A critical vulnerability in Cisco VPN routers makes it possible for attackers to completely take over the remote devices or have them rebooted, causing a denial-of-service, the network manufacturer that released security updates to fix the problem warns. The vulnerability, designated CVE-2022-20842, is present in the web interface of Cisco Small Business RV routers RV340, […]
A vulnerability in crypto bridge Nomad caused during maintenance has resulted in the theft of $190 million worth of cryptocurrencies. Coindesk will let you know. Nomad is a protocol that allows users to exchange tokens between different blockchains. When a user wants to transfer cryptocurrency from one blockchain to another, the bridge puts it in […]
Hackers are constantly monitoring software vendor bulletin boards for new vulnerability announcements they can leverage for initial access to a corporate network or to perform remote code execution. So how do you manage your vulnerabilities on a periodic basis?
With remote working now the norm agent-based scanning is becoming a must, while network-based scanning is an optional extra.External vulnerability scanning can give a great overview of what you look like to a hacker, the information that can be gleaned without access to your systems can be limited. Internal vulnerability scanning is about protecting the […]
Microsoft’s market dominance creates a big disucssion as they also have the most critical vulnerabilities. Does your organisation assess the 3rd party risk of technology suppliers?
Citrix warned customers to deploy security updates that address a critical Citrix Application Delivery Management (ADM) vulnerability that can let attackers reset admin passwords.Citrix ADM is a web-based solution that provides admins with a centralized cloud-based console for managing on-premises or cloud Citrix deployments, including Citrix Application Delivery Controller (ADC), Citrix Gateway, and Citrix Secure […]
This guidance helps SME’s, large organisations and Public Sector bodies to:– understand the basics of vulnerability scanning and how it integrates with a VMP– decide on when and how to employ vulnerability scanning most effectively– set the important criteria when purchasing a vulnerability scanning solution
VMware has issued patches to contain two security flaws impacting Workspace ONE Access, Identity Manager, and vRealize Automation that could be exploited to backdoor enterprise networks.
10 common mistakes when configuring, managing and securing systems means that attackers can still break into organizations and gain access to networks and data, the US, UK, Canadian, Dutch and New Zealand governments warn in a joint statement. advisory. The advisory wants to point out common mistakes, security practices and configurations that lead to poor […]
The cybersecurity researchers at Morphisec have discovered recently a critical RCE vulnerability in VMware Workspace ONE Access that is being actively exploited by advanced hackers, and this critical flaw has been tracked as “CVE-2022-22954.” By exploiting CVE-2022-22954, the attackers are able to access the network environment initially.

