Remove 2023 Remove Firewall Remove Penetration Testing
article thumbnail

CVE-2023-50969: Critical Flaw in Imperva SecureSphere WAF Could Lead to Devastating Breaches

Penetration Testing

A newly discovered vulnerability in Imperva SecureSphere, a widely used on-premise Web Application Firewall (WAF), has the potential to expose organizations to devastating security breaches.

article thumbnail

CVE-2024-25089: RCE Risk in Malwarebytes Binisoft Windows Firewall Control

Penetration Testing

Recently, two security vulnerabilities have been identified in Malwarebytes Binisoft Windows Firewall Control, a widely-used tool that enhances the capabilities of the Windows Firewall.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

PingRAT: secretly passes C2 traffic through firewalls using ICMP payloads

Penetration Testing

PingRAT PingRAT secretly passes C2 traffic through firewalls using ICMP payloads.

Firewall 111
article thumbnail

Zyxel Security Vulnerabilities: DoS, Command Injection & More

Penetration Testing

Zyxel’s recent security advisory spotlights multiple vulnerabilities present in select firewall and access point models. Vulnerability Breakdown CVE-2023-6397 (Firewalls): Potential denial-of-service... The post Zyxel Security Vulnerabilities: DoS, Command Injection & More appeared first on Penetration Testing.

article thumbnail

Critical flaw in WooCommerce Payments plugin allows site takeover

Security Affairs

On March 23, 2023, researchers from Wordfence observed that the “ WooCommerce Payments – Fully Integrated Solution Built and Supported by Woo” plugin had been updated to version 5.6.2. it was first discovered by Michael Mazzolini from penetration testing firm GoldNetwork. The vulnerability impacts plugin versions 4.8.0

article thumbnail

Top API Security Tools 2023

eSecurity Planet

AWS quotes Reblaze pricing starting at $5,440 a month for comprehensive web application protection, including API, web application firewall and DDoS protection. Read next: Top Application Security Tools & Software The post Top API Security Tools 2023 appeared first on eSecurityPlanet.

article thumbnail

Progress fixed a third flaw in MOVEit Transfer software

Security Affairs

Customers have to modify firewall rules to deny HTTP and HTTPs traffic to the software on ports 80 and 443. Recently another MOVEit software vulnerability, tracked as CVE-2023-34362 , made the headlines. The group claimed to have compromised the companies by exploiting the zero-day CVE-2023-34362.