Cisco's Talos group has released critical security updates for ClamAV, a widely used open-source antivirus engine integrated into mail gateways and endpoint security tools. The patches address seven distinct vulnerabilities found in versions 1.5.3 and 1.4.5 of the software. Several of these flaws have existed within the codebase for nearly two decades, highlighting long-standing risks in legacy parsing logic. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
