CISA warned today that hackers are now actively exploiting a recently patched high-severity SolarWinds Serv-U flaw to crash servers. SolarWinds has patched four critical Serv-U remote code execution ...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned today that hackers are now actively exploiting a recently patched high-severity SolarWinds Serv-U flaw to crash servers. Serv-U ...
Four newly disclosed critical CVEs could allow attackers to create privileged accounts and execute arbitrary code, and they reinforce SolarWinds’ status as a high-value target. SolarWinds continues to ...
UPDATE: SolarWinds has fixed a Serv-U bug discovered when attackers used the Log4j flaw to try to log in to the file-sharing software. Attackers are trying to log in to SolarWinds Serv-U file-sharing ...
The fourth vulnerability is of the “Insecure Direct Object Reference” (IDOR) type. It also allows malicious actors to execute malicious code from the network with “root” privileges if successfully ...
Federal civilian agencies face a hard deadline to fix a SolarWinds Serv-U vulnerability that attackers are already using against live targets. The Cybersecurity and Infrastructure Security Agency ...