as working with more than 500 health plans, managed care organizations, governments and agencies to provide medically-tailored meals to those covered by Medicare and Medicaid, has recently suffered a data breach that exposed the data of more than 1.2 million customers.  […]