Alerts

Paessler PRTG Security Update – 16 January 2024

Paessler has released a security update to fix a vulnerability in PRTG Network Monitor 23.4.90.1299 and earlier versions. The addressed vulnerability could allow the remote attacker to perform cross-site scripting attacks, inject arbitrary scripts, and bypass the authentication on the affected systems by persuading the PRTG user with an active session to visit a specially […]

Paessler PRTG Security Update – 16 January 2024 Read More »

VMware Security Update – 16 January 2024

VMware has released a security update to address a critical vulnerability across VMware Aria Automation (formerly vRealize Automation), and VMware Cloud Foundation (Aria Automation). The addressed vulnerability could allow the authenticated attacker to gain unauthorized access to remote organizations and workflows. VMware Aria Automation Missing Access Control Vulnerability (CVE-2023-34063): CVSS: 9.9 Attack Vector: Network Attack

VMware Security Update – 16 January 2024 Read More »

Atlassian Security Updates – 16 January 2024

Atlassian has released security updates to address several vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to bypass security restrictions, perform denial of service attacks, or execute arbitrary code and gain access to the affected system. Sample of the addressed vulnerabilities: Confluence Data Center and Server Remote Code Execution Vulnerability (CVE-2024-21674): CVSS:

Atlassian Security Updates – 16 January 2024 Read More »

Trend Micro Security Update – 14 January 2024

Trend Micro has released a security update to address several vulnerabilities across Trend Micro Apex Central. The addressed vulnerabilities could allow the remote attacker to trigger cross-site scripting attacks, obtain sensitive information, or execute arbitrary code and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Trend Micro Apex Central Server-Side Request

Trend Micro Security Update – 14 January 2024 Read More »

Juniper Security Updates – 11 January 2024

Juniper has released security updates to fix several vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to obtain sensitive information, cause a denial of service attack, bypass security restrictions, gain elevated privileges, or execute arbitrary code and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Juniper Junos OS

Juniper Security Updates – 11 January 2024 Read More »

Cisco Security Updates – 11 January 2024

Cisco has released security updates to fix several vulnerabilities in multiple Cisco products. The addressed vulnerabilities could allow the attacker to upload arbitrary files, gain elevated privileges to root, trigger cross-site scripting attacks, manipulate data by sending specially crafted SQL statements, or execute arbitrary commands and gain access to the affected products. Sample of the

Cisco Security Updates – 11 January 2024 Read More »

Ivanti Security Updates – 11 January 2024

Ivanti has released security updates to fix two zero-day vulnerabilities across Ivanti Connect Secure (ICS) and Ivanti Policy Secure. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, and bypass security restrictions on the affected systems by sending a specially crafted request. The addressed vulnerabilities: 1. Ivanti ICS and Ivanti Policy Secure

Ivanti Security Updates – 11 January 2024 Read More »

Google Chrome Security Update – 10 January 2024

Google has released an updated Chrome version 120.0.6099.216/217 for Windows and 120.0.6099.216 for Mac and Linux. The addressed vulnerability could allow the remote attacker to bypass security restrictions caused by insufficient data validation in Extensions of the affected system by persuading the victim to visit a specially crafted website. Google Chrome Security Bypass Vulnerability (CVE-2024-0333):

Google Chrome Security Update – 10 January 2024 Read More »

Intel Security Updates – 10 January 2024

Intel has released security updates to address several vulnerabilities in multiple Intel products The severity of the addressed vulnerabilities could allow the local authenticated attacker to gain elevated privileges or perform denial-of-service attacks on the affected products. Samples of the addressed vulnerabilities: 1. Intel NUC BIOS Firmware Privilege Escalation (CVE-2023-42429): CVSS: 7.5 Attack Vector: Local

Intel Security Updates – 10 January 2024 Read More »

Fortinet Security Updates – 10 January 2024

Fortinet has released security updates to fix multiple vulnerabilities across several products. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, escalate privilege, obtain sensitive information, perform denial of service attacks, or execute code and gain access to the affected products. Sample of the addressed vulnerabilities: FortiOS & FortiProxy Improper Authorization for

Fortinet Security Updates – 10 January 2024 Read More »

SAP January 2024 Security Patch Day

SAP has released security updates to address several vulnerabilities affecting multiple products. SAP has released a patch that fixes several vulnerabilities affecting multiple SAP products such as SAP Application Interface Framework, SAP S/4HANA Finance, SAP Web Dispatcher, SAP NetWeaver Application Server ABAP, and ABAP Platform. The attacker could exploit some of these vulnerabilities to bypass

SAP January 2024 Security Patch Day Read More »

ManageEngine Security Updates – 09 January 2024

ManageEngine has released security updates to address a critical vulnerability across multiple product builds till 127259. The addressed vulnerability could allow the remote authenticated attacker to traverse directories by sending a specially crafted URL request containing “dot dot” sequences (/../) to create arbitrary files on the affected systems. ManageEngine OpManager Directory Traversal Vulnerability (CVE-2023-47211): CVSS:

ManageEngine Security Updates – 09 January 2024 Read More »

Microsoft Edge Security Update – 08 January 2024

Microsoft has released an updated Microsoft Edge version 120.0.2210.121 to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: Microsoft Edge Code Execution Vulnerability (CVE-2024-0222): CVSS: 8.8

Microsoft Edge Security Update – 08 January 2024 Read More »

Google Chrome Security Update – 04 January 2024

Google has released an updated Chrome version 120.0.6099.199/200 for Windows, and 120.0.6099.199 for Mac and Linux to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: Google

Google Chrome Security Update – 04 January 2024 Read More »

Apache Security Updates – 27 December 2023

Apache has released security updates to address several vulnerabilities across multiple versions of Apache OFBiz. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, and gain access to the affected system by sending a specially crafted request. Sample of the addressed vulnerabilities: Apache Pre-authentication Remote Code Execution (CVE-2023-51467): CVSS: 9.8 Attack Vector:

Apache Security Updates – 27 December 2023 Read More »

Barracuda Security Update – 26 December 2023

Barracuda has released a security update to address two zero-day vulnerabilities across multiple versions of Email Security Gateway (ESG) appliances. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code within a third-party library “Spreadsheet::ParseExcel” on the affected system of Barracuda ESG Appliance by deploying a specially crafted Excel email attachment. Sample of

Barracuda Security Update – 26 December 2023 Read More »

Palo Alto Security Updates – 14 December 2023

Palo Alto has released security updates to address multiple vulnerabilities affecting PAN-OS and Cortex XSOAR. The addressed vulnerabilities could allow the attacker to perform cross-site scripting (XSS) attacks, obtain sensitive information or execute arbitrary code, and gain elevated privileges to the affected products. Sample of the addressed vulnerabilities: 1. PAN-OS: DOM-Based Cross-Site Scripting (XSS) Vulnerability

Palo Alto Security Updates – 14 December 2023 Read More »