Alerts

Microsoft December 2024 Patch Tuesday

 Microsoft has released its monthly patch of security updates, known as Patch Tuesday. The mentioned patch addressed one zero-day vulnerability. Microsoft has fixed (72) vulnerabilities, with (1) classified as critical as they could allow the attacker to conduct spoofing attacks, gain elevated privileges, perform denial of service attacks, obtain sensitive information, or execute arbitrary code […]

Microsoft December 2024 Patch Tuesday Read More »

Ivanti Security Updates – 11 December 2024

Ivanti has released security updates to fix several vulnerabilities across multiple Ivanti products. The addressed vulnerabilities could allow the attacker to manipulate data, bypass security restrictions, perform denial of service attacks, or execute arbitrary code and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Ivanti CSA Administrative Access Vulnerability (CVE-2024-11639): CVSS:

Ivanti Security Updates – 11 December 2024 Read More »

SAP December 2024 Security Patch Day

SAP has released security updates to address several vulnerabilities affecting multiple SAP products. SAP has released a patch that fixes several vulnerabilities affecting multiple SAP products such as SAP NetWeaver AS for JAVA, SAP Web Dispatcher, SAP BusinessObjects Business Intelligence Platform, SAP NetWeaver Application Server (ABAP), SAP HCM, SAP Product Lifecycle Costing, SAP NetWeaver Administrator

SAP December 2024 Security Patch Day Read More »

SonicWall Security Updates – 05 December 2024

SonicWall has released security updates to fix multiple vulnerabilities across SonicWall SMA100 SSL-VPN versions 10.2.1.13-72sv and earlier. The addressed vulnerabilities could allow the attacker to bypass security restrictions, perform stack-based and heap-based buffer overflow, or execute arbitrary code, and gain access to the affected systems. Sample of the addressed vulnerabilities: 1- SonicWall SMA100 SSLVPN Web

SonicWall Security Updates – 05 December 2024 Read More »

SolarWinds Security Update – 05 December 2024

SolarWinds has released a security update to address a vulnerability affecting SolarWinds Platform 2024.4 and prior versions. The addressed vulnerability could allow the attacker to perform a cross-site scripting attack and affect the user interface’s search and node information section. SolarWinds Platform Cross Site Scripting Vulnerability (CVE-2024-45717): CVSS: 7.0 Attack Vector: Adjacent Attack Complexity: Low

SolarWinds Security Update – 05 December 2024 Read More »

Veeam Security Updates – 05 December 2024

 Veeam has released security updates to fix several vulnerabilities affecting multiple Veeam products. The addressed vulnerabilities could allow the attacker to perform denial of service attacks, gain elevated privileges, conduct DLL injection attacks, obtain sensitive information, manipulate data or execute arbitrary code, and gain access to the affected systems. Sample of the addressed vulnerabilities: 1.

Veeam Security Updates – 05 December 2024 Read More »

Google Chrome Security Update – 04 December 2024

Google has released an updated Chrome version “131.0.6778.108/.109” for Windows and Mac and “131.0.6778.108” for Linux. The addressed vulnerability could allow the remote attacker to execute arbitrary code to gain access to the affected system by persuading the victim to visit a specially crafted website. Google Chrome Code Execution Vulnerability (CVE-2024-12053): CVSS: 8.8 Attack Vector:

Google Chrome Security Update – 04 December 2024 Read More »

Trellix Security Update – 01 December 2024

Trellix has released a security update to fix several vulnerabilities in Trellix Enterprise Security Manager (ESM) version 11.6.13. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, execute arbitrary code, and gain access to the affected system. The addressed vulnerabilities: 1. Trellix Enterprise Security Manager Code Execution Vulnerability (CVE-2024-11482): CVSS: 9.8 Attack

Trellix Security Update – 01 December 2024 Read More »

Mozilla FireFox Security Updates – 28 November 2024

Mozilla has released an updated Firefox version 133, Firefox ESR versions 128.5, and 115.18 to fix multiple vulnerabilities.  The addressed vulnerabilities could allow the remote attacker to perform denial of service attacks, conduct cross-site scripting attacks, obtain sensitive information, perform spoofing attacks, bypass security restrictions or execute arbitrary code and gain access to the affected

Mozilla FireFox Security Updates – 28 November 2024 Read More »

Palo Alto Security Update – 27 November 2024

Palo Alto has released security update to fix a vulnerability affecting Palo Alto GlobalProtect App. The addressed vulnerability could allow the attacker to gain elevated privileges to the affected product. GlobalProtect App Insufficient Certificate Validation Privilege Escalation Vulnerability (CVE-2024-5921): CVSS v4.0: 5.6 Attack Vector: Adjacent Attack Complexity: Low Privileges Required: None User Interaction: Passive Consequences:

Palo Alto Security Update – 27 November 2024 Read More »

VMware Security Updates – 26 November 2024

VMware has released security updatesto address multiple vulnerabilities affecting VMware Cloud Foundation and VMware Aria Operations. The addressed vulnerabilities could allow the attacker to gain elevated privileges or conduct stored cross-site scripting attacks on the affected system. Sample of the addressed vulnerabilities: 1. VMware Privilege Escalation Vulnerability (CVE-2024-38830): CVSS: 7.8 Attack Vector: Local Attack Complexity:

VMware Security Updates – 26 November 2024 Read More »

Trend Micro Security Updates – 25 November 2024

Trend Micro has released security updates to address several vulnerabilities affecting Trend Micro Deep Security and Trend Micro Deep Discovery Inspector. The addressed vulnerabilities could allow the attacker to obtain sensitive information or execute arbitrary code and gain elevated privilegesto the affected product. Sample of the addressed vulnerabilities: 1. Trend Micro Deep Security Agent Manual

Trend Micro Security Updates – 25 November 2024 Read More »

Apple Security Updates – 20 November 2024

Apple has released security updates to address two vulnerabilities affecting macOS Sequoia and Safari. The addressed vulnerabilities could allow the attacker to perform cross-site scripting attacks or execute arbitrary code and gain access to the affected systems. The addressed vulnerabilities: 1. Apple macOS Sequoia Code Execution Vulnerability (CVE-2024-44308): CVSS: 8.8 Attack Vector: Network Attack Complexity:

Apple Security Updates – 20 November 2024 Read More »

Atlassian Security Updates – 20 November 2024

Atlassian has released security updates to fix several vulnerabilities across multiple Atlassian products. The addressed vulnerabilities could allow the attacker to perform denial of service attacks, conduct cross-site scripting attacks, obtain sensitive information, or execute arbitrary code and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. SourceTree Remote Code Execution Vulnerability

Atlassian Security Updates – 20 November 2024 Read More »

Google Chrome Security Update – 20 November 2024

 Google has released an updated Chrome version 131.0.6778.85/.86 for Windows, and Mac and 131.0.6778.85 for Linux The addressed vulnerability could allow the remote attacker to gain access to the affected system, which could be caused by potentially exploiting heap corruption via a crafted HTML page. Google Chrome Heap Exploitation Vulnerability (CVE-2024-11395): CVSS: 8.8 Attack Vector:

Google Chrome Security Update – 20 November 2024 Read More »

Palo Alto Security Updates – 19 November 2024

Palo Alto has released security updatesto fix multiple vulnerabilities affecting Palo Alto PAN-OS. The addressed vulnerabilities could allow the attacker to gain elevated privileges, perform denial of service attacks, conduct SSRF attacks, obtain sensitive information, bypass security restrictions or gain access to the affected system. Sample of the addressed vulnerabilities: 1. PAN-OS Authentication Bypass in

Palo Alto Security Updates – 19 November 2024 Read More »

Aruba Security Updates – 17 November 2024

 Aruba has released security updates to fix multiple vulnerabilities affecting Aruba HPE StoreEasy, SGI CXFS, and Cray System Management Software. The addressed vulnerabilities could allow the attacker to perform denial of service attacks, or gain elevated privileges and gain unauthorized access to files on the affected products. Sample of the addressed vulnerabilities: HPE Data Management

Aruba Security Updates – 17 November 2024 Read More »

Microsoft Edge Security Update – 17 November 2024

Microsoft has released an updated version of Microsoft Edge (131.0.2903.48) to address multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, bypass security restrictions, or execute arbitrary code and gain access to the affected system, by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities:

Microsoft Edge Security Update – 17 November 2024 Read More »

Fortinet Security Update – 13 November 2024

Fortinet has released security updates to fix multiple vulnerabilities across several Fortinet products. The addressed vulnerabilities could allow the attacker to bypass security restrictions, gain elevated privileges, obtain sensitive information, or execute arbitrary code and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Fortinet FortiClient Windows Privilege Escalation Vulnerability (CVE-2024- 36513):

Fortinet Security Update – 13 November 2024 Read More »