We’re aware of a critical vulnerability in Apache Struts 2, which is an open-source model-view-controller (MVC) framework for creating Java web applications. This is an 'Unrestricted Upload of File with Dangerous Type' vulnerability (CVSSv4 score of 9.5) that exists...
Encrypted Client Hello’s impact on Web Filtering
Encrypted Client Hello (or ECH for short) is a privacy encryption method that’s been enabled on some websites globally by third parties, which includes a very small percentage of websites used by schools. If a website has ECH enabled, it makes it difficult for N4L’s...
Remote code execution affecting IPv6 in Windows products (CVE-2024-38063, Severity – CRITICAL)
N4L is aware that Windows 10, Windows 11 and Windows servers are currently being impacted by a critical vulnerability. This vulnerability affects IPv6 and devices which have IPv6 enabled on them.The vulnerability could allow an unauthenticated malicious actor to send...
Advisory: XZ Utils vulnerability (CVE-2024-3094)
We’re aware of a critical vulnerability impacting XZ Utils, where malicious code was inserted into a library that could allow for remote code execution via Secure Shell Protocol (SSH). XZ is a general-purpose data compression format present in nearly every Linux...