Alerts

Trend Micro Security Update – 14 January 2024

Trend Micro has released a security update to address several vulnerabilities across Trend Micro Apex Central. The addressed vulnerabilities could allow the remote attacker to trigger cross-site scripting attacks, obtain sensitive information, or execute arbitrary code and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Trend Micro Apex Central Server-Side Request

Trend Micro Security Update – 14 January 2024 Read More »

Juniper Security Updates – 11 January 2024

Juniper has released security updates to fix several vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to obtain sensitive information, cause a denial of service attack, bypass security restrictions, gain elevated privileges, or execute arbitrary code and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Juniper Junos OS

Juniper Security Updates – 11 January 2024 Read More »

Cisco Security Updates – 11 January 2024

Cisco has released security updates to fix several vulnerabilities in multiple Cisco products. The addressed vulnerabilities could allow the attacker to upload arbitrary files, gain elevated privileges to root, trigger cross-site scripting attacks, manipulate data by sending specially crafted SQL statements, or execute arbitrary commands and gain access to the affected products. Sample of the

Cisco Security Updates – 11 January 2024 Read More »

Ivanti Security Updates – 11 January 2024

Ivanti has released security updates to fix two zero-day vulnerabilities across Ivanti Connect Secure (ICS) and Ivanti Policy Secure. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, and bypass security restrictions on the affected systems by sending a specially crafted request. The addressed vulnerabilities: 1. Ivanti ICS and Ivanti Policy Secure

Ivanti Security Updates – 11 January 2024 Read More »

Google Chrome Security Update – 10 January 2024

Google has released an updated Chrome version 120.0.6099.216/217 for Windows and 120.0.6099.216 for Mac and Linux. The addressed vulnerability could allow the remote attacker to bypass security restrictions caused by insufficient data validation in Extensions of the affected system by persuading the victim to visit a specially crafted website. Google Chrome Security Bypass Vulnerability (CVE-2024-0333):

Google Chrome Security Update – 10 January 2024 Read More »

Intel Security Updates – 10 January 2024

Intel has released security updates to address several vulnerabilities in multiple Intel products The severity of the addressed vulnerabilities could allow the local authenticated attacker to gain elevated privileges or perform denial-of-service attacks on the affected products. Samples of the addressed vulnerabilities: 1. Intel NUC BIOS Firmware Privilege Escalation (CVE-2023-42429): CVSS: 7.5 Attack Vector: Local

Intel Security Updates – 10 January 2024 Read More »

Fortinet Security Updates – 10 January 2024

Fortinet has released security updates to fix multiple vulnerabilities across several products. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, escalate privilege, obtain sensitive information, perform denial of service attacks, or execute code and gain access to the affected products. Sample of the addressed vulnerabilities: FortiOS & FortiProxy Improper Authorization for

Fortinet Security Updates – 10 January 2024 Read More »

SAP January 2024 Security Patch Day

SAP has released security updates to address several vulnerabilities affecting multiple products. SAP has released a patch that fixes several vulnerabilities affecting multiple SAP products such as SAP Application Interface Framework, SAP S/4HANA Finance, SAP Web Dispatcher, SAP NetWeaver Application Server ABAP, and ABAP Platform. The attacker could exploit some of these vulnerabilities to bypass

SAP January 2024 Security Patch Day Read More »

ManageEngine Security Updates – 09 January 2024

ManageEngine has released security updates to address a critical vulnerability across multiple product builds till 127259. The addressed vulnerability could allow the remote authenticated attacker to traverse directories by sending a specially crafted URL request containing “dot dot” sequences (/../) to create arbitrary files on the affected systems. ManageEngine OpManager Directory Traversal Vulnerability (CVE-2023-47211): CVSS:

ManageEngine Security Updates – 09 January 2024 Read More »

Microsoft Edge Security Update – 08 January 2024

Microsoft has released an updated Microsoft Edge version 120.0.2210.121 to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: Microsoft Edge Code Execution Vulnerability (CVE-2024-0222): CVSS: 8.8

Microsoft Edge Security Update – 08 January 2024 Read More »

Google Chrome Security Update – 04 January 2024

Google has released an updated Chrome version 120.0.6099.199/200 for Windows, and 120.0.6099.199 for Mac and Linux to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: Google

Google Chrome Security Update – 04 January 2024 Read More »

Apache Security Updates – 27 December 2023

Apache has released security updates to address several vulnerabilities across multiple versions of Apache OFBiz. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, and gain access to the affected system by sending a specially crafted request. Sample of the addressed vulnerabilities: Apache Pre-authentication Remote Code Execution (CVE-2023-51467): CVSS: 9.8 Attack Vector:

Apache Security Updates – 27 December 2023 Read More »

Barracuda Security Update – 26 December 2023

Barracuda has released a security update to address two zero-day vulnerabilities across multiple versions of Email Security Gateway (ESG) appliances. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code within a third-party library “Spreadsheet::ParseExcel” on the affected system of Barracuda ESG Appliance by deploying a specially crafted Excel email attachment. Sample of

Barracuda Security Update – 26 December 2023 Read More »

Palo Alto Security Updates – 14 December 2023

Palo Alto has released security updates to address multiple vulnerabilities affecting PAN-OS and Cortex XSOAR. The addressed vulnerabilities could allow the attacker to perform cross-site scripting (XSS) attacks, obtain sensitive information or execute arbitrary code, and gain elevated privileges to the affected products. Sample of the addressed vulnerabilities: 1. PAN-OS: DOM-Based Cross-Site Scripting (XSS) Vulnerability

Palo Alto Security Updates – 14 December 2023 Read More »

Ivanti Security Updates – 21 December 2023

Ivanti has released security updates to fix multiple vulnerabilities affecting all supported versions of Ivanti Avalanche. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, gain access, perform server-side request forgery (SSRF), or trigger denial of services attacks on the affected products. Sample of the addressed vulnerabilities: 1. Ivanti Wavelink Avalanche Premise

Ivanti Security Updates – 21 December 2023 Read More »