Radio silence from DMS vendor quartet over XSS zero-days

Providers of vulnerable document management systems have yet to respond or release patches for serious issues reported. Researchers have identified multiple critical vulnerabilities in document management systems (DMS) across four major enterprise vendors, who have yet to address these issues. In a blog post released on February 7, Tod Beardsley, the director of research at…

Read More

Radio silence from DMS vendor quartet over XSS zero-days

There has been no response or patch announced by the providers of vulnerable document management systems. Security researchers have revealed a series of critical vulnerabilities in document management systems (DMS) affecting four enterprise vendors, which remain unresolved as of now. In a recent blog post, Tod Beardsley, the director of research at Rapid7, highlighted that…

Read More

Radio silence from DMS vendor quartet over XSS zero-days

Providers of vulnerable document management systems have yet to respond or issue patches for reported security issues. Recent research has revealed several significant vulnerabilities in document management systems (DMS) affecting four major enterprise vendors, none of which have yet made any corrections to the issues. A blog post released on February 7 highlights insights from…

Read More

Deserialized web security roundup: KeePass dismisses ‘vulnerability’ report, OpenSSL gets patched, and Reddit admits phishing hack

Your biweekly summary of application security vulnerabilities, innovative hacking methods, and recent cybersecurity developments. KeePass has found itself in the spotlight following the identification of a suspected vulnerability that threatens its credibility. Security experts alerted that it may be feasible to create a trigger that extracts all data from the KeePass database in plain text,…

Read More

Deserialized web security roundup: KeePass dismisses ‘vulnerability’ report, OpenSSL gets patched, and Reddit admits phishing hack

Your bi-weekly update on application security vulnerabilities, innovative hacking methods, and other essential cybersecurity information. KeePass has recently found itself under scrutiny regarding a reported vulnerability within its password management software. Security experts cautioned that a potential flaw could allow an attacker to trigger the export of all data from the KeePass database in plaintext…

Read More

Remote code execution flaw patched in Apache Kafka

Charlie Osborne 15 February 2023 at 14:01 UTC Updated: 17 February 2023 at 11:07 UTC New vulnerabilities related to Remote Code Execution (RCE) and denial-of-service have been identified in Kafka Connect. UPDATED The Apache Software Foundation (ASF) has addressed a critical vulnerability that could allow RCE attacks via Kafka Connect. This flaw, announced on February…

Read More
Back To Top