Oracle October 2023 Critical Patch Update Addresses 176 CVEs
Oracle addresses 176 CVEs in its fourth quarterly update of 2023 with 387 patches, including 46 critical updates.
CVE-2023-4966:Citrix NetScaler ADC and NetScaler Gateway Information Disclosure Exploited in the Wild
A critical information disclosure vulnerability in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway has been exploited in the wild as a zero-day vulnerability. 强烈建议企业立即进行修补。
CVE-2023-20198:在现实中遭利用的 Cisco IOS XE 零日漏洞
A maximum severity CVSS 10 zero-day vulnerability in Cisco IOS XE has been exploited in the wild. Organizations should apply the mitigation steps from Cisco as soon as possible until patches are released.
Microsoft 的 2023 年 10 月补丁星期二解决了 103 个 CVE(CVE-2023-36563、CVE-2023-41763)
Microsoft addresses 103 CVEs including two vulnerabilities that were exploited in the wild.
CVE-2023-38545、CVE-2023-38546:curl 中新漏洞的常见问题
Frequently asked questions relating to two vulnerabilities patched in curl version 8.4.0
MrBeast 诈骗:经过验证的帐户,DeepFakes 用于在 Impersonations 中在 YouTube 和 TikTok 上推广虚假赠品
MrBeast, the most popular YouTube creator as of October 2023, has been impersonated in a variety of scams on YouTube and TikTok, including a recent deepfake promoting a free iPhone giveaway
CVE-2023-22515:Atlassian Confluence Data Center and Server 中的零日漏洞在现实环境中遭到利用
A critical zero-day vulnerability in Atlassian Confluence Data Center and Server has been exploited in the wild in a limited number of cases. Organizations should patch or apply the mitigation steps as soon as possible.
CVE-2023-40044、CVE-2023-42657:Progress Software 修补 WS_FTP 服务器中的多个漏洞
Progress Software patches multiple flaws in its WS_FTP Server product, including a pair of critical flaws, one with a maximum CVSS rating of 10
CVE-2023-41064、CVE-2023-4863、CVE-2023-5129:ImageIO 和 WebP/libwebp 零日漏洞的常见问题
Frequently asked questions relating to vulnerabilities in Apple, Google and the open source libwebp library.
CVE-2023-29357、CVE-2023-24955:针对 Microsoft SharePoint Server 漏洞发布的漏洞利用链
A proof-of-concept exploit chain has been released for two vulnerabilities in Microsoft SharePoint Server that can be exploited to achieve unauthenticated remote code execution.
Microsoft 2023 年 9 月补丁星期二修复了 61 个 CVE (CVE-2023-36761)
Microsoft addresses 61 CVEs including two vulnerabilities that were exploited in the wild
CVE-2023-20269:据报道,Cisco Adaptive Security Appliance 和 Firepower Threat Defense Reportedly 中的零日漏洞被勒索软件集团利用
Ransomware groups including LockBit and Akira are reportedly exploiting a zero-day vulnerability in Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) appliances with VPN functionality enabled.