Alerts

Oracle Security Patch Update – 18 January 2024

Oracle released its critical patch update for January 2024, containing (389) new security patches for multiple affected products in Oracle code and third-party components included in Oracle products. The addressed vulnerabilities could allow the attacker to perform various attacks such as obtaining sensitive information, performing denial of service attacks, bypassing security restrictions, executing arbitrary code, and

Oracle Security Patch Update – 18 January 2024 Read More »

Microsoft Edge Security Update – 18 January 2024

Microsoft has released an updated Microsoft Edge version 120.0.2210.144 to fix multiple vulnerabilities. The addressed vulnerabilities could allow the attacker to gain elevated privileges, perform denial of service attacks, bypass security restrictions, execute arbitrary code, and gain access to the affected system by persuading the victim to openspecially crafted content. Sample of the addressed vulnerabilities:

Microsoft Edge Security Update – 18 January 2024 Read More »

Google Chrome Security Update – 17 January 2024

Google has released an updated Chrome version 120.0.6099.234 for Mac, 120.0.6099.224 for Linux, and version 120.0.6099.224/225 for Windows. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: Google Chrome Code

Google Chrome Security Update – 17 January 2024 Read More »

Citrix Security Updates – 17 January 2024

Citrix has released security updates to address several vulnerabilities across multiple products. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, conduct cross-site scripting attacks, perform denial of service attacks, or gain access to the affected system. Sample of the addressed vulnerabilities: 1. Citrix NetScaler ADC and NetScaler Gateway Denial of Service

Citrix Security Updates – 17 January 2024 Read More »

VMware Security Update – 16 January 2024

VMware has released a security update to address a critical vulnerability across VMware Aria Automation (formerly vRealize Automation), and VMware Cloud Foundation (Aria Automation). The addressed vulnerability could allow the authenticated attacker to gain unauthorized access to remote organizations and workflows. VMware Aria Automation Missing Access Control Vulnerability (CVE-2023-34063): CVSS: 9.9 Attack Vector: Network Attack

VMware Security Update – 16 January 2024 Read More »

Atlassian Security Updates – 16 January 2024

Atlassian has released security updates to address several vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to bypass security restrictions, perform denial of service attacks, or execute arbitrary code and gain access to the affected system. Sample of the addressed vulnerabilities: Confluence Data Center and Server Remote Code Execution Vulnerability (CVE-2024-21674): CVSS:

Atlassian Security Updates – 16 January 2024 Read More »

Trend Micro Security Update – 14 January 2024

Trend Micro has released a security update to address several vulnerabilities across Trend Micro Apex Central. The addressed vulnerabilities could allow the remote attacker to trigger cross-site scripting attacks, obtain sensitive information, or execute arbitrary code and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Trend Micro Apex Central Server-Side Request

Trend Micro Security Update – 14 January 2024 Read More »

Juniper Security Updates – 11 January 2024

Juniper has released security updates to fix several vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to obtain sensitive information, cause a denial of service attack, bypass security restrictions, gain elevated privileges, or execute arbitrary code and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Juniper Junos OS

Juniper Security Updates – 11 January 2024 Read More »

Cisco Security Updates – 11 January 2024

Cisco has released security updates to fix several vulnerabilities in multiple Cisco products. The addressed vulnerabilities could allow the attacker to upload arbitrary files, gain elevated privileges to root, trigger cross-site scripting attacks, manipulate data by sending specially crafted SQL statements, or execute arbitrary commands and gain access to the affected products. Sample of the

Cisco Security Updates – 11 January 2024 Read More »

Ivanti Security Updates – 11 January 2024

Ivanti has released security updates to fix two zero-day vulnerabilities across Ivanti Connect Secure (ICS) and Ivanti Policy Secure. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, and bypass security restrictions on the affected systems by sending a specially crafted request. The addressed vulnerabilities: 1. Ivanti ICS and Ivanti Policy Secure

Ivanti Security Updates – 11 January 2024 Read More »

Google Chrome Security Update – 10 January 2024

Google has released an updated Chrome version 120.0.6099.216/217 for Windows and 120.0.6099.216 for Mac and Linux. The addressed vulnerability could allow the remote attacker to bypass security restrictions caused by insufficient data validation in Extensions of the affected system by persuading the victim to visit a specially crafted website. Google Chrome Security Bypass Vulnerability (CVE-2024-0333):

Google Chrome Security Update – 10 January 2024 Read More »

Intel Security Updates – 10 January 2024

Intel has released security updates to address several vulnerabilities in multiple Intel products The severity of the addressed vulnerabilities could allow the local authenticated attacker to gain elevated privileges or perform denial-of-service attacks on the affected products. Samples of the addressed vulnerabilities: 1. Intel NUC BIOS Firmware Privilege Escalation (CVE-2023-42429): CVSS: 7.5 Attack Vector: Local

Intel Security Updates – 10 January 2024 Read More »

Fortinet Security Updates – 10 January 2024

Fortinet has released security updates to fix multiple vulnerabilities across several products. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, escalate privilege, obtain sensitive information, perform denial of service attacks, or execute code and gain access to the affected products. Sample of the addressed vulnerabilities: FortiOS & FortiProxy Improper Authorization for

Fortinet Security Updates – 10 January 2024 Read More »

SAP January 2024 Security Patch Day

SAP has released security updates to address several vulnerabilities affecting multiple products. SAP has released a patch that fixes several vulnerabilities affecting multiple SAP products such as SAP Application Interface Framework, SAP S/4HANA Finance, SAP Web Dispatcher, SAP NetWeaver Application Server ABAP, and ABAP Platform. The attacker could exploit some of these vulnerabilities to bypass

SAP January 2024 Security Patch Day Read More »

ManageEngine Security Updates – 09 January 2024

ManageEngine has released security updates to address a critical vulnerability across multiple product builds till 127259. The addressed vulnerability could allow the remote authenticated attacker to traverse directories by sending a specially crafted URL request containing “dot dot” sequences (/../) to create arbitrary files on the affected systems. ManageEngine OpManager Directory Traversal Vulnerability (CVE-2023-47211): CVSS:

ManageEngine Security Updates – 09 January 2024 Read More »