Author Archives: Onsite Computing, Inc.

Patch Issued for Critical VMware vCenter Flaw Allowing Remote Code Execution

Broadcom on Tuesday released updates to address a critical security flaw impacting VMware vCenter Server that could pave the way for remote code execution. The vulnerability, tracked as CVE-2024-38812 (CVSS score: 9.8), has been described as a heap-overflow vulnerability in the DCE/RPC protocol. “A malicious actor with network access to vCenter Server may trigger this […]

Microsoft fixes Authenticator design flaw after eight years overwriting accounts

Having ignored user complaints about a security design flaw within Microsoft Authenticator for eight years, Microsoft confirmed in an email to CSO on Tuesday that it has finally corrected the issue. CSO Online reported details about the flaw last month. At issue was an oversight seemingly unique to Microsoft’s approach to introducing new accounts to […]

Warning to ServiceNow admins: Block publicly available KB articles

Many organizations using ServiceNow are inadvertently exposing sensitive personal and corporate data through misconfigured Knowledge Base (KB) articles created by employees, says a security provider. ServiceNow is a cloud-based platform for automatic workflows. It’s often used by IT help desks for creating and tracking employee or customer tickets, and also by HR, security, finance, and […]

This site uses cookies to offer you a better browsing experience. By browsing this website, you agree to our use of cookies.