* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Friday, December 26, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    City of Gautier signs off on entertainment contract extension for The Sound Amphitheater – WLOX

    City of Gautier signs off on entertainment contract extension for The Sound Amphitheater – WLOX

    The big business stories in Hollywood with entertainment reporter John Horn – NEPM

    Unveiling Hollywood’s Biggest Business Stories with Entertainment Reporter John Horn

    Bart Story Dies: Veteran Entertainment Research Executive Was 63 – Deadline

    Bart Story Dies: Veteran Entertainment Research Executive Was 63 – Deadline

    Las Vegas: Caesars Entertainment extending discounts into 2026 – CDC Gaming

    Las Vegas: Caesars Entertainment extending discounts into 2026 – CDC Gaming

    Ayushmann Khurrana Banks on Family Entertainment With Four-Film Slate Following ‘Thamma’ Success (EXCLUSIVE) – Variety

    Ayushmann Khurrana Banks on Family Entertainment With Four-Film Slate Following ‘Thamma’ Success (EXCLUSIVE) – Variety

    From The Pitt to Forever & Heated Rivalry , These Were The Best TV Shows Of 2025 – Refinery29

    From The Pitt to Forever & Heated Rivalry , These Were The Best TV Shows Of 2025 – Refinery29

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Micron Technology (MU) Stock News and Forecasts: Record Highs, HBM Demand, and Analyst Targets to Watch on Dec. 26, 2025 – ts2.tech

    Micron Technology Hits Record Highs: Unpacking the Surge in HBM Demand and Key Analyst Targets for December 26, 2025

    Mehai Technology Limited (540730)’s Trend in 2025 – Market Entry Points & Low Risk Trading Plans – Bollywood Helpline

    Mehai Technology Limited (540730) in 2025: Unlocking Key Market Entry Points and Low-Risk Trading Strategies

    [News] Japan Develops 10nm Nanoimprint Technology, with Potential to Tackle EUV Bottleneck – TrendForce

    Japan Unveils Revolutionary 10nm Nanoimprint Technology Set to Surpass EUV Constraints

    Rising technology use prompts digital detoxing efforts in Austin – Community Impact | News

    Austin Embraces a Growing Digital Detox Movement Amid Tech Surge

    Astrobotic Technology lands $17.5M in contracts to advance reusable rocket development – WPXI

    Astrobotic Technology Lands $17.5M to Drive Breakthroughs in Reusable Rocket Innovation

    State officials warn of technology threatening online victims with sophisticated scams – Kauai Now

    State Officials Sound the Alarm on Sophisticated Tech-Driven Online Scams Targeting Victims

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    City of Gautier signs off on entertainment contract extension for The Sound Amphitheater – WLOX

    City of Gautier signs off on entertainment contract extension for The Sound Amphitheater – WLOX

    The big business stories in Hollywood with entertainment reporter John Horn – NEPM

    Unveiling Hollywood’s Biggest Business Stories with Entertainment Reporter John Horn

    Bart Story Dies: Veteran Entertainment Research Executive Was 63 – Deadline

    Bart Story Dies: Veteran Entertainment Research Executive Was 63 – Deadline

    Las Vegas: Caesars Entertainment extending discounts into 2026 – CDC Gaming

    Las Vegas: Caesars Entertainment extending discounts into 2026 – CDC Gaming

    Ayushmann Khurrana Banks on Family Entertainment With Four-Film Slate Following ‘Thamma’ Success (EXCLUSIVE) – Variety

    Ayushmann Khurrana Banks on Family Entertainment With Four-Film Slate Following ‘Thamma’ Success (EXCLUSIVE) – Variety

    From The Pitt to Forever & Heated Rivalry , These Were The Best TV Shows Of 2025 – Refinery29

    From The Pitt to Forever & Heated Rivalry , These Were The Best TV Shows Of 2025 – Refinery29

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Micron Technology (MU) Stock News and Forecasts: Record Highs, HBM Demand, and Analyst Targets to Watch on Dec. 26, 2025 – ts2.tech

    Micron Technology Hits Record Highs: Unpacking the Surge in HBM Demand and Key Analyst Targets for December 26, 2025

    Mehai Technology Limited (540730)’s Trend in 2025 – Market Entry Points & Low Risk Trading Plans – Bollywood Helpline

    Mehai Technology Limited (540730) in 2025: Unlocking Key Market Entry Points and Low-Risk Trading Strategies

    [News] Japan Develops 10nm Nanoimprint Technology, with Potential to Tackle EUV Bottleneck – TrendForce

    Japan Unveils Revolutionary 10nm Nanoimprint Technology Set to Surpass EUV Constraints

    Rising technology use prompts digital detoxing efforts in Austin – Community Impact | News

    Austin Embraces a Growing Digital Detox Movement Amid Tech Surge

    Astrobotic Technology lands $17.5M in contracts to advance reusable rocket development – WPXI

    Astrobotic Technology Lands $17.5M to Drive Breakthroughs in Reusable Rocket Innovation

    State officials warn of technology threatening online victims with sophisticated scams – Kauai Now

    State Officials Sound the Alarm on Sophisticated Tech-Driven Online Scams Targeting Victims

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Now MOVEit maker Progress patches holes in WS_FTP

October 2, 2023
in Technology
Now MOVEit maker Progress patches holes in WS_FTP
Share on FacebookShare on Twitter

Infosec in brief Progress Software, maker of the mass-exploited MOVEit document transfer tool, is back in the news with more must-apply security patches, this time for another file-handling product: WS_FTP.

We’re told this software’s ad hoc transfer module and WS_FTP’s server management interface were found to have eight vulnerabilities, with CVSS severity scores ranging from 5.3 all the way to 10 out of 10.

At their most severe, all versions of WS_FTP Server prior to 8.7.4 and 8.8.2 are vulnerable to a .NET deserialization attack from a pre-authenticated attacker. If successful, the attacker could execute commands on the underlying host system, leveraging the other seven vulnerabilities, such as path traversal, XSS, SQL injection, missing cross-site request forgery protection, and the like. 

According to the Progress’ website, WS_FTP is used by some high-profile customers, including Scientific American, clothing store H&M, and the The Denver Broncos American football team to name a few. Those companies, and the rest of the WS_FTP community, are being advised to update their installation immediately. Exploitation of these bugs could well lead to public-facing systems being hijacked, and IT networks infiltrated at a large scale.

For those who don’t recall, a hole in Progress’ MOVEit software allowed miscreants to break into at least 400 organizations so far. Progress is facing over a dozen lawsuits connected to the MOVEit security fiasco. The Cl0p ransomware gang notably exploited the flaw to swipe people’s data.

Progress said it has seen no evidence that the WS_FTP vulnerabilities have been exploited in the wild, which is similar to what it said about another bug discovered in MOVEit in June. 

MOVEit attacks are ongoing as orgs fail to update their installations. Patches for WS_FTP are available for all supported versions, as well as a workaround for those who can’t immediately fix the flaws. 

Critical vulnerabilities: Is there something in the air?

My, has it been a week. Along with that nasty new Progress bug, a number of big tech names have had to issue urgent updates this week.

Exim, the open source mail server that is widely used on the internet, had some details of six flaws made public this week, and only three of them are patched. The two most serious issues allow full remote code execution, and according to the finders at the Zero Day Initiative the Exim Project has known about them since last year. Look out for updates and apply them as soon as you can.

“Fixes are available in a protected repository and are ready to be applied by the distribution maintainers,” commented Exim representative Heiko Schlittermann on Friday. “The remaining issues are debatable or misinformation [regarding whether] we need to fix them.”

Cisco has also had a bad week. The company’s Group Encrypted Transport VPN feature in IOS has a remote code execution bug that’s currently being tried in the wild, so get patching immediately.

Along with that issue, Cisco published 14 other security advisories this week, including news of several critical vulnerabilities in its SD-WAN Manager. 

Not to be outdone, Apple released a bunch of patches for Safari 17 and macOS Sonoma this week addressing a whole host of issues – several critical, including a one that’s under active exploit. The exploited code is yet another WebKit code execution vulnerability that can be triggered by opening malicious web content. 

Google also patched its fifth Chrome zero day of 2023 this week, which is under active exploit, along with issuing other fixes for nine other issues.

Oh, and Mozilla issued updates to Firefox (regular, ESR, Android and Focus for Android) and Thunderbird to address a critical heap buffer overflow vulnerability in libvpx.

Lastly, Mitsubishi Electric’s GX Works3 software is vulnerable (CVSS 9.8, CVE-2023-4088) to remote code execution thanks to permissions issues. 

One more active exploit to point out, and it’s a doozy:

CVSS 9.8 – CVE-2018-14667: An expression language injection vulnerability in RedHat’s RichFaces Framework may be exploited in the wild already.

Johnson Controls hit by IT ‘disruption’

Johnson Controls, a massive industrial control systems concern, has been hit by an equally massive ransomware attack that has reportedly taken a number of its systems offline and may even pose a national security risk. 

The afflicted business admitted to a “cybersecurity incident” in an SEC filing this week that multiple sources reported as a ransomware attack whose perpetrators made off with more than 27 terabytes of company data – neither of which Johnson has confirmed.  

“Johnson Controls International plc (the “Company”) has experienced disruptions in portions of its internal information technology infrastructure and applications,” the biz said, adding that other systems “are largely unaffected and remain operational.” 

According to one cybersecurity researcher, a ransomware group called Dark Angels is behind the attack. The group is reportedly demanding a $51 million ransom from Johnson Controls. 

The US Department of Homeland Security is also reportedly concerned that some of the stolen data may include sensitive information about Uncle Sam’s buildings, as Johnson handles physical security equipment for several important facilities.

Japanese ransomware attack triggers supply chain fears

A group that recently claimed to have leaked data stolen from Sony online has apparently struck again, claiming to have hit Japanese cell carrier NTT Docomo in what researchers fear could be a sign of a new supply chain attack.

Ransomed.vc, the group behind the claimed attack, is a relative newcomer whose attacks have raised questions in the underground world. But researchers at Resecurity are worried the miscreants may have used the Sony attack to sow seeds of future chaos. 

While it hasn’t confirmed the NTT Docomo attack and Sony incidents are linked, the security shop said it’s investigating “whether the Sony incident served as an intrusion vector for broader supply-chain compromise that enabled the group to illegally access the telecom operator’s data.” 

Ransomed.vc reportedly claimed to have abandoned trying to get Sony to pay a ransom and instead was looking for a buyer for 3.14GB of data stolen from the tech giant, but another individual released all the data while claiming Ransomed was lying about their attack. ®

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : The Register – https://go.theregister.com/feed/www.theregister.com/2023/10/01/in_brief_infosec/

Tags: makerMOVEittechnology
Previous Post

Mattel CEO Claims Its Barney Movie Won’t Be Weird

Next Post

ASUS’s Zenbook S 13 is light, fast, and immediately impressive

Tokyo Lifestyle (NASDAQ:TKLF) Could Be Struggling To Allocate Capital – simplywall.st

Is Tokyo’s Lifestyle at a Crossroads: Navigating Challenges in Capital Allocation

December 26, 2025
Micron Technology (MU) Stock News and Forecasts: Record Highs, HBM Demand, and Analyst Targets to Watch on Dec. 26, 2025 – ts2.tech

Micron Technology Hits Record Highs: Unpacking the Surge in HBM Demand and Key Analyst Targets for December 26, 2025

December 26, 2025
The 25 best sports photos of 2025 – and the stories behind them – BBC

25 Unforgettable Sports Photos of 2025 and the Legendary Stories Behind Them

December 26, 2025
Predators, Mammoth each have NHL-high 7 prospects at 2026 World Junior Championship – NHL.com

Predators and Mammoth Dominate with NHL-High Seven Prospects at 2026 World Junior Championship

December 26, 2025
Santa The Economic Terrorist – The Daily Economy

Santa The Economic Terrorist – The Daily Economy

December 26, 2025
City of Gautier signs off on entertainment contract extension for The Sound Amphitheater – WLOX

City of Gautier signs off on entertainment contract extension for The Sound Amphitheater – WLOX

December 26, 2025
What the doctors ordered: John Muir Health spreads holiday cheer with party, toy drive – Local News Matters

John Muir Health Spreads Holiday Cheer with Festive Party and Toy Drive

December 26, 2025
Opinion | Identity Politics: My Professional Look-Alikes – The Wall Street Journal

When Your Professional Doppelgängers Shake Up Identity Politics

December 26, 2025
Cyclosa Menge, 1866 (Araneidae) Orb-Weavers Build Stabilimenta That Resemble Larger Spiders – Wiley Online Library

Cyclosa Menge Orb-Weavers Craft Web Decorations That Mimic Larger Spiders

December 26, 2025
What feels strange and scary today might be a foundation of society tomorrow. – Psychology Today

What Feels Strange and Scary Today Could Become Tomorrow’s New Normal

December 26, 2025

Categories

Archives

December 2025
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
293031  
« Nov    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (988)
  • Economy (1,007)
  • Entertainment (21,884)
  • General (18,961)
  • Health (10,047)
  • Lifestyle (1,020)
  • News (22,149)
  • People (1,013)
  • Politics (1,021)
  • Science (16,222)
  • Sports (21,508)
  • Technology (15,990)
  • World (996)

Recent News

Tokyo Lifestyle (NASDAQ:TKLF) Could Be Struggling To Allocate Capital – simplywall.st

Is Tokyo’s Lifestyle at a Crossroads: Navigating Challenges in Capital Allocation

December 26, 2025
Micron Technology (MU) Stock News and Forecasts: Record Highs, HBM Demand, and Analyst Targets to Watch on Dec. 26, 2025 – ts2.tech

Micron Technology Hits Record Highs: Unpacking the Surge in HBM Demand and Key Analyst Targets for December 26, 2025

December 26, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version