Recent cybersecurity reports indicate multiple vulnerabilities affecting various technologies. A proof of concept (PoC) exploit was released for a command injection vulnerability in the Palo Alto Expedition Tool. Additionally, a flaw in Google's OAuth system has left numerous users exposed, particularly through failed startup domains. In another development, vulnerabilities in four tunneling protocols have compromised 4.2 million internet hosts, including VPN servers and routers, allowing potential hijacking of devices and access to networks. The W3 Total Cache plugin for WordPress has also been identified as exposing hundreds of thousands of sites to attacks. Furthermore, critical vulnerabilities in the Rsync file-synchronizing tool were disclosed, posing risks of remote code execution and data leakage. Other vulnerabilities include a Microsoft Configuration Manager flaw allowing remote code execution, and a zero-day vulnerability in the Windows Common Log File System (CLFS) Driver, identified as CVE-2024-49138, for which PoC code has been released. Lastly, flaws in the Planet WGS-804HPT Industrial Switch could potentially be exploited to achieve remote code execution.
Internetin reunalaitteen haavoittuvuus voi avata ovia tunkeutujille, jos hallintakäyttöliittymä näkyy julkisessa verkossa. Juhani Eronen muistuttaa, että yritysten on tärkeää rajoittaa pääsyä hallintakäyttöliittymiin aina, kun se on mahdollista. #kyberturvallisuus #tietoturva https://t.co/kYGMsJmvxF
A flaw in the W3 Total Cache plugin exposes hundreds of thousands of WordPress sites to attacks https://t.co/zBDy3cfeJt
Planet WGS-804HPT Industrial Switch flaws could be chained to achieve remote code execution https://t.co/AUMcnu6u22