Alerts

Fortinet Security Updates – 13 March 2024

Fortinet has released security updates to fix several vulnerabilities across multiple Fortinet products. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, gain elevated privileges, manipulate data, view, add, modify, or delete information in the back-end database, execute arbitrary code, and gain access to the affected products by sending specially crafted HTTP […]

Fortinet Security Updates – 13 March 2024 Read More »

Apple Security Updates – 10 March 2024

Apple has released security updates to address several vulnerabilities across Safari, macOS Ventura, macOS Monterey, and macOS Sonoma. The addressed vulnerabilities could allow the attacker to bypass security restrictions, obtain sensitive information, perform denial of service attacks, gain elevated privileges, or execute arbitrary code and gain access to the affected systems. Sample of the addressed

Apple Security Updates – 10 March 2024 Read More »

Microsoft Edge Security Update – 10 March 2024

Microsoft has released an updated Microsoft Edge version 122.0.2365.80 to address multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, or execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted Web site. Sample of the addressed vulnerabilities: 1. Microsoft Edge

Microsoft Edge Security Update – 10 March 2024 Read More »

Cisco Security Updates – 07 March 2024

Cisco has released security updates to fix several vulnerabilities across multiple Cisco products. The addressed vulnerabilities could allow the attacker to obtain sensitive information, conduct cross-site scripting attacks, gain elevated privileges, or execute arbitrary code, and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Cisco Secure Client Carriage Return Line Feed

Cisco Security Updates – 07 March 2024 Read More »

Aruba Security Update – 06 March 2024

Aruba has released a security update to fix multiple vulnerabilities affecting HPE Aruba OS. The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, perform denial of service attacks, or execute arbitrary commands and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Authenticated Remote Command Execution in the ArubaOS

Aruba Security Update – 06 March 2024 Read More »

VMware Security Updates – 06 March 2024

VMware has released security updates to address several vulnerabilities across multiple VMware products. The addressed vulnerabilities could allow the attacker to obtain sensitive information, or execute arbitrary code and gain access to the affected products. Sample of the addressed vulnerabilities: 1. VMware Workstation/Fusion Use-after-free Vulnerability in XHCI USBController (CVE-2024-22252): CVSS: 9.3 Attack Vector: Local Attack

VMware Security Updates – 06 March 2024 Read More »

SolarWinds Security Update – 05 March 2024

SolarWinds has released a security update to address a vulnerability affectingSolarWinds SEM 2023.4 and prior ersions. The addressed vulnerability could allow the attacker to execute arbitrary code and gain access to the affected system. SolarWinds Security Event Manager Remote Code Execution Vulnerability (CVE-2024-0692): CVSS: 8.8 Attack Vector: Adjacent Network Attack Complexity: Low Privileges Required: None

SolarWinds Security Update – 05 March 2024 Read More »

Aruba Security Update – 04 March 2024

Aruba has released a security update to fix multiple vulnerabilities affecting HPE Aruba ClearPass Policy Manager. The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, perform cross-site scripting, or execute arbitrary commands and gain access to the affected product. Sample of the addressed vulnerabilities: 1. HPE Aruba ClearPass Policy Manager Command Execution

Aruba Security Update – 04 March 2024 Read More »

Microsoft Edge Security Update – 03 March 2024

Microsoft has released an updated Microsoft Edge version 122.0.2365.63 to address multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: Microsoft Edge (Chromium-based) Code Execution (CVE-2024-1938): CVSS: 8.8

Microsoft Edge Security Update – 03 March 2024 Read More »

Google Chrome Security Update – 29 February 2024

Google has released an updated Chrome version 122.0.6261.94/.95 for Windows and 122.0.6261.94 for Mac and Linux to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: Google

Google Chrome Security Update – 29 February 2024 Read More »

Microsoft Edge Security Update – 27 February 2024

Microsoft has released an updated Microsoft Edge Stable Channel (122.0.2365.52) to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, bypass security restrictions, or execute arbitrary code and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Microsoft Edge (Chromium-based) Code Execution (CVE-2024-1669): CVSS: 8.8 Attack

Microsoft Edge Security Update – 27 February 2024 Read More »

Linux Security Updates – 25 February 2024

Linux has released security updates to address several vulnerabilities in Linux Kernel. The addressed vulnerabilities could allow the attacker to gain elevated privileges, perform denial of service attacks, obtain sensitive information, or execute arbitrary code and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Linux Kernel Information Disclosure Vulnerability (CVE-2024-26594): CVSS:

Linux Security Updates – 25 February 2024 Read More »

Atlassian Security Updates – 21 February 2024

Atlassian has released security updates to address several vulnerabilities across multiple Atlassian products. The addressed vulnerabilities could allow the attacker to obtain sensitive information, trigger cross-site scripting attacks, perform denial of services attacks, or execute arbitrary code and gain access to the affected product. Sample of the addressed vulnerabilities: 1. Atlassian Confluence Data Center and

Atlassian Security Updates – 21 February 2024 Read More »

Google Chrome Security Update – 21 February 2024

Google has released an updated Chrome version 122.0.6261.57/.58 for Windows and 122.0.6261.57 for Mac and Linux. The addressed vulnerabilities could allow the remote attacker to bypass securityrestrictions, or execute arbitrary code and gain access to the affected system by pesuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: 1. Google

Google Chrome Security Update – 21 February 2024 Read More »

Mozilla FireFox Security Update – 21 February 2024

Mozilla has released an updated Firefox version 123, and Firefox ESR version 115.8 to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to conduct spoofing attacks, cause DNS cache poisoning, perform denial of service attacks, bypass security restrictions, or execute arbitrary code, and gain access to the affected systems by persuading the

Mozilla FireFox Security Update – 21 February 2024 Read More »

ConnectWise Security Updates – 21 February 2024

ConnectWise has released security updates to fix multiple vulnerabilities across ConnectWise ScreenConnect 23.9.7 and prior. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions and obtain administrative access, or traverse directories and obtain sensitive information by sending a specially crafted URL request containing “dot dot” sequences (/../) to view arbitrary files on

ConnectWise Security Updates – 21 February 2024 Read More »

VMware Security Updates – 21 February 2024

VMware has released security updates to address several vulnerabilities in multiple VMware products. The addressed vulnerabilities could allow the attacker to bypass security restrictions to request and relay service tickets for arbitrary Active Directory Service Principal Names (SPNs), or hijack the user’s session cookie to hijack a privileged EAP session, or gain elevated privileges to

VMware Security Updates – 21 February 2024 Read More »