Rapid7 finds a North Korea-linked toolkit hiding inside trojanized HAProxy builds at two South Korean firms.
Citrix fixed a CVSS 9.3 authentication bypass in NetScaler ADC and Gateway that attackers are expected to exploit quickly.
Attackers are exploiting a critical SharePoint authentication bypass days after Rapid7 shipped proof-of-concept code.
The argument injection flaw affects default Gogs installations with open registration enabled, allowing any registered user to access private repositories…