Eighty to 200 law firms across the UK may have their phone, email, and case management systems inaccessible following a cyberattack against managed service provider CTS that involved the exploitation of the Citrix Bleed vulnerability, reports The Record, a news site by cybersecurity firm Recorded Future.
While Intel released a fix for the Reptar flaw — and that’s good — security pros say teams must keep the BIOS, OS, and drivers updated as a matter of course.
Ongoing remote code execution attacks leveraging four Juniper J-Web interface vulnerabilities, tracked from CVE-2023-36844 to CVE-2023-36847, in a pre-auth exploit chain have led to their inclusion in the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog, BleepingComputer reports.
Atlassian Confluence Data Center and Server instances infected with the Effluence backdoor through the exploitation of the critical vulnerability, tracked as CVE-2023-22515, remained compromised even after the application of issued patches, reports The Hacker News.