A proof-of-concept exploit for a critical security flaw in Apache ActiveMQ enables remote code execution on servers while remaining undetected. Although the flaw was patched by Apache, many organisations remain vulnerable. The exploit facilitates stealthier attacks on the vulnerability, allowing attackers to gain access and potentially cause damage such as account access removal, destroying data, or hijacking resources. Administrators are urged to patch the vulnerability as soon as possible.
Rogue VPN servers used to spread malware via malicious updates
AmberWolf researchers identified two vulnerabilities, dubbed “NachoVPN,” in popular VPN products SonicWall NetExtender and Palo Alto Networks GlobalProtect, which can be exploited by cyber-attackers to