Alerts

Adobe Security Updates – 15 November 2023

Adobe has released security updates to fix multiple vulnerabilities across several products. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, bypass security restrictions, obtain sensitive information or trigger denial of services attacks on the affected products. Sample of the Addressed Vulnerabilities: 1. Adobe ColdFusion Code Execution Vulnerability (CVE-2023-44351): CVSS: 9.8 Attack […]

Adobe Security Updates – 15 November 2023 Read More »

TA402 APT Utilizing IronWind Malware to Target Middle East – 14 November 2023

TA402, recognized as a Middle Eastern advanced persistent threat (APT) group launched a new series of targeted phishing campaigns that are designed to deliver a new initial access downloader “IronWind” to target government entities in the Middle East. TA402 utilized three variations of the infection chain moving from using Dropbox links to using XLL and

TA402 APT Utilizing IronWind Malware to Target Middle East – 14 November 2023 Read More »

Microsoft Edge Security Update – 12 November 2023

Microsoft has released an updated Microsoft Edge Stable version (119.0.2151.58) and Extended Stable version (118.0.2088.102) to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to gain access, execute arbitrary code, and gain privileges on the affected system. Sample of the addressed vulnerabilities: 1. Microsoft Edge (Chromium-based) Code Execution (CVE-2023-5996): CVSS: 8.8 Attack

Microsoft Edge Security Update – 12 November 2023 Read More »

FreeBSD Security Update – 09 November 2023

FreeBSD systems have released a security update to address multiple vulnerabilities in FreeBSD libc and FreeBSD libcap_net. The addressed vulnerabilities could allow the remote attacker to overflow a buffer, execute arbitrary code, and gain access to the affected system by sending a specially crafted request. Sample of the addressed vulnerabilities: FreeBSD buffer overflow (CVE-2023-5941): CVSS:

FreeBSD Security Update – 09 November 2023 Read More »

WS_FTP Security Update – 09 November 2023

WS_FTP has released a security update to address a critical vulnerability affecting WS_FTP Server. The addressed vulnerability could allow the remote attacker to bypass security restrictions and upload a file to a specified location on the operating system hosting the WS_FTP Server application. WS_FTP Server Arbitrary File Upload (CVE-2023-42659): CVSS: 9.1 Attack Vector: Network Attack

WS_FTP Security Update – 09 November 2023 Read More »

SolarWinds Security Updates – 08 November 2023

SolarWinds has released security updates to fix multiple vulnerabilities in SolarWinds products. The addressed vulnerabilities could allow the attacker to obtain sensitive information or execute arbitrary code with system privileges and gain access to the affected systems. Sample of the addressed vulnerabilities: SolarWinds Network Configuration Manager Directory Traversal Vulnerability (CVE-2023-33226): CVSS: 8 Attack Vector: Adjacent

SolarWinds Security Updates – 08 November 2023 Read More »

Trend Micro Security Update – 08 November 2023

Trend Micro has released a security update to fix multiple vulnerabilities across Trend Micro Apex One and Apex One as a Service. The addressed vulnerabilities could allow the attacker to escalate privileges on the affected products. Sample of the addressed vulnerabilities: Agent Link Following Local Privilege Escalation Vulnerability (CVE-2023-47192): CVSS: 7.8 Attack Vector: Local Attack

Trend Micro Security Update – 08 November 2023 Read More »

Google Chrome Security Update – 08 November 2023

Google has released an updated Chrome version 119.0.6045.123/.124 for Windows, and 119.0.6045.123 for Mac and Linux to fix a vulnerability. The addressed vulnerability could allow the remote attacker to execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website. Google Chrome Code Execution Vulnerability (CVE-2023-5996):

Google Chrome Security Update – 08 November 2023 Read More »

Veeam Security Update – 07 November 2023

Veeam has released a security update to fix several vulnerabilities in Veeam ONE IT infrastructure monitoring and analytics platform versions 11, 11a, and 12. The addressed vulnerabilities could allow the attacker to obtain sensitive information, perform cross-site scripting attacks, execute arbitrary code, and gain access to the affected system. Sample of the addressed vulnerabilities: 1.

Veeam Security Update – 07 November 2023 Read More »

Cisco Security Updates – 02 November 2023

Cisco has released security updates to fix several vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to bypass security restrictions, obtain sensitive information, conduct cross-site scripting or perform denial of service attacks, execute arbitrary commands, and gain access to the affected system by sending a specially crafted HTTP request. Sample of the

Cisco Security Updates – 02 November 2023 Read More »

Tenable Security Updates – 01 November 2023

Tenable has released security updates to fix multiple vulnerabilities in several third-party components (curl, OpenSSL, zlib) affecting multiple tenable products. The addressed vulnerabilities could allow the attacker to execute arbitrary code, conduct denial of service attacks, bypass security restrictions, or gain elevated privileges to the affected system by loading a specially crafted file during installation

Tenable Security Updates – 01 November 2023 Read More »

Google Chrome Security Update – 01 November 2023

Google has released an updated Chrome version (119.0.6045.105/.106) for Windows, and (119.0.6045.105) for Mac and Linux to fix several vulnerabilities. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, execute arbitrary code, and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the

Google Chrome Security Update – 01 November 2023 Read More »

Atlassian Security Update – 31 October 2023

Atlassian has released a security update to address a critical vulnerability across all versions of Confluence Data Center and Confluence Server products. The addressed vulnerability could allow the unauthenticated remote attacker to cause significant data loss on the vulnerable Confluence Data Center and Server but there is no impact to confidentiality as the attacker cannot

Atlassian Security Update – 31 October 2023 Read More »

Microsoft Edge Security Update – 30 October 2023

Microsoft has released an updated Microsoft Edge stable version (118.0.2088.76) to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, conduct spoofing attacks, execute arbitrary code, and gain access to the affected system by persuading the victim to open a specially crafted Adobe PDF file. Sample of the addressed

Microsoft Edge Security Update – 30 October 2023 Read More »

VMware Security Updates – 29 October 2023

VMware has released security updates to address vulnerabilities affecting VMware Tools version 12.x.x, 11.x.x, 10.3.x macOS and Windows. The addressed vulnerabilities could allow the attacker to gain elevated privileges on the affected systems. Sample of the addressed vulnerabilities: VMware Tools Privilege Escalation (CVE-2023-34057): CVSS: 7.8 Attack Vector: Local Attack Complexity: Low Privileges Required: Low User

VMware Security Updates – 29 October 2023 Read More »

F5 Security Updates – 28 October 2023

F5 has released security updates to fix multiple vulnerabilities across multiple products. The addressed vulnerabilities could allow the remote attacker to perform denial of service attacks, launch SQL injection attacks, execute arbitrary commands, and gain access to the affected products by sending specially crafted requests. Sample of the addressed vulnerabilities: 1. F5 BIG-IP Command Execution

F5 Security Updates – 28 October 2023 Read More »

Aruba Security Update – 26 October 2023

Aruba has released a security update to address multiple vulnerabilities across ClearPass Policy Manager. The addressed vulnerabilities could allow the attacker to gain elevated privilege, manipulate data, conduct phishing attacks, execute arbitrary commands, and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Aruba Networks ClearPass Policy Manager Privilege Escalation Vulnerability (CVE-2023-43506):

Aruba Security Update – 26 October 2023 Read More »