Aggregator
CVE-2023-20867 | VMware Tools up to 12.2 improper authentication (VMSA-2023-0013 / Nessus ID 292731)
CVE-2023-4001 | Grub2 Password Protection improper authentication (EUVD-2023-53896 / Nessus ID 292734)
LastPass Warns of Fake Maintenance Messages Targeting Users’ Master Passwords
Critical Oracle WebLogic Server Proxy Vulnerability Lets Attackers Compromise the Server
Oracle has disclosed a severe security vulnerability affecting its Fusion Middleware suite, specifically targeting the Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. Assigned CVE-2026-21962, this flaw carries the maximum severity rating and poses an immediate threat to enterprise environments that use these proxy components. The vulnerability stems from a defect in how […]
The post Critical Oracle WebLogic Server Proxy Vulnerability Lets Attackers Compromise the Server appeared first on Cyber Security News.
Ваша IDE за вами подглядывает. Рассказываем о стилере, который живёт в расширениях для VS Code
CVE-2026-21975 | Oracle Database Server up to 19.29/21.20 Java VM privilege escalation (EUVD-2026-3537)
CVE-2026-21970 | Oracle Life Sciences Central Designer 7.0.1.0 information disclosure (EUVD-2026-3542)
CVE-2026-21973 | Oracle FLEXCUBE Investor Servicing 14.5.0.15.0/14.7.0.8.0/14.8.0.1.0 Oracle Financial Service improper authorization (EUVD-2026-3539)
CVE-2026-21974 | Oracle Life Sciences Central Designer 7.0.1.0 Platform information disclosure (EUVD-2026-3538)
CVE-2026-21978 | Oracle FLEXCUBE Universal Banking up to 14.8.0.0.0 Oracle Financial Service information disclosure (EUVD-2026-3534)
CVE-2026-21977 | Oracle Zero Data Loss Recovery Appliance Software up to 23.1.202509 Security information disclosure (EUVD-2026-3535)
JVN: 複数のFesto製品における技術情報の提供が不十分な問題
Cybercriminals speak the language young people trust
Criminal groups actively recruit, train, and retain people in structured ways. They move fast, pay in crypto, and place no weight on age. Young people are dealing with a new kind of addiction. It isn’t drugs, alcohol, or gambling. It’s screens. Constant time online chips away at attention, confidence, and judgment, and pushes young people toward views and choices that don’t always work in their favour. Children are drawn into organized crime for many reasons, … More →
The post Cybercriminals speak the language young people trust appeared first on Help Net Security.
JVN: Schneider Electric製Uni-Telwayドライバにおける不適切な入力確認の脆弱性
JVN: 複数のSchneider Electric製品における複数の脆弱性
Azure Private Endpoint Deployments Exposes Azure Resources to DoS Attack
A critical architectural flaw in Microsoft Azure’s Private Endpoint implementation that enables denial-of-service (DoS) attacks against production Azure resources. The vulnerability affects over 5% of Azure storage accounts, exposing organizations to service disruptions across Key Vault, CosmosDB, Azure Container Registry, Function Apps, and OpenAI accounts. How the Vulnerability Works Palo Alto Networks uncovers that the […]
The post Azure Private Endpoint Deployments Exposes Azure Resources to DoS Attack appeared first on Cyber Security News.
Airlock Digital Announces Independent TEI Study Quantifying Measurable ROI & Security Impact
Atlanta, GA, United States, January 20th, 2026, CyberNewsWire Airlock Digital, a leader in proactive application control and endpoint security, announced the release of The Total Economic Impact (TEI) of Airlock Digital, an independent study commissioned by Airlock Digital and conducted by Forrester Consulting. The study demonstrates a significant 224% return on investment (ROI) and a $3.8 […]
The post Airlock Digital Announces Independent TEI Study Quantifying Measurable ROI & Security Impact appeared first on Cyber Security News.