SolarWinds Issues Patch for Critical ARM Vulnerability Enabling RCE Attacks

SolarWinds has released fixes to address two security flaws in its Access Rights Manager (ARM) software, including a critical vulnerability that could result in remote code execution.
The vulnerability, tracked as CVE-2024-28991, is rated 9.0 out of a maximum of 10.0 on the CVSS scoring system. It has been described as an instance of deserialization of untrusted data.
“SolarWinds Access Rights

The Hacker News – ​Read More

Cambodian Tycoon Sanctioned for Forced Cyber Labor, Trafficking

The sanctions are unlikely to affect the growing network of criminals who lure victims into working for cybercrime sweat shops around the world.

darkreading – ​Read More

‘Void Banshee’ Exploits Second Microsoft Zero-Day

Attackers have been using the Windows MSHTML Platform spoofing vulnerability in conjunction with another zero-day flaw.

darkreading – ​Read More

Ivanti Cloud Bug Goes Under Exploit After Alarms Are Raised

Three days after Ivanti published an advisory about the high-severity vulnerability CVE-2024-8190, threat actors began to abuse the flaw.

darkreading – ​Read More

Feds sentence 12 crypto thieves behind SIM swaps, home invasions

Post Content

The Record from Recorded Future News – ​Read More

Elon Musk Is a National Security Risk

Musk’s now-deleted post questioning why no one has attempted to assassinate Joe Biden and Kamala Harris renews concerns over his work for the US government—and potential to inspire extremist violence.

Security Latest – ​Read More

‘Clipper’ malware is being used to steal crypto, Binance warns

Post Content

The Record from Recorded Future News – ​Read More

Tile Trackers now include an SOS feature – here’s how they compare with Apple’s AirTags

Available in all shapes and sizes, Life360’s new line of Tile Bluetooth trackers helps you do much more than just keep track of valuable items.

Latest stories for ZDNET in Security – ​Read More

Apple Patches Major Security Flaws with iOS 18 Refresh

Apple warns that attackers can use Siri to access sensitive user data, control nearby devices, or view recent photos without authentication. 

The post Apple Patches Major Security Flaws with iOS 18 Refresh appeared first on SecurityWeek.

SecurityWeek – ​Read More