Alerts

Ivanti Security Update – 03 August 2023

Ivanti released a security update to fix a critical vulnerability affecting Ivanti Endpoint Manager Mobile (EPMM) version 11.2 and older, formerly known as MobileIron Core. The addressed vulnerability could allow the remote attacker to gain access to specific API paths without requiring authentication, and disclose information related to personally identifiable information (PII) and this vulnerability […]

Ivanti Security Update – 03 August 2023 Read More »

Cisco Security Updates – 03 August 2023

Cisco has released security updates to fix multiple vulnerabilities in Cisco Secure Web Appliance and Cisco BroadWorks. The addressed vulnerabilities could allow the remote attacker to bypass security nrestrictions or perform cross-site scripting on the affected products. The addressed vulnerabilities: 1- Cisco AsyncOS Software for Cisco Secure Web Appliance Security Bypass (CVE-2023-20215): CVSS: 5.8 Attack

Cisco Security Updates – 03 August 2023 Read More »

F5 Security Updates – 03 August 2023

F5 has released security updates to fix several vulnerabilities across multiple F5 products such as (BIG-IP, BIG-IP APM, F5OS-A, BIG-IQ Centralized Management). The addressed vulnerabilities could allow the attacker to bypass security restrictions, perform a cross-site scripting attack, obtain sensitive information, or gain elevated privileges by sending a specially crafted request to the affected systems.

F5 Security Updates – 03 August 2023 Read More »

Google Chrome Security Update – 03 August 2023

Google has released an updated Chrome version (115.0.5790.170/.171) for Windows, and (115.0.5790.170) for Linux, and Mac to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerability: Google

Google Chrome Security Update – 03 August 2023 Read More »

Mozilla FireFox Security Updates – 02 August 2023

Mozilla has released an updated Firefox version 116, and Firefox ESR versions 102.14, 115.1 to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to gain access, obtain sensitive information, perform a denial of service attack, bypass security restrictions, gain elevated privileges, or execute arbitrary code on the affected system by persuading the

Mozilla FireFox Security Updates – 02 August 2023 Read More »

VMware Security Updates – 26 July 2023

VMware has released security updates to fix multiple vulnerabilities in VMware SD-Wan and Tanzu Application Service. The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, caused by improper authentication in SD-Wan and logging credentials in hex encoding in platform system audit logs in VMware Tanzu Application. Sample of the addressed vulnerabilities: VMware

VMware Security Updates – 26 July 2023 Read More »

Apple Security Updates – 25 July 2023

Apple has released security updates to address several vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to execute arbitrary code, perform denial of service attacks, bypass security restrictions, obtain sensitive information, gain elevated privileges, or gain access to the affected systems by persuading the victim to visit a specially crafted website. Sample

Apple Security Updates – 25 July 2023 Read More »

Ivanti Security Update – 25 July 2023

Ivanti released a security update to fix a critical vulnerability affecting all supported versions of Ivanti Endpoint Manager Mobile (EPMM), formerly known as MobileIron Core. The addressed vulnerability could allow the remote attacker to gain access to specific API paths without requiring authentication. The API paths can access personally identifiable information (PII) such as names,

Ivanti Security Update – 25 July 2023 Read More »

OpenSSH Security Update – 24 July 2023

OpenSSH released a security update to fix a vulnerability affecting all versions of OpenSSH before 9.3p2. The addressed vulnerability could allow the remote attacker to execute arbitrary code on the affected system by sending specially crafted requests. OpenSSH Code Execution Vulnerability (CVE-2023-38408): CVSS: 8.1 Attack Vector: Network Attack Complexity: High Privileges Required: None User Interaction:

OpenSSH Security Update – 24 July 2023 Read More »

Atlassian Security Updates – 24 July 2023

Atlassian has released security updates to address several vulnerabilities in Atlassian Confluence and Atlassian Bamboo. The severity of the addressed vulnerabilities could allow the remote attacker to gain access, and execute arbitrary code on the affected systems. Sample of the addressed vulnerabilities: Atlassian Confluence Data Center and Atlassian Confluence Server Code Execution Vulnerability (CVE-2023-22508): CVSS:

Atlassian Security Updates – 24 July 2023 Read More »

Microsoft Edge Security Update – 24 July 2023

Microsoft has released an updated Edge version (115.0.1901.183) and extended stable version (114.0.1823.90) to fix multiple vulnerabilities. The addressed vulnerabilities could allow the attacker to gain privileges or trigger spoofing attack by persuading the victim to open specially crafted file or request. Sample of the addressed vulnerabilities: Microsoft Edge (Chromium-based) Privilege Escalation (CVE-2023-38187): CVSS: 7.5

Microsoft Edge Security Update – 24 July 2023 Read More »

Adobe ColdFusion Security Updates – 20 July 2023

Adobe has released security updates to fix multiple vulnerabilities in Adobe ColdFusion. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code on the system via the deserialization of untrusted data or bypass security restrictions by persuading the victim to open a specially crafted file. Sample of the addressed vulnerabilities: 1. Adobe ColdFusion

Adobe ColdFusion Security Updates – 20 July 2023 Read More »

Oracle Security Patch Updates July 2023

Oracle released its critical patch updates for July 2023, containing (508) new security patches for multiple affected products. The remote attacker could exploit some of these vulnerabilities to take control of the affected system. This critical patch update includes security updates addressing numerous vulnerabilities that could potentially be exploited remotely without authentication. The affected product

Oracle Security Patch Updates July 2023 Read More »

Citrix Security Updates – 19 July 2023

Citrix has released security updates to address several vulnerabilities in Citrix ADC, and Citrix Gateway. The addressed vulnerabilities could allow the remote attacker to gain access, execute arbitrary code, perform cross-site scripting attacks, or gain elevated privileges on the affected systems. The addressed vulnerabilities: 1. Citrix ADC, Citrix Gateway Unauthenticated Remote Code Execution (CVE- 2023-3519):

Citrix Security Updates – 19 July 2023 Read More »

Adobe ColdFusion Security Updates – 18 July 2023

Adobe has released security updates to fix multiple vulnerabilities in Adobe ColdFusion. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code on the system via the deserialization of untrusted data or bypass security restrictions by persuading the victim to open a specially crafted file. Sample of the addressed vulnerabilities: 1. Adobe ColdFusion

Adobe ColdFusion Security Updates – 18 July 2023 Read More »

Microsoft Edge Security Update – 16 July 2023

Microsoft has released an updated Edge version (114.0.1823.82) to fix multiple vulnerabilities. The addressed vulnerabilities could allow the attacker to gain access or trigger a spoofing attack by persuading the victim to open a specially crafted file or request. Sample of the addressed vulnerabilities: Microsoft Edge (Chromium-based) Code Execution (CVE-2023-36887): CVSS: 7.8 Attack Vector: Local

Microsoft Edge Security Update – 16 July 2023 Read More »

Juniper Security Updates – 13 July 2023

Juniper has released security updates to fix multiple vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to obtain sensitive information, perform denial of service, execute arbitrary code, and gain access to the affected products. Sample of the addressed vulnerabilities: Juniper Networks Junos OS Denial of Service Vulnerability (CVE-2023-36832): CVSS: 7.5 Attack Vector:

Juniper Security Updates – 13 July 2023 Read More »