NetScaler SAML Flaw Lets Remote Attackers Run Code as Root
Public research turns a patched NetScaler memory overflow into a root-code-execution risk for SAML deployments, making build verification urgent.
Read article →Reader view
Choose the default article length.
Network activity, protocols, infrastructure, and detection.
Public research turns a patched NetScaler memory overflow into a root-code-execution risk for SAML deployments, making build verification urgent.
Read article →Exposed ASA and FTD remote-access services need release-specific hot fixes; Cisco offers no workaround for the exploited denial-of-service flaw.
Read article →Government agencies traced Gunra from exploited edge devices through credential theft, cloud exfiltration, backup deletion, and cross-platform ransomware.
Read article →CISA confirms exploitation of a pre-authentication LoadMaster command-injection flaw. API-enabled appliances need a fixed release and an exposure review.
Read article →OVSwrap exploits a 16-bit nested-action limit in the Linux kernel, leaving defenders to verify both the running fix and the earlier exposure window.
Read article →Cisco's August IOS XE hardening release fixes seven vulnerability classes across five reviewed trains, and only an upgrade closes the exposure.
Read article →TP-Link TL-WR940N hardware revision 6 can let an unauthenticated attacker turn a LAN client's outbound RTSP session into code execution inside the router kernel.
Read article →INC ransomware activity raises the cost of treating an SMA 1000 hotfix as closure: affected appliances need log and configuration triage before defenders can trust them again.
Read article →IPMI's RAKP exchange exposes material for offline password cracking, leaving defenders with a management-plane incident that host telemetry may miss.
Read article →One variant uses UPnP to open 155 inbound paths, then relays same-port traffic through infected devices that conceal the real command servers.
Read article →Actors changed controller IP addresses and passwords across at least seven states. Operators need known-good logic and connected-device evidence before closing an incident.
Read article →On-premises VCO is exposed by default. Arista says defenders must inspect web activity and managed Edge state after patching.
Read article →Every on-prem Secure FMC configuration is affected. Cisco published hot fixes, a shared license.tmp indicator, and credential-rotation guidance.
Read article →