Alerts

VMware Security Update – 05 March 2025

VMware has released a security update to fix several vulnerabilities across VMware ESXi, Workstation, and Fusion. The addressed vulnerabilities could allow the attacker to obtain sensitive information, escalate privileges, or execute arbitrary code, and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. VMware ESXi, and Workstation Heap-Overflow Vulnerability (CVE-2025- 22224): CVSS: […]

VMware Security Update – 05 March 2025 Read More »

Cisco Security Updates – 27 February 2025

Cisco has released security updates to fix several vulnerabilities affecting multiple Cisco products. The addressed vulnerabilities could allow the attacker to conduct cross-site scripting attacks, obtain sensitive information, perform denial of services attacks, bypass security restrictions, or execute arbitrary commands and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Cisco Nexus

Cisco Security Updates – 27 February 2025 Read More »

Microsoft Edge Security Update – 24 February 2025

Microsoft has released an updated Microsoft Edge stable channel (133.0.3065.82) to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to perform a denial of service attack or exploit heap corruption via a crafted HTML page and gain access to the affected system. Sample of the addressed vulnerabilities: Microsoft Edge (Chromium-based) Heap Buffer

Microsoft Edge Security Update – 24 February 2025 Read More »

OpenSSH Security Update – 23 February 2025

OpenSSH released a security update to fix multiple vulnerabilities affecting OpenSSH version 9.9p1 and prior. The addressed vulnerabilities could allow the remote attacker to perform denial-of-service attacks or conduct man-in-the-middle attacks and obtain sensitive information from the affected systems. 1. OpenSSH Information Disclosure Vulnerability (CVE-2025-26465): CVSS: 6.8 Attack Vector: Network Attack Complexity: High Privileges Required:

OpenSSH Security Update – 23 February 2025 Read More »

Citrix Security Updates – 19 February 2025

Citrix has released security updates to address multiple vulnerabilities across several products. The addressed vulnerabilities could allow the attacker to gain elevated privileges on the affected systems. Sample of the addressed vulnerabilities: 1. NetScaler Authenticated Privilege Escalation Vulnerability (CVE-2024-12284): CVSS: 8.8 Attack Vector: Adjacent Network Attack Complexity: High Privileges Required: High User Interaction: None Consequences:

Citrix Security Updates – 19 February 2025 Read More »

Microsoft Edge Security Update – 16 February 2025

Microsoft has released an updated Microsoft Edge stable channel “133.0.3065.69” to fix multiple vulnerabilities. The addressed vulnerabilities could allow the attacker to bypass security restrictions or execute arbitrary code and gain access to the affected systems by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: 1. Microsoft Edge (Chromium-based)

Microsoft Edge Security Update – 16 February 2025 Read More »

Google Chrome Security Update – 13 February 2025

Google has released an updated Chrome version “133.0.6943.98/.99” for Windows and Mac and “133.0.6943.98” for Linux. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions or execute arbitrary code and gain access to the affected systems by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: 1.

Google Chrome Security Update – 13 February 2025 Read More »

Palo Alto Security Updates – 13 February 2025

Palo Alto has released security updatesto fix multiple vulnerabilities affecting Palo Alto PAN-OS and Palo Alto Cortex XDR. The addressed vulnerabilities could allow the attacker to bypass security restrictions, manipulate data, obtain sensitive information, execute arbitrary commands/codes, and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. PAN-OS Authentication Bypass in the

Palo Alto Security Updates – 13 February 2025 Read More »

Intel Security Updates – 12 February 2025

Intel has released security updates to address several vulnerabilities affecting multiple Intel products. The addressed vulnerabilities could allow the attacker to gain elevated privileges, perform denial-of-service attacks, or obtain sensitive information and gain access to the affected systems. Samples of the addressed vulnerabilities: 1. Intel Graphics Software Improper Access Control Vulnerability (CVE-2024- 37355): CVSS: 8.8

Intel Security Updates – 12 February 2025 Read More »

Ivanti Security Updates – 12 February 2025

Ivanti has released security updates to fix several critical vulnerabilities across multiple Ivanti products. The addressed vulnerabilities could allow the attacker to conduct cross-site scripting attacks, obtain sensitive information, bypass security restrictions, or execute arbitrary code and gain access to the affected systems. Sample of the addressed vulnerabilities: Ivanti Connect Secure (ICS) Code Execution Vulnerability

Ivanti Security Updates – 12 February 2025 Read More »

Progress LoadMaster Security Update – 12 February 2025

Progress has released a security update to address multiple vulnerabilities affecting Progress LoadMaster.  The addressed vulnerabilities could allow the attacker to obtain sensitive information, or execute arbitrary system commands and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Progress LoadMaster Command Execution Vulnerability (CVE-2024-56131): CVSS: 8.4 Attack Vector: Adjacent Attack Complexity:

Progress LoadMaster Security Update – 12 February 2025 Read More »

Adobe Security Updates – 12 February 2025

Adobe has released security updates to fix several vulnerabilities across multiple Adobe Commerce products. The addressed vulnerabilities could allow the attacker to bypass security restrictions, perform cross-site scripting attacks, gain elevated privileges, or execute arbitrary code and gain access to the affected systems Sample of the addressed vulnerabilities: 1. Adobe Commerce Improper Authorization (CWE-285) (CVE-2025-24434):

Adobe Security Updates – 12 February 2025 Read More »

Juniper Security Updates – 12 February 2025

Juniper has released security updatesto fix a critical vulnerability affectingmultiple Juniper Networks products. The addressed vulnerability could allow the remote attacker to bypass authentication and take administrative control of the affected systems. Juniper Networks API Authentication Bypass Vulnerability (CVE-2025-21589): CVSS: 9.8 Attack Vector: Network Attack Complexity: Low Privileges Required: None User Interaction: None Consequences: Gain

Juniper Security Updates – 12 February 2025 Read More »

Microsoft February 2025 Patch Tuesday

Microsoft has released its monthly patch of security updates, known as Patch Tuesday. The mentioned patch addressed four zero-day vulnerabilities. Microsoft has fixed (68) vulnerabilities, with (1) classified as critical as they could allow the attacker to gain elevated privileges, perform denial of service attacks, obtain sensitive information, conduct spoofing attacks, bypass security restrictions, or

Microsoft February 2025 Patch Tuesday Read More »

Fortinet Security Updates – 12 February 2025

Fortinet has released security updates to fix several vulnerabilities across multiple Fortinet products. The addressed vulnerabilities could allow the attacker to gain elevated privileges, obtain sensitive information, bypass security restrictions, conduct cross-site scripting attacks, or execute arbitrary codes/commands and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. FortiOS And FortiProxy Security

Fortinet Security Updates – 12 February 2025 Read More »

SAP February 2025 Security Patch Day

SAP has released security updates to address several vulnerabilities affecting multiple SAP products. SAP has released a patch that fixes several vulnerabilities affecting multiple SAP products such as SAP NetWeaver, SAP BusinessObjects Business Intelligence platform, SAP Supplier Relationship Management, SAP Approuter, SAP Enterprise Project Connection, SAP HANA, SAP Commerce and SAP Commerce Cloud, SAP GUI

SAP February 2025 Security Patch Day Read More »

Rsync Security Updates – 09 February 2025

Rsync has released security updatesto fix several vulnerabilities affecting all Rsync versions up to and including version 3.4.0. The addressed vulnerabilities could allow the attacker to obtain sensitive information, bypass security restrictions, gain elevated privileges, manipulate data, or execute arbitrary code and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Rsync

Rsync Security Updates – 09 February 2025 Read More »

Microsoft Edge Security Update – 09 February 2025

Microsoft Edge has released an updated Microsoft Edge version “133.0.3065.51” to address multiple vulnerabilities. The addressed vulnerabilities could allow the attacker to bypass security restrictions, perform spoofing attacks, or execute arbitrary codes and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Microsoft Edge Code Execution Vulnerability (CVE-2025-21342): CVSS: 8.8 Attack Vector:

Microsoft Edge Security Update – 09 February 2025 Read More »

Cisco Security Updates – 06 February 2025

Cisco has released security updates to fix multiple vulnerabilities affecting several Cisco products. The addressed vulnerabilities could allow the attacker to bypass security restrictions, perform cross-site scripting attacks, obtain sensitive information, conduct denial of services attacks, execute arbitrary commands, and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Cisco Identity Services

Cisco Security Updates – 06 February 2025 Read More »