15 November 2023
New Intel CPU Vulnerability Impacts Multi-Tenant Virtualized Environments
- Intel addresses a high-severity vulnerability, codenamed Reptar, affecting desktop, mobile, and server CPUs.
- Tracked as CVE-2023-23583 with a CVSS score of 8.8, it could allow escalation of privilege, information disclosure, and denial of service in multi-tenant virtualized environments.
Microsoft Releases Patch Updates for 5 New Zero-Day Vulnerabilities
- Microsoft releases patches for 63 security bugs in November 2023, including three actively exploited zero-day vulnerabilities.
- The updates cover Critical, Important, and Moderate severity flaws, emphasizing the need for prompt application of these fixes.
VMware Warns of Unpatched Critical Cloud Director Vulnerability
- VMware issues an urgent warning about a critical, unpatched security flaw (CVE-2023-34060) in Cloud Director.
- The vulnerability could be exploited to bypass authentication protections, posing a significant risk to instances upgraded to version 10.5.
IPStorm botnet with 23,000 proxies for malicious traffic dismantled
- The U.S. Department of Justice announces the takedown of the IPStorm botnet's network and infrastructure, which included 23,000 proxies for malicious traffic.
WP Fastest Cache plugin bug exposes 600K WordPress sites to attacks
- A vulnerability in the WordPress plugin WP Fastest Cache is identified, allowing unauthenticated attackers to read the contents of a site's database, potentially affecting 600,000 WordPress sites.