this post was submitted on 23 Feb 2024
13 points (93.3% liked)

Cybersecurity

5984 readers
182 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 2 years ago
MODERATORS
 

IT administrators are urged to immediately patch on-premises ScreenConnect servers due to active exploitation of a critical vulnerability, CVE-2024-1709, with a maximum CVSS score of 10.0. This authentication bypass bug allows for arbitrary code execution and sensitive data access without user interaction. ConnectWise, the software's developer, also disclosed a path traversal vulnerability, CVE-2024-1708, with a CVSS score of 8.4. While cloud instances have been updated, on-premises installations require manual patching. The vulnerabilities pose significant risks, with potential for ransomware attacks, especially given the software's widespread use and the trust placed in remote access tools.

no comments (yet)
sorted by: hot top controversial new old
there doesn't seem to be anything here