Traefik's request read timeout feature, enabled by default and documented as applying universally, has failed to protect HTTP/3 connections for at least four years across multiple releases. Bishop Fox discovered and measured this gap in timeout enforcement for HTTP/3 traffic against backend systems, leading the vendor to deploy a fix within twelve days of disclosure.
PaperCut has issued emergency patches to address chained vulnerabilities that threat actors exploited in attacks targeting the company's print management software. The attacks primarily focused on higher education customers during 2023, highlighting the risk posed by coordinated vulnerability exploitation in widely-deployed enterprise software.
Threat actors exploiting PaperCut zero-day vulnerabilities are installing legitimate remote access tools on compromised internet-facing Application Servers to maintain persistent access. PaperCut Software disclosed the ongoing campaign and advised customers running NG and MF print management solutions to immediately restrict web access to trusted IP addresses only. The covert deployment of these tools demonstrates attackers' intent to establish long-term footholds on affected infrastructure.
Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product. The post Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit appeared first on SecurityWeek.
ServiceNow has released patches addressing three critical code injection vulnerabilities that could allow attackers to execute arbitrary code on affected systems. Exploitation of these flaws could enable unauthorized access to sensitive data or allow attackers to modify information within ServiceNow instances.