Alerts

Veeam Security Update – 08 February 2024

Veeam has released a security update to fix several vulnerabilities across multiple Veeam products. The addressed vulnerabilities could allow the remote authenticated attacker to obtain sensitive information, such as plans from other scopes, or obtain the service account’s NTLM hash and use this information to launch further attacks against the affected system. The addressed vulnerabilities: […]

Veeam Security Update – 08 February 2024 Read More »

Tenable Security Update – 07 February 2024

Tenable has released a security update to fix several vulnerabilities in Nessus with stable version 10.7.0. The addressed vulnerabilities could allow the authenticated remote attacker to conduct cross-site scripting attacks, execute arbitrary scripts, scan DB content, manipulate data, and view, add, modify, or delete information on the affectedsystem. The addressed vulnerabilities: 1. Tenable Nessus SQL

Tenable Security Update – 07 February 2024 Read More »

VMware Security Update – 07 February 2024

VMware has released a security update to address several vulnerabilities in the VMware Aria Operations for Networks (formerly vRealize Network Insight). The addressed vulnerabilities could allow the attacker to gain elevated privileges, obtain sensitive information, or perform cross-site scripting attacks on the affected system. Sample of the addressed vulnerabilities: 1. VMware Aria Operations for Networks

VMware Security Update – 07 February 2024 Read More »

ManageEngine Security Updates – 06 February 2024

ManageEngine has released security updates to address several vulnerabilitiesacross multiple products such as ADAudit Plus and ADSelfService Plus. The addressed vulnerabilities could allow the remote attacker to manipulate data and view, add, modify, or delete information in the back-end database by sending a specially crafted SQL statement, or execute arbitrary code, and gain access to

ManageEngine Security Updates – 06 February 2024 Read More »

Juniper Security Updates – 04 February 2024

Juniper has released security updates to fix multiple vulnerabilities affecting Juniper Secure Analytics (JSA) Applications. The addressed vulnerabilities could allow the attacker to obtain sensitive information, manipulate files, trigger cross-site scripting, perform denial of service attacks, or execute arbitrary code and gain access to the affected products. Sample of the addressed vulnerabilities: Juniper Netlib LAPACK

Juniper Security Updates – 04 February 2024 Read More »

Microsoft Edge Security Update – 04 February 2024

Microsoft has released an updated Microsoft Edge Stable Channel (121.0.2277.98) and Microsoft Edge Extended Stable Channel (120.0.2210.167) to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities:

Microsoft Edge Security Update – 04 February 2024 Read More »

Symantec Security Vulnerabilities – 30 January 2024

Symantec has published several critical vulnerabilities in end-of-life versions across multiple products. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code or cause a buffer overflow and gain access to the affected products by sending specially crafted requests or persuading the victim to open a crafted document. Sample of the addressed vulnerabilities:

Symantec Security Vulnerabilities – 30 January 2024 Read More »

Juniper Security Updates 28 – January 2024

Juniper has released security updates to fix several vulnerabilities across multiple Juniper products. The addressed vulnerabilities could allow the attacker to obtain sensitive information, bypass security restrictions, trigger cross-site scripting attacks, or execute arbitrary code and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Juniper Networks Junos OS Cross-Site Scripting (CVE-2024-21620):

Juniper Security Updates 28 – January 2024 Read More »

Microsoft Edge Security Update – 28 January 2024

Microsoft has released an updated Microsoft Edge Stable Channel (121.0.2277.83) and Microsoft Edge Extended Stable Channel (120.0.2210.160) to fix multiple vulnerabilities. The addressed vulnerabilities could allow the attacker to gain elevated privilege, bypass security restrictions, execute arbitrary code, and gain access to the affected system by persuading the victim to open a malicious file. Sample

Microsoft Edge Security Update – 28 January 2024 Read More »

Cisco Security Updates – 25 January 2024

Cisco has released security updates to fix several vulnerabilities across multiple Cisco products.  The addressed vulnerabilities could allow the attacker to bypass security restrictions, gain elevated privileges, trigger cross-site scripting attacks, or execute arbitrary code and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Cisco Unified Communications Products Remote Code Execution

Cisco Security Updates – 25 January 2024 Read More »

Fortra Security Update – 24 January 2024

Fortra has released a security update to address a critical vulnerability in multiple versions of Fortra GoAnywhere MFT (Managed File Transfer). The addressed vulnerability could allow the unauthorized remote attacker to create admin users via the administration portal which could lead to a complete device takeover, access sensitive data, introduce malware, and potentially enable further

Fortra Security Update – 24 January 2024 Read More »

Google Chrome Security Update – 24 January 2024

Google has released an updated Chrome version 121.0.6167.85/.86 for Windows and 121.0.6167.85 for Mac and Linux. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, or execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: 1.

Google Chrome Security Update – 24 January 2024 Read More »

Splunk Security Updates – 23 January 2024

Splunk has released security updates to fix several vulnerabilities across multiple Splunk products. The addressed vulnerabilities could allow the attacker to bypass security restrictions, perform denial of service attacks, obtain sensitive information, or execute arbitrary code and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Splunk Enterprise Code Execution Vulnerability (CVE-2024-23678):

Splunk Security Updates – 23 January 2024 Read More »

Apple Security Updates – 23 January 2024

Apple has released security updates to address multiple vulnerabilities across macOS Monterey, Ventura, Sonoma, and Safari. The addressed vulnerabilities could allow the attacker to bypass security restrictions, gain elevated privileges, obtain sensitive information, execute arbitrary code, and gain access to the affected systems by persuading the victimto visit a specially crafted website. Sample of the

Apple Security Updates – 23 January 2024 Read More »

Atlassian Security Update – 22 January 2024

Atlassian has released a security update to address a critical vulnerability in Atlassian Confluence Data Center and Server out-of-date versions (8.0.x, 8.1.x, 8.2.x, 8.3.x, 8.4.x, 8.5.0-8.5.3). The addressed vulnerability is described as a template injection weakness that could allow the unauthenticated remote attacker to execute arbitrary code and gain access to the affected system. Atlassian

Atlassian Security Update – 22 January 2024 Read More »