Tag

Denial Of Service

All articles tagged with #denial of service

cyber-security-news22 hours ago

Unauthenticated PAN-OS DoS Flaw Forces Quick GlobalProtect Patch

Palo Alto Networks patched a critical PAN-OS vulnerability (CVE-2026-0227) that lets unauthenticated attackers trigger a denial-of-service on GlobalProtect gateways/portals. The flaw, rated CVSS 7.7 (HIGH), stems from improper handling of unusual conditions and affects multiple PAN-OS versions (Cloud NGFW is spared). A PoC exists, exploitation is not yet observed, and no workarounds are available. Administrators should upgrade to the latest hotfixes (PAN-OS 12.1.4 or 11.2.10-h2) and verify configurations via Palo Alto’s support portal while monitoring for DoS attempts.

cybersecurity1 year ago

French Government Targeted by Unprecedented Cyberattacks

The French government has reported facing "unprecedented intensity" cyberattacks targeting several of its services, with a group of hackers called Anonymous Sudan claiming responsibility. The attacks, which started Sunday night, were said to have hit multiple government ministries, but the impact has since been reduced for most services. The government has accused Russia of operating a long-running online manipulation campaign and has been working to improve cyber defenses ahead of the Paris Olympics.

cybersecurity1 year ago

"KeyTrap DNS Attack Disrupts Internet Access with Single Packet"

A serious vulnerability named KeyTrap in the DNSSEC feature of the Domain Name System (DNS) could be exploited to cause long-lasting denial-of-service (DoS) conditions in vulnerable resolvers by sending a single DNS packet, potentially disrupting internet access for applications. The flaw, present for over two decades, was discovered by researchers and impacts widely used DNS implementations. Mitigations have been developed by companies like Akamai, Google, and Cloudflare to address the issue, but addressing the problem at a fundamental level may require a reevaluation of the DNSSEC design philosophy.

cybersecurity1 year ago

"Pennsylvania Courts' Website Suffers Cyberattack, Causes Crashes and Downtime"

The Pennsylvania Courts' website is currently experiencing a denial of service cyberattack, rendering certain web services unavailable. Officials have stated that there is no evidence of court data being accessed, and all courts remain open. Alternative methods for filing and making payments are being provided, and individuals seeking court documents and information are advised to contact the Pennsylvania Courts spokesperson for assistance.

technology2 years ago

"Microsoft Uncovers Critical RCE Vulnerability in Helix Core Server, Posing System Control Risk"

Microsoft has discovered four vulnerabilities, including one critical flaw, in the widely used Perforce Helix Core Server, a source code management platform. The vulnerabilities mainly involve denial of service issues, with the most severe allowing unauthenticated attackers to execute arbitrary code as LocalSystem. Microsoft has not observed any exploitation attempts in the wild but recommends users to upgrade to the latest version to mitigate the risk. The remaining vulnerabilities can cause operational disruption. Microsoft suggests regular software updates, access restriction, TLS certificates, logging, crash alerts, and network segmentation for protection.

hardware-security2 years ago

"Reptar CPU Vulnerability: Intel Patches High-Severity Flaw Impacting Multi-Tenant Virtualized Environments"

Intel has released fixes for a high-severity CPU vulnerability called Reptar, affecting desktop, mobile, and server CPUs. The flaw, tracked as CVE-2023-23583, could allow privilege escalation, information disclosure, and denial of service via local access. Exploiting the vulnerability in a multi-tenant virtualized environment could crash the host machine, causing a denial of service to other guest machines. Intel has published updated microcode for all affected processors, and there is no evidence of active attacks using this vulnerability.