Category Security

Critical Flaw Patched in VMware Workstation and Fusion

VMware has addressed multiple security vulnerabilities in its Workstation and Fusion products. The vulnerabilities identified as CVE-2023-20869, CVE-2023-20870, CVE-2023-20871, and CVE-2023-20872 have been privately reported to VMware and have a CVSS v3.x score of 7.3 9.3. One of the flaws,…

Insecure Default Configuration Exposes Servers to RCE Attacks

April 26, 2023Rabbi LakshmananServer security/vulnerability The maintainers of the Apache Superset open source data visualization software have released a fix to plug in an insecure default configuration that could lead to remote code execution. Vulnerabilities tracked as CVE-2023-27524 (CVSS score:…

New SLP Vulnerability Could Enable Massive DDoS Attacks

Security researchers have discovered a high-severity vulnerability in the Service Location Protocol (SLP). This vulnerability could start as one of the largest DDoS amplification attacks ever seen. BitSight and Curesec state that bug CVE-2023-29552, classified under CVSS 8.6, could allow…

Google Finds Flaws in Intel TDX After Nine-Month Audit

Google analyzed 81 potential attack vectors and identified 10 vulnerabilities in Intel Trust Domain Extensions (TDX) after a nine-month audit process. TDX is a type of “confidential computing” technology built to provide security while processing sensitive data in a hardware-isolated…