A critical Roundcube vulnerability patched in May is being actively exploited by hackers in code injection attacks. The Canadian Centre for Cyber Security has confirmed the ongoing threat.
Roundcube Webmail users face immediate risk from a high-severity flaw that allows code injection attacks. Despite a patch released in May, threat actors are now actively leveraging the vulnerability to compromise systems.
The Canadian Centre for Cyber Security flagged the active exploitation, urging organizations to prioritize updates. Roundcube, a widely-used open-source webmail client, powers email access for numerous businesses and service providers.
Code injection vulnerabilities enable attackers to insert malicious code into applications, potentially granting them unauthorized access or control over affected systems. The flaw's active exploitation underscores the risk of delayed patching.
Administrators should apply the May patch immediately if not already done. Organizations using Roundcube should verify their systems are running the latest version and monitor for suspicious activity. The vulnerability represents a critical risk to email infrastructure security.
Researchers have discovered a method to break RSA encryption that doesn't rely on factoring, challenging decades of cryptographic assumptions and potentially undermining current security standards.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) alerted federal agencies that ransomware gangs are actively exploiting a critical JetBrains TeamCity vulnerability that was patched in July.
A Senate Judiciary Subcommittee criticized automatic license plate reader technology Wednesday, with particular concerns raised about Flock Safety. The company's CEO and others declined to attend the hearing.