Alerts

Citrix Security Updates – 11 October 2023

Citrix has released security updates to address multiple vulnerabilities across Citrix NetScaler ADC and NetScaler Gateway. The addressed vulnerabilities could allow the remote unauthenticated attacker to trigger a denial of service attack or obtain sensitive information from the affected product if configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or an […]

Citrix Security Updates – 11 October 2023 Read More »

SAP October 2023 Security Patch Day

SAP has released security updates to address several vulnerabilities affecting multiple products. SAP has released a patch that fixes several vulnerabilities affecting multiple SAP products such as SAP BusinessObjects Web Intelligence, SAP PowerDesigner Client, SAP NetWeaverAS Java, SAP Business One (B1i) and SAP S/4HANA Core, S/4HANA (Manage Withholding Tax Items), SAP NetWeaver AS for Java

SAP October 2023 Security Patch Day Read More »

Linux Security Updates – 09 October 2023

Linux has released security updates to fix multiple vulnerabilities in GNU C Library’s dynamic loader glibc version 2.34 and GNU grub2. The addressed vulnerabilities could allow the attacker to execute arbitrary code, obtain sensitive information, gain access, or gain elevated privileges using a maliciously crafted GLIBC_TUNABLES environment variable processed by the ld.so dynamic loader to

Linux Security Updates – 09 October 2023 Read More »

Atlassian Security Update – 05 October 2023

Atlassian has released a security update to address a critical vulnerability across multiple products. The addressed vulnerability could allow the remote attacker to gain elevated privileges on the system, caused by an error related to the /setup/* endpoints on Confluence instances allowing the creation of administrator accounts that can be used to access Confluence instances. Atlassian

Atlassian Security Update – 05 October 2023 Read More »

Cisco Security Updates – 05 October 2023

Cisco has released security updates to fix several vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to execute arbitrary commands, gain elevated privileges, gain access to the affected products, or perform denial of service attacks by sending a specially crafted HTTP request to a specific API. Sample of the addressed vulnerabilities: 1.

Cisco Security Updates – 05 October 2023 Read More »

SonicWall Security Updates – 04 October 2023

SonicWall has released security updates to fix multiple vulnerabilities in NetExtender Windows (32 and 64-bit) 10.2.336 and earlier versions. The addressed vulnerabilities could allow the attacker to gain elevated privileges on affected systems by sending a specially crafted request. The addressed vulnerabilities: 1. SonicWall NetExtender Pre-Logon Vulnerability (CVE-2023-44218): CVSS: 8.8 Attack Vector: Adjacent Attack Complexity:

SonicWall Security Updates – 04 October 2023 Read More »

Google Chrome Security Update – 04 October 2023

Google has released an updated Chrome version (117.0.5938.149/.150) for Windows, and (117.0.5938.149) for Mac and Linux to fix a vulnerability. The addressed vulnerability could allow the remote attacker to execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website. Google Chrome Code Execution Vulnerability (CVE-2023-5346):

Google Chrome Security Update – 04 October 2023 Read More »

WS_FTP Security Updates – 01 October 2023

WS_FTP has released security updates to address vulnerabilities affecting WS_FTP Server Ad hoc Transfer Module and the WS_FTP Server Manager Interface. The addressed vulnerabilities could allow the remote attacker to execute arbitrary commands, perform cross-site scripting attacks, or gain access to the affected systems. Sample of the addressed vulnerabilities: 1. WS_FTP Server Command Execution Vulnerability

WS_FTP Security Updates – 01 October 2023 Read More »

Cisco Security Updates – 28 September 2023

Cisco has released security updates to fix several vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to execute arbitrary commands, perform denial of service attacks, bypass security restrictions, or gain access to the affected products by various techniques such as sending specially crafted input to the web UI or sending requests directly

Cisco Security Updates – 28 September 2023 Read More »

Google Chrome Security Update – 28 September 2023

Google has released an updated Chrome version (117.0.5938.132) for Windows, Linux, and Mac to fix several vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, and gain access to the affected system by persuading the victim to visit a specially-crafted website. Sample of the addressed vulnerabilities: Google Chrome Heap Buffer Overflow

Google Chrome Security Update – 28 September 2023 Read More »

Mozilla FireFox Security Updates – 27 September 2023

Mozilla has released an updated Firefox version 118, and Firefox ESR version 115.3 to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, obtain sensitive information, perform denial of service attacks, or gain access to the affected system by persuading the victim to visit a specially crafted website. Sample

Mozilla FireFox Security Updates – 27 September 2023 Read More »

VMware Security Update – 27 September 2023

VMware has released a security update to address a vulnerability that affects Aria Operations. The addressed vulnerability could allow the local attacker with administrator privileges to gain ‘root’ privileges on the affected system. VMware Aria Operations Privilege Escalation Vulnerability (CVE-2023-34043): CVSS: 6.7 Attack Vector: Local Attack Complexity: Low Privileges Required: High User Interaction: None Consequences:

VMware Security Update – 27 September 2023 Read More »

MOVEit Transfer Security Updates – 24 September 2023

MOVEit Transfer has released security updates to address multiple vulnerabilities in multiple versions of Progress MOVEit Transfer. The addressed vulnerabilities could allow the remote attacker to perform either cross-site scripting attack by sending specially crafted URLs, or SQL injection attack to view, add, modify, or delete information in the back-end database on the affected system.

MOVEit Transfer Security Updates – 24 September 2023 Read More »

Apple Security Updates – 22 September 2023

Apple has released security updates to address three zero-day vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to gain access, elevate the privilege, and bypass security restrictions on the affected products by persuading the victim to open a specially crafted web content or application. Sample of the addressed vulnerabilities: 1. Apple Safari

Apple Security Updates – 22 September 2023 Read More »

SolarWinds Security Updates – 21 September 2023

SolarWinds has released security updates to fix multiple vulnerabilities in the SolarWinds Platform 2023.3 and prior versions. The addressed vulnerabilities could allow the remote attacker to execute arbitrary commands with NETWORK SERVICE privileges on the affected system. The addressed vulnerabilities: 1. SolarWinds Platform Command Execution Vulnerability (CVE-2023-23840): CVSS: 6.8 Attack Vector: Adjacent Network Attack Complexity:

SolarWinds Security Updates – 21 September 2023 Read More »