Stories
Slash Boxes
Comments

SoylentNews is people

posted by Fnord666 on Saturday July 25 2020, @09:55PM   Printer-friendly
from the keep-up-with-your-patches dept.

Hackers actively exploit high-severity networking vulnerabilities:

Hackers are actively exploiting two unrelated high-severity vulnerabilities that allow unauthenticated access or even a complete takeover of networks run by Fortune 500 companies and government organizations.

The most serious exploits are targeting a critical vulnerability in F5's Big-IP advanced delivery controler, a device that's typically placed between a perimeter firewall and a Web application to handle load balancing and other tasks. The vulnerability, which F5 patched three weeks ago, allows unauthenticated attackers to remotely run commands or code of their choice. Attackers can then use their control of the device to hijack the internal network it's connected to.

[...] Attackers are exploiting a second vulnerability found in two network products sold by Cisco. Tracked as CVE-2020-3452, the path traversal flaw resides in the company's Adaptive Security Appliance and Firepower Threat Defense systems. It allows unauthenticated people to remotely view sensitive files that among other things can disclose WebVPN configurations, bookmarks, web cookies, partial web content, and HTTP URLs. Cisco issued a patch on Wednesday. A day later, it updated its advisory.

[...] The impact of these vulnerabilities—particularly the one affecting F5 customers—is serious. These in-the-wild attacks provide ample reason to occupy the weekend of any IT administrators who have yet to patch their vulnerable systems.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 0, Offtopic) by Anonymous Coward on Saturday July 25 2020, @11:01PM (2 children)

    by Anonymous Coward on Saturday July 25 2020, @11:01PM (#1026330)

    Now is the time to strike for higher pay.

    As an industry, we have TWENTY YEARS OF pay raises to catch up on.

    Fuck the corporations! They abandoned us twenty years ago and have spent the past two decades investing in India instead of the United States. They are traitors to our country. They betrayed the trust we placed in them and the gifts we have lavished upon them.

    NO MORE WEEKEND WORK WITHOUT PAY

    Starting Score:    0  points
    Moderation   0  
       Offtopic=4, Insightful=1, Interesting=1, Underrated=1, TouchĂ©=1, Total=8
    Extra 'Offtopic' Modifier   0  

    Total Score:   0  
  • (Score: 1) by Zinnia Zirconium on Saturday July 25 2020, @11:14PM (1 child)

    by Zinnia Zirconium (11163) on Saturday July 25 2020, @11:14PM (#1026338) Homepage Journal

    I get paid double for weekend work.

    • (Score: 0) by Anonymous Coward on Sunday July 26 2020, @12:05AM

      by Anonymous Coward on Sunday July 26 2020, @12:05AM (#1026362)

      Yes but you'll die young to make up for it... karma.