Alerts

Palo Alto Security Updates – 14 March 2024

Palo Alto has released security updates to address multiple vulnerabilities affecting GlobalProtect App and PAN-OS. The addressed vulnerabilities could allow the attacker to gain elevated privileges to the affected products. Sample of the addressed vulnerabilities: GlobalProtect App: Local User Can Disable GlobalProtect (CVE-2024-2431): CVSS: 5.7 Attack Vector: Local Attack Complexity: Low Privileges Required: Low User […]

Palo Alto Security Updates – 14 March 2024 Read More »

ManageEngine Security Update – 13 March 2024

ManageEngine has released a security update to address a critical vulnerability across Zoho ManageEngine Desktop Central version 9, build 90055. The addressed vulnerability could allow the remote attacker to upload arbitrary files, execute arbitrary PHP code, and gain access to the affected system by sending a specially crafted HTTP request. ManageEngine Desktop Central Unrestricted File

ManageEngine Security Update – 13 March 2024 Read More »

Intel Security Updates – 13 March 2024

Intel has released security updates to address several vulnerabilities in multiple Intel products. The addressed vulnerabilities could allow the attacker to gain elevated privileges, obtain sensitive information, or perform denial-of-service attacks on the affected products. Samples of the addressed vulnerabilities: 1. 4th Generation Intel Xeon Processors using Intel SGX or Intel TDX Privilege Escalation Vulnerability

Intel Security Updates – 13 March 2024 Read More »

Google Chrome Security Update – 13 March 2024

Google has released an updated Chrome version 122.0.6261.128/.129 for Windows and Mac and 122.0.6261.128 for Linux. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website. Google Chrome Code Execution Vulnerability (CVE-2024-2400): CVSS: 8.8 Attack Vector:

Google Chrome Security Update – 13 March 2024 Read More »

Fortinet Security Updates – 13 March 2024

Fortinet has released security updates to fix several vulnerabilities across multiple Fortinet products. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, gain elevated privileges, manipulate data, view, add, modify, or delete information in the back-end database, execute arbitrary code, and gain access to the affected products by sending specially crafted HTTP

Fortinet Security Updates – 13 March 2024 Read More »

Apple Security Updates – 10 March 2024

Apple has released security updates to address several vulnerabilities across Safari, macOS Ventura, macOS Monterey, and macOS Sonoma. The addressed vulnerabilities could allow the attacker to bypass security restrictions, obtain sensitive information, perform denial of service attacks, gain elevated privileges, or execute arbitrary code and gain access to the affected systems. Sample of the addressed

Apple Security Updates – 10 March 2024 Read More »

Microsoft Edge Security Update – 10 March 2024

Microsoft has released an updated Microsoft Edge version 122.0.2365.80 to address multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, or execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted Web site. Sample of the addressed vulnerabilities: 1. Microsoft Edge

Microsoft Edge Security Update – 10 March 2024 Read More »

Cisco Security Updates – 07 March 2024

Cisco has released security updates to fix several vulnerabilities across multiple Cisco products. The addressed vulnerabilities could allow the attacker to obtain sensitive information, conduct cross-site scripting attacks, gain elevated privileges, or execute arbitrary code, and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Cisco Secure Client Carriage Return Line Feed

Cisco Security Updates – 07 March 2024 Read More »

Aruba Security Update – 06 March 2024

Aruba has released a security update to fix multiple vulnerabilities affecting HPE Aruba OS. The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, perform denial of service attacks, or execute arbitrary commands and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Authenticated Remote Command Execution in the ArubaOS

Aruba Security Update – 06 March 2024 Read More »

VMware Security Updates – 06 March 2024

VMware has released security updates to address several vulnerabilities across multiple VMware products. The addressed vulnerabilities could allow the attacker to obtain sensitive information, or execute arbitrary code and gain access to the affected products. Sample of the addressed vulnerabilities: 1. VMware Workstation/Fusion Use-after-free Vulnerability in XHCI USBController (CVE-2024-22252): CVSS: 9.3 Attack Vector: Local Attack

VMware Security Updates – 06 March 2024 Read More »

SolarWinds Security Update – 05 March 2024

SolarWinds has released a security update to address a vulnerability affectingSolarWinds SEM 2023.4 and prior ersions. The addressed vulnerability could allow the attacker to execute arbitrary code and gain access to the affected system. SolarWinds Security Event Manager Remote Code Execution Vulnerability (CVE-2024-0692): CVSS: 8.8 Attack Vector: Adjacent Network Attack Complexity: Low Privileges Required: None

SolarWinds Security Update – 05 March 2024 Read More »

Aruba Security Update – 04 March 2024

Aruba has released a security update to fix multiple vulnerabilities affecting HPE Aruba ClearPass Policy Manager. The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, perform cross-site scripting, or execute arbitrary commands and gain access to the affected product. Sample of the addressed vulnerabilities: 1. HPE Aruba ClearPass Policy Manager Command Execution

Aruba Security Update – 04 March 2024 Read More »

Microsoft Edge Security Update – 03 March 2024

Microsoft has released an updated Microsoft Edge version 122.0.2365.63 to address multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: Microsoft Edge (Chromium-based) Code Execution (CVE-2024-1938): CVSS: 8.8

Microsoft Edge Security Update – 03 March 2024 Read More »

Google Chrome Security Update – 29 February 2024

Google has released an updated Chrome version 122.0.6261.94/.95 for Windows and 122.0.6261.94 for Mac and Linux to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: Google

Google Chrome Security Update – 29 February 2024 Read More »

Microsoft Edge Security Update – 27 February 2024

Microsoft has released an updated Microsoft Edge Stable Channel (122.0.2365.52) to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, bypass security restrictions, or execute arbitrary code and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Microsoft Edge (Chromium-based) Code Execution (CVE-2024-1669): CVSS: 8.8 Attack

Microsoft Edge Security Update – 27 February 2024 Read More »