Hewlett-Packard Enterprise (HPE) has issued a critical security bulletin addressing multiple high-severity vulnerabilities discovered in its StoreOnce backup software. These flaws, which impact versions earlier than 4.3.11, pose serious threats such as remote code execution, authentication bypass, server-side request forgery (SSRF), and unauthorized file deletion. The most severe vulnerability, tracked as CVE-2025-37093, allows attackers to bypass authentication and gain full system access without any credentials or user interaction. With a CVSS score of 9.8, it is categorized as critical and presents a significant risk to enterprise data security. These vulnerabilities stem from weaknesses in input validation and access control mechanisms within the StoreOnce Software. In particular, the improper implementation of the machineAccountCheck method enables attackers to gain elevated privileges remotely. Other flaws allow attackers to exploit the system through directory traversal, leading to potential data leaks or file deletions. Given the nature of these attack vectors—most requiring no user interaction and being exploitable over the network—the vulnerabilities significantly undermine the confidentiality, integrity, and availability of the affected systems, especially in enterprise environments relying on StoreOnce for secure backup and recovery. HPE strongly advises all users to upgrade to version 4.3.11 or later, as this release contains patches for all identified issues. Immediate patching is essential since no workarounds exist. Security teams should also take additional precautions, such as isolating vulnerable systems from untrusted networks, enabling network segmentation, and closely monitoring for any suspicious activity. Regular reviews of system security protocols can further help in maintaining resilience against future threats.
A recent cyber campaign has been observed targeting procurement and sales professionals through RFQ (Request for Quotation) themed phishing emails. Attackers impersonate legitimate...
Apple has expanded the release of iOS 18.7.7 and iPadOS 18.7.7 to protect users from a serious web-based threat known as the DarkSword exploit. Although initial fixes for this expl...
A major cybersecurity breach has exposed sensitive military-related data after attackers compromised PSK Wind Technologies, a defense contractor supporting the Israel Defense Force...