Vulnerability Summary for the Week of May 4, 2020

Original release date: May 11, 2020The CISA Weekly Vulnerability Summary Bulletin is created using information from the NIST NVD. In some cases, the vulnerabilities in the Bulletin may not yet…

Comments Off on Vulnerability Summary for the Week of May 4, 2020

Google Releases Security Updates for Chrome 

Google has released Chrome version 81.0.4044.138 for Windows, Mac, and Linux. This version addresses vulnerabilities that an attacker could exploit to take control of an affected system. The Cybersecurity and…

Comments Off on Google Releases Security Updates for Chrome 

AA20-126A: APT Groups Target Healthcare and Essential Services

This is a joint alert from the United States Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) and the United Kingdom’s National Cyber Security Centre (NCSC). CISA…

Comments Off on AA20-126A: APT Groups Target Healthcare and Essential Services

Vulnerability Summary for the Week of April 27, 2020

Original release date: May 4, 2020The CISA Weekly Vulnerability Summary Bulletin is created using information from the NIST NVD. In some cases, the vulnerabilities in the Bulletin may not yet…

Comments Off on Vulnerability Summary for the Week of April 27, 2020

Unpatched Oracle WebLogic Servers Vulnerable to CVE-2020-2883

Oracle has released a blog post warning users that a previously disclosed Oracle WebLogic Server remote code execution vulnerability (CVE-2020-2883) is being exploited in the wild. Oracle disclosed the vulnerability…

Comments Off on Unpatched Oracle WebLogic Servers Vulnerable to CVE-2020-2883

SaltStack Patches Critical Vulnerabilities in Salt

SaltStack has released a security update to address critical vulnerabilities affecting Salt versions prior to 2019.2.4 and 3000.2. Salt is an open-source remote task and configuration management framework widely used in…

Comments Off on SaltStack Patches Critical Vulnerabilities in Salt

WordPress Releases Security Update

WordPress 5.4 and prior versions are affected by multiple vulnerabilities. An attacker could exploit some of these vulnerabilities to take control of an affected website. The Cybersecurity and Infrastructure Security…

Comments Off on WordPress Releases Security Update