ScanForge Security Digest 2632-03

200 items
78 critical20 high10 news

This week's security digest includes 0 actively exploited vulnerabilities (CISA KEV), 78 critical CVEs, and 20 high-severity CVEs. Review the details below and prioritize patching for any affected systems.

Critical

78

High Severity

20

Security News

10
Hackers breach TrueConf to trojanize client installers with backdoors Bleeping Computer

The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to r

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data SecurityWeek

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and Sh

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers The Hacker News

Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in us

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens The Hacker News

New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Acr

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication The Hacker News

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization sof

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist The Hacker News

N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts The Hacker News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impac

Friday Squid Blogging: Arctic Bobtail Squid Video Schneier on Security

Nice video of the Arctic bobtail squid. As usual, you can also use this squid post to talk about the security stories in

Content aggregated from NIST/NVD, CISA, CERT/CC, and public security news sources. External articles are linked to their original source.