Alerts

Veeam Security Update – 05 September 2024

Veeam has released a security update to fix several vulnerabilities across multiple Veeam products. The addressed vulnerabilities could allow the attacker to upload malicious files, obtain sensitive information, manipulate data and files, obtain credentials, gain elevated privileges, execute malicious commands, and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Veeam VSPC […]

Veeam Security Update – 05 September 2024 Read More »

Cisco Security Updates – 05 September 2024

Cisco has released security updates to fix several vulnerabilities affecting multiple Cisco products. The addressed vulnerabilities could allow the attacker to bypass security restrictions, obtain sensitive information, or gain elevated privileges to the affected product. Sample of the addressed vulnerabilities: 1. Cisco Smart Licensing Utility Static Credential Vulnerability (CVE-2024-20439): CVSS: 9.8 Attack Vector: Network Attack

Cisco Security Updates – 05 September 2024 Read More »

Mozilla FireFox Security Updates – 04 September 2024

Mozilla has released an updated Firefox version 130, Firefox ESR version 115.15, and 128.2 to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, conduct spoofing attacks, obtain sensitive information, execute arbitrary code, and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Mozilla Firefox Code

Mozilla FireFox Security Updates – 04 September 2024 Read More »

RansomHub Ransomware – 03 September 2024

RansomHub ransomware is a ransomware-as-a-service variant formerly known as Cyclops and Knight which emerged in 2017, encrypts files on victims’ systems, and demands payment for decryption. In February 2024 threat actors affiliated with the RansomHub ransomware group systematically encrypted and exfiltrated data from at least 210 victims across various sectors, including information technology, government services,

RansomHub Ransomware – 03 September 2024 Read More »

Google Chrome Security Update – 03 September 2024

Google has released an updated Chrome version “128.0.6613.119/.120” for Windows and Mac and “128.0.6613.119” for Linux. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: Google Chrome Code Execution Vulnerability

Google Chrome Security Update – 03 September 2024 Read More »

Progress WhatsUp Gold Security Update – 01 September 2024

Progress has released a security update to address several vulnerabilities affecting WhatsUp Gold versions before 2024.0.0. The addressed vulnerabilities could allow the remote attacker to perform SQL injection attacks on the affected system by sending specially crafted SQL statements. Sample of the addressed vulnerabilities: 1. Progress Software WhatsUp Gold SQL Injection (CVE-2024-6670): CVSS: 9.8 Attack

Progress WhatsUp Gold Security Update – 01 September 2024 Read More »

Fortra Security Updates – 29 August 2024

Fortra has released security updates to fix multiple vulnerabilities affecting Fortra FileCatalyst Workflow and Fortra GoAnywhere MFT. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, perform SQL injection attacks, or gain access to the affected system by utilizing the credentials stored in the HSQLDB. Sample of the addressed vulnerabilities: 1. Insecure

Fortra Security Updates – 29 August 2024 Read More »

Google Chrome Security Update – 29 August 2024

Google has released an updated Chrome version “128.0.6613.113/.114” for Windows and Mac, and “128.0.6613.113” for Linux. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code and gain access or cause a buffer overflow into the affected system by persuading the victim to visit a specially crafted Website. Sample of the addressed vulnerabilities:

Google Chrome Security Update – 29 August 2024 Read More »

Microsoft Edge Security Update – 25 August 2024

Microsoft has released an updated Microsoft Edge Stable Channel (Version 128.0.2739.42) to address multiple vulnerabilities. The addressed vulnerabilities could allow the attacker to gain elevated privileges, bypass security restrictions, execute buffer overflow attacks, or execute arbitrary code and gain access to the affected product. Sample of the addressed vulnerabilities: 1. Microsoft Edge (Chromium-based) Buffer Overflow

Microsoft Edge Security Update – 25 August 2024 Read More »

SonicWall Security Update – 25 August 2024

SonicWall has released a security update to fix a critical vulnerability across SonicWall SonicOS management access. The addressed vulnerability could allow the remote attacker to gain unauthorized access or in specific conditions cause the firewall to crash. SonicWall SonicOS Code Execution Vulnerability (CVE-2024-40766): CVSS: 9.3 Attack Vector: Network Attack Complexity: Low Privileges Required: None User

SonicWall Security Update – 25 August 2024 Read More »

SolarWinds Security Update – 25 August 2024

SolarWinds has released a security update to fix a vulnerability affecting SolarWinds Web Help Desk. The addressed vulnerability could allow the remote unauthenticated attacker to access internal functionality and modify data on the affected system. Web Help Desk Hardcoded Credential Vulnerability (CVE-2024-28987): CVSS: 9.1 Attack Vector: Network Attack Complexity: Low Privileges Required: None User Interaction:

SolarWinds Security Update – 25 August 2024 Read More »

Cisco Security Updates – 22 August 2024

Cisco has released security updates to fix several vulnerabilities affecting multiple Cisco products. The addressed vulnerabilities could allow the attacker to perform denial of service attacks, execute SQL injection attacks, obtain sensitive information, conduct cross-site scripting attacks, or execute arbitrary code and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Cisco

Cisco Security Updates – 22 August 2024 Read More »

Google Chrome Security Update – 22 August 2024

Google has released an updated Chrome version “128.0.6613.84/.85” for Windows and Mac, and version “128.0.6613.84” for Linux. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, or execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities:

Google Chrome Security Update – 22 August 2024 Read More »

Atlassian Security Updates – 22 August 2024

Atlassian has released security updates to fix several vulnerabilities across multiple Atlassian products. The addressed vulnerabilities could allow the remote attacker to perform denial of service attacks, conduct cross-site request forgery and server-side request forgery attacks, or execute arbitrary code and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Atlassian Crowd

Atlassian Security Updates – 22 August 2024 Read More »

Palo Alto Security Updates – 15 August 2024

Palo Alto has released security updates to fix multiple vulnerabilities across several Palo Alto products. The addressed vulnerabilities could allow the attacker to gain elevated privileges, conduct information disclosure, or execute arbitrary commands and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Palo Alto Cortex XSOAR Command Injection in CommonScripts Pack

Palo Alto Security Updates – 15 August 2024 Read More »

Intel Security Updates – 14 August 2024

Intel has released security updates to address several vulnerabilities across multiple Intel products. The addressed vulnerabilities could allow the attacker to gain elevated privileges, conduct an information disclosure, perform denial of service attacks, obtain sensitive information, and gain access to the affected systems. Samples of the addressed vulnerabilities: 1. Intel® Ethernet Complete Driver Pack Escalation

Intel Security Updates – 14 August 2024 Read More »

SolarWinds Security Updates – 14 August 2024

SolarWinds has released security updates to address a critical vulnerability affecting SolarWinds Web Help Desk 12.8.3 and all previous versions. The addressed vulnerability could allow the remote attacker to execute arbitrary code, run commands on the host machine, and gain access to the affected system. SolarWinds Web Help Desk Java Deserialization Remote Code Execution Vulnerability

SolarWinds Security Updates – 14 August 2024 Read More »

Adobe Security Updates – 14 August 2024

Adobe has released security updates to fix several vulnerabilities across Adobe Commerce, Acrobat, and Reader. The addressed vulnerabilities could allow the attacker to bypass security restrictions, escalate privileges, perform denial of services attacks, or execute arbitrary code and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Adobe Commerce Code Execution (CVE-2024-39397):

Adobe Security Updates – 14 August 2024 Read More »