news

MalwareBytesSecurity

CISA: You’ve got two weeks to patch Citrix NetScaler vulnerability CVE-2023-3519

Categories: Exploits and vulnerabilities

Categories: News

Tags: Citrix

Tags: NetScaler

Tags: CVE-2023-3519

Tags: web shell

A critical unauthenticated remote code execution vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway is being actively exploited

(Read more…)

The post CISA: You’ve got two weeks to patch Citrix NetScaler vulnerability CVE-2023-3519 appeared first on Malwarebytes Labs.

Read More
MalwareBytesSecurity

Microsoft validation error allowed state actor to access user email of government agencies and others

Categories: News

Tags: Microsoft. MSA

Tags: OWA

Tags: validation token

Tags: signing key

Tags: Storm-0556

Tags: GetAccessTokensForResource

Due to a validation error in Microsoft code, a suspected Chinese attacker was able to access user email from approximately 25 organizations, including government agencies.

(Read more…)

The post Microsoft validation error allowed state actor to access user email of government agencies and others appeared first on Malwarebytes Labs.

Read More
MalwareBytesSecurity

Act now! In-the-wild Zimbra vulnerability needs a workaround

Categories: Exploits and vulnerabilities

Categories: News

Tags: Zimbra

Tags: MalasLocker

Tags: vulnerability

Tags: Google

Tags: actively exploited

Tags: fn:escapeXml

Security experts are warning Zimbra users that a vulnerability for which there is no patch is being actively exploited in the wild.

(Read more…)

The post Act now! In-the-wild Zimbra vulnerability needs a workaround appeared first on Malwarebytes Labs.

Read More