Category: Cybersecurity

CISA Announces Ransomware Vulnerability Warning Pilot

Last week, Monday March 13, CISA announced the creation of the Ransomware Vulnerability Warning Pilot (RVWP). This...

by Cody Rubio
Read More

KEV Catalog: PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability (CVE-2019-11043)

Since May 2009, every major Linux distribution had a privilege escalation vulnerability due to the default pkexec application provided by Polkit. This is...

by Cody Rubio
Read More

Introducing and Setting Up the New Kali Linux 2023.1: Kali Purple

Today, Kali Linux’s 10-year anniversary, Kali Linux released their newest Kali Linux version: Kali Purple. Kali Linux...

by Cody Rubio
Read More

KEV Catalog: SaltStack Salt Authentication Bypass (CVE-2020-11651)

The SaltStack Salt Authentication Bypass vulnerability (CVE-2020-116151) is a critical remote code execution vulnerability.

by Cody Rubio
Read More

An Overview of the Biden-Harris New National Cyber Security Strategy

The key messages emphasize where the U.S. government wants to allocate its cybersecurity spending and who should...

by Cody Rubio
Read More

KEV Catalog: Red Hat Polkit “pwnkit” Out-of-Bounds Read and Write Vulnerability...

Since May 2009, every major Linux distribution had a privilege escalation vulnerability due to the default pkexec application provided by Polkit. This is...

by Cody Rubio
Read More

DDoS Attacks Emerge as Main Cyber Threat in Ukraine Conflict

The CyberPeace Institute has recorded cyber-attacks against a variety of host nations, including Ukraine and Russia. Reviewing...

by Cody Rubio
Read More

KEV Catalog: VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability...

Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions are vulnerable to remote code execution due...

by Cody Rubio
Read More

Reports: Rapid Rise In Open Source Supply Chain Attacks

Last month, Mend released their Open Source Risk Report which outlines the risks associated with open source vulnerabilities and software supply...

by Cody Rubio
Read More

KEV Catalog: VMware Spring Cloud Gateway Code Injection Vulnerability (CVE-2022-22947)

Wyatt Dahlenburg found this Expression Language injection vulnerability.  Applications using Spring Cloud Gateway are vulnerable to a code...

by Cody Rubio
Read More