Alerts

Aruba Security Updates – 09 January 2025

Aruba has released security updates to fix multiple vulnerabilities affecting Aruba Networking 501 Wireless Client and Aruba CX 10000 Switch Series. The addressed vulnerabilities could allow the attacker to bypass security restrictions or execute arbitrary commands and gain access to the affected products. Sample of the addressed vulnerabilities: HPE Aruba Networking 501 Wireless Client Bridge […]

Aruba Security Updates – 09 January 2025 Read More »

Juniper Security Updates – 09 January 2025

Juniper has released security updates to fix several vulnerabilities affecting multiple Juniper Networks products. The addressed vulnerabilities could allow the attacker to obtain sensitive information or perform denial of service attacks to the affected products. Sample of the addressed vulnerabilities: 1. Juniper Networks Junos OS and Junos OS Evolved Denial of Service Vulnerability (CVE-2025-21599): CVSS:

Juniper Security Updates – 09 January 2025 Read More »

Mozilla FireFox Security Updates – 09 January 2025

Mozilla has released an updated Firefox version 134, Firefox ESR versions 128.6, and 115.19 to fix multiple vulnerabilities. The addressed vulnerabilities could allow the attacker to perform spoofing attacks, gain elevated privileges, bypass security restrictions or execute arbitrary code and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Mozilla Firefox Memory

Mozilla FireFox Security Updates – 09 January 2025 Read More »

Ivanti Security Updates – 09 January 2025

Ivanti has released security updates to fix two vulnerabilities across multiple versions of Ivanti Connect Secure, Policy Secure, and ZTA Gateways. The addressed vulnerabilities could allow the attacker to gain elevated privileges or execute arbitrary code and gain access to the affected system. The addressed vulnerabilities: 1. Ivanti Connect Secure Remote Code Execution (CVE-2025-0282): CVSS:

Ivanti Security Updates – 09 January 2025 Read More »

Google Chrome Security Update – 08 January 2025

Google has released an updated Chrome version “131.0.6778.264/.265” for Windows and Mac and “131.0.6778.264” for Linux. The addressed vulnerability could allow the remote attacker to execute arbitrary code to gain access to the affected system by persuading the victim to visit a specially crafted website. Google Chrome Code Execution Vulnerability (CVE-2025-0291): CVSS: 8.8 Attack Vector:

Google Chrome Security Update – 08 January 2025 Read More »

SonicWall Security Updates – 08 January 2025

SonicWall has released security updates to fix multiple vulnerabilities affecting SonicOS and SonicWALL SSL-VPN. The addressed vulnerabilities could allow the attacker to perform denial of service attacks, obtain sensitive information, gain elevated privileges, conduct server-side request forgery attacks, or execute arbitrary code and gain access to the affected systems. Sample of the addressed vulnerabilities: 1.

SonicWall Security Updates – 08 January 2025 Read More »

Apache Tomcat Security Updates – 24 December 2024

Apache has released security updates to address a vulnerability affecting multiple versions of Apache Tomcat. The addressed vulnerability could allow the remote attacker to execute arbitrary code, bypass intended file system access controls, and gain access to the affected systems. Apache Tomcat Code Execution Vulnerability (CVE-2024-56337): CVSS: 8.1 Attack Vector: Network Attack Complexity: High Privileges

Apache Tomcat Security Updates – 24 December 2024 Read More »

Sophos Security Update – 22 December 2024

Sophos has released security updates to fix multiple vulnerabilities in Sophos firewall versions 21.0 GA (21.0.0) and older. The severity of the addressed vulnerability could allow the remote attacker to execute remote code and gain access to the affected versions. 1. Sophos firewall pre-auth SQL injection vulnerability (CVE-2024-12727): CVSS: 9.8 Attack Vector: Network Attack Complexity:

Sophos Security Update – 22 December 2024 Read More »

Apache Tomcat Security Updates – 19 December 2024

Apache has released security updates to address two vulnerabilities affecting multiple versions of Apache Tomcat. The addressed vulnerabilities could allow the remote attacker to perform denial of service attacks or execute arbitrary code, and gain access to the affected systems. The addressed vulnerabilities: 1. Apache Tomcat Code Execution Vulnerability (CVE-2024-50379): CVSS: 9.8 Attack Vector: Network

Apache Tomcat Security Updates – 19 December 2024 Read More »

Fortinet Security Updates – 19 December 2024

Fortinet has released security updates to fix multiple vulnerabilities across several Fortinet products. The addressed vulnerabilities could allow the attacker to obtain sensitive information or execute arbitrary command/code and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. FortiWLM Remote Command/Code Execution Vulnerability (CVE-2023- 34990): CVSS: 9.6 Attack Vector: Network Attack Complexity:

Fortinet Security Updates – 19 December 2024 Read More »

Google Chrome Security Update – 19 December 2024

Google has released an updated Chrome version “131.0.6778.204/.205” for Windows and Mac and “131.0.6778.204” for Linux. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: Google Chrome Code Execution Vulnerability

Google Chrome Security Update – 19 December 2024 Read More »

Apple Security Updates – 15 December 2024

 Apple has released security updates to address multiple vulnerabilities across macOS Ventura, macOS Sequoia, macOS Sonoma, and Safari. The addressed vulnerabilities could allow the attacker to bypass security restrictions, obtain sensitive information, perform denial of services attacks, elevate privileges, or execute arbitrary code and gain access to the affected systems. Sample of the addressed vulnerabilities:

Apple Security Updates – 15 December 2024 Read More »

Splunk Security Updates – 11 December 2024

Splunk has released security updates to fix multiple vulnerabilities affecting several Splunk products. The addressed vulnerabilities could allow the attacker to bypass security restrictions, obtain sensitive information, or execute arbitrary code and gain access to the affected systems. Sample of the addressed vulnerabilities: Splunk Secure Gateway App Remote Code Execution Vulnerability (CVE-2024- 53247): CVSS: 8.8

Splunk Security Updates – 11 December 2024 Read More »

Google Chrome Security Update – 11 December 2024

Google has released an updated Chrome version “131.0.6778.139/.140” for Windows and Mac and “131.0.6778.139” for Linux. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code to gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: Google Chrome Code Execution Vulnerability

Google Chrome Security Update – 11 December 2024 Read More »

Aruba Security Updates – 11 December 2024

Aruba has released security updatesto fix multiple vulnerabilities affecting several Aruba products. The addressed vulnerabilities could allow the remote attacker to conduct cross-site scripting attacks or denial of service attacks or execute arbitrary commands/codes and gain access to the affected systems. Sample of the addressed vulnerabilities: HPE Aruba Networking ClearPass Authenticated Remote Code Execution Vulnerability

Aruba Security Updates – 11 December 2024 Read More »

Adobe Security Updates – 11 December 2024

Adobe has released security updates to fix several vulnerabilities across Adobe Acrobat and Reader, Adobe Experience Manager (AEM), and Adobe Illustrator.  The addressed vulnerabilities could allow the attacker to bypass security restrictions, perform denial of service attacks, or execute arbitrary code and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Adobe

Adobe Security Updates – 11 December 2024 Read More »

Intel Security Updates – 11 December 2024

Intel has released security updates to address several vulnerabilities affecting multiple Intel products.  The addressed vulnerabilities could allow the attacker to gain elevated privileges, obtain sensitive information, or perform denial-of-service attacks on the affected systems. Samples of the addressed vulnerabilities: 1. Improper Access Control in the Intel® NUC Software Studio Service Software Vulnerability (CVE-2024-23498): CVSS:

Intel Security Updates – 11 December 2024 Read More »