PoC Exploit Targeting Apache Struts Surfaces on GitHub

Researchers have discovered freely available PoC code and exploit that can be used to attack unpatched security holes in Apache Struts 2. Continue reading PoC Exploit Targeting Apache Struts Surfaces on GitHub

Supermicro, Apache Struts, & HTTPS – Paul’s Security Weekly #574

In the security news, Spanish driver tests positive for every drug test, vulnerabilities found in the remote management interface of Supermicro servers, Apache Struts 2 flaw in the wild, HTTPS crypto-shame, and how to manipulate Apple’s podcast c… Continue reading Supermicro, Apache Struts, & HTTPS – Paul’s Security Weekly #574

Cisco Issues Security Patch Updates for 32 Flaws in its Products

Cisco today released thirty security patch advisory to address a total of 32 security vulnerabilities in its products, three of which are rated critical, including the recently disclosed Apache Struts remote code execution vulnerability that is being e… Continue reading Cisco Issues Security Patch Updates for 32 Flaws in its Products

Whoops, Turns Out 2.5 Million More Americans Were Affected By Equifax Breach

Equifax data breach was bigger than initially reported, exposing highly sensitive information of more Americans than previously revealed.

Credit rating agency Equifax says an additional 2.5 million U.S. consumers were also impacted by the massive data… Continue reading Whoops, Turns Out 2.5 Million More Americans Were Affected By Equifax Breach

Equifax Suffered Data Breach After It Failed to Patch Old Apache Struts Flaw

The massive Equifax data breach that exposed highly sensitive data of as many as 143 million people was caused by exploiting a flaw in Apache Struts framework, which Apache patched over two months earlier of the security incident, Equifax has confirmed… Continue reading Equifax Suffered Data Breach After It Failed to Patch Old Apache Struts Flaw

Apache Struts 2 Flaws Affect Multiple Cisco Products

After Equifax massive data breach that was believed to be caused due to a vulnerability in Apache Struts, Cisco has initiated an investigation into its products that incorporate a version of the popular Apache Struts2 web application framework.

Apache… Continue reading Apache Struts 2 Flaws Affect Multiple Cisco Products

New Apache Struts Zero-Day Vulnerability Being Exploited in the Wild

Security researchers have discovered a Zero-Day vulnerability in the popular Apache Struts web application framework, which is being actively exploited in the wild.

Apache Struts is a free, open-source, Model-View-Controller (MVC) framework for creati… Continue reading New Apache Struts Zero-Day Vulnerability Being Exploited in the Wild