vulnerabilities

Microsoft patches perfect-10 Entra ID flaw exploited in wild

Microsoft disclosed on Thursday a maximum-severity vulnerability in its Entra ID cloud identity service that attackers had already been exploiting, though the company says it has fully mitigated the flaw server-side and no customer action is required.

Critical Fastjson flaw actively exploited with no patch

A critical remote code execution vulnerability in Alibaba's Fastjson library is under active exploitation, with no fix available for the affected 1.x branch and attackers already hitting production systems across the United States.

Two 15-year-old Linux kernel flaws prompt urgent patching

Two high-severity vulnerabilities that together lay dormant in the Linux kernel for more than 15 years were publicly disclosed this week, prompting urgent patching across major distributions and cloud providers. Both were demonstrated through Google Alphabet Inc. bug bounty programs…