Alerts

Atlassian Security Updates – 21 September 2023

Atlassian has released security updates to address several vulnerabilities across multiple products. The addressed vulnerabilities could allow the remote attacker to gain access, execute arbitrary code, or trigger a denial of service attack on the affected products. Sample of the addressed vulnerabilities: 1. Atlassian Bitbucket Server, Data Center Code Execution (CVE-2023-22513): CVSS: 8.5 Attack Vector: […]

Atlassian Security Updates – 21 September 2023 Read More »

Trend Micro Security Updates – 20 September 2023

Trend Micro has released security updates to address a critical zero-day vulnerability across Trend Micro Apex One (on-premise, SaaS), Trend Micro Worry-Free Business Security, and Trend Micro Worry-Free Business Security SaaS. The addressed vulnerability could allow the remote authenticated attacker toexecute arbitrary code on the affected system. Trend Micro Endpoint Security Products Code Execution (CVE-2023-41179):

Trend Micro Security Updates – 20 September 2023 Read More »

Fortinet Security Updates – 18 September 2023

Fortinet has released security updates to fix several vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to gain access, obtain sensitive information, or manipulate files on the affected products. Sample of the addressed vulnerabilities: 1- Fortinet FortiWeb Code Execution Vulnerability (CVE-2023-34984): CVSS: 7.1 Attack Vector: Network Attack Complexity: High Privileges Required: None

Fortinet Security Updates – 18 September 2023 Read More »

Microsoft Edge Security Update – 17 September 2023

Microsoft Edge has released an updated Microsoft Edge Stable version (117.0.2045.31), and version 109 (109.0.1518.140) to fix a zero-day vulnerability. The addressed vulnerability could allow the remote attacker to exploit it through a malicious WebP image, when the victim opens the compromised image it could trigger a heap buffer overflow within the content process, potentially

Microsoft Edge Security Update – 17 September 2023 Read More »

Fortinet Security Updates -14 September 2023

Fortinet has released security updates to fix several vulnerabilities in FortiProxy, FortiADC, and FortiOS. The addressed vulnerabilities could allow the attacker to perform cross-site scripting attacks, or gain access to the affected products and inject malicious script into the webpage to steal the victim’s cookie-based authentication credentials. The addressed vulnerabilities: 1. FortiADC – Command Injection

Fortinet Security Updates -14 September 2023 Read More »

Apache Security Update – 14 September 2023

Apache has released a security update to address a vulnerability in Apache Tomcat Connectors. The addressed vulnerability could allow the remote attacker to obtain sensitive information caused by a flaw in the mod_jk component by sending a specially crafted HTTP request. Apache Tomcat Connectors Information Disclosure (CVE-2023-41081): CVSS: 7.5 Attack Vector: Network Attack Complexity: Low

Apache Security Update – 14 September 2023 Read More »

Cisco Security Updates – 14 September 2023

Cisco has released security updates to fix multiple vulnerabilities in Cisco IOS XR Software. The addressed vulnerabilities could allow the attacker to gain access, execute arbitrary code, perform denial of service attacks, or bypass security restrictions on the affected products. Sample of the addressed vulnerabilities: 1. Cisco IOS XR Code Execution Vulnerability (CVE-2023-20236): CVSS: 6.7

Cisco Security Updates – 14 September 2023 Read More »

Palo Alto Security Updates – 14 September 2023

Palo Alto has released security updates to address vulnerabilities affecting PAN-OS and Cortex XDR Agent. The addressed vulnerabilities could allow the attacker to cause denial of serviceattacks on the affected products, or allow the local user to disable the Cortex XDRagent on the vulnerable Windows devices. The addressed vulnerabilities: 1. PAN-OS: Denial-of-Service Vulnerability in BGP

Palo Alto Security Updates – 14 September 2023 Read More »

Google Chrome Security Update – 14 September 2023

Google has released an updated Chrome version (117.0.5938.62/.63) for Windows, (117.0.5938.62) for Linux, and Mac and (109.0.5414.165) for Windows Server 2012, and Windows Server 2012 R2 only to fix several vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, bypass security restrictions, and gain access to the affected system by persuading

Google Chrome Security Update – 14 September 2023 Read More »

Adobe Security Updates – 13 September 2023

Adobe has released security updates to address multiple vulnerabilities in Adobe Acrobat and Reader, Adobe Connect, and Adobe Experience Manager. The addressed vulnerabilities could allow the attacker to steal the victim’s cookiebased authentication credentials or execute arbitrary code and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Adobe Acrobat and Adobe

Adobe Security Updates – 13 September 2023 Read More »

Zoom Security Updates – 13 September 2023

Zoom has released security updates to fix vulnerabilities in Zoom CleanZoom, Zoom clients, and Zoom Desktop Client for Windows and Linux. The addressed vulnerabilities could allow the attacker to perform denial of service attacks, or gain elevated privileges on the affected systems. Sample of the addressed vulnerabilities: 1. Zoom CleanZoom Privilege Escalation Vulnerability (CVE-2023-39201): CVSS:

Zoom Security Updates – 13 September 2023 Read More »

Microsoft September 2023 Patch Tuesday

Microsoft has released its monthly patch of security updates, known as Patch Tuesday. The mentioned patch addressed two actively exploited zero-day vulnerabilities. September’s Patch Tuesday was released to fix security flaws in several Microsoft products such as .NET Framework, 3D Builder, Windows Server 2012, Windows RT 8.1, Windows 10 x64, Microsoft Exchange Server, Microsoft Azure,

Microsoft September 2023 Patch Tuesday Read More »

SAP September 2023 Security Patch Day

SAP has released security updates to address several vulnerabilities affecting multiple products. In addition, SAP also announced (5) updates to the previously released patch day security notes. This month’s patch fixes several vulnerabilities affecting multiple SAP products such as SAP Business Objects Business Intelligence Platform (Promotion Management), SAP CommonCryptoLib, SAP PowerDesignerClient, SAP Quotation Management Insurance

SAP September 2023 Security Patch Day Read More »

Google Chrome Security Update – 12 September 2023

Google has released an updated Chrome version (116.0.5845.187/188) for Windows, and (116.0.5845.187) for Linux, and Mac to fix a zero-day vulnerability. The addressed vulnerability could allow the remote attacker to overflow the buffer and execute arbitrary code by persuading the victim to visit a specially craftedwebsite. Google Chrome Buffer Overflow Vulnerability (CVE-2023-4863): CVSS: 8.8 Attack

Google Chrome Security Update – 12 September 2023 Read More »

Cisco VPN Zero-Day Vulnerability – 11 September 2023

Cisco has released a security warning to mitigate a zero-day vulnerability across Cisco Adaptive Security Appliance (ASA) and Cisco Firepower Threat Defense (FTD). The addressed zero-day vulnerability is located within the web services interface of the Cisco ASA and Cisco FTD devices, specifically the functions that deal with authentication, authorization, and accounting (AAA) functions. This

Cisco VPN Zero-Day Vulnerability – 11 September 2023 Read More »

Aruba Security Updates – 10 September 2023

Aruba has released security updates to fix several vulnerabilities in HPE Aruba Networking (9000, 9200) Series Mobility Controllers and SD-WAN Gateways. The addressed vulnerabilities could allow the remote attacker to gain access, execute arbitrary code, or bypass security restrictions on the affected product  bysending a specially crafted request. Sample of the addressed vulnerabilities: 1. HPE

Aruba Security Updates – 10 September 2023 Read More »

Apple Security Updates – 08 September 2023

Apple has released security updates to address multiple vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to obtain sensitive information, perform cross-site scripting attacks, execute arbitrary code, and gain access to the affected products by persuading the victim to open a specially crafted image, attachment, or application. Sample of the addressed vulnerabilities:

Apple Security Updates – 08 September 2023 Read More »

Cisco Security Updates – 07 September 2023

Cisco has released security updates to fix multiple vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to gain access, execute arbitrary code, bypass security restrictions, gain elevated privileges, or perform denial of service attacks on the affected products by sending a specially crafted request. Sample of the addressed vulnerabilities: 1. Cisco BroadWorks

Cisco Security Updates – 07 September 2023 Read More »

Google Chrome Security Update – 06 September 2023

Google has released an updated Chrome version (116.0.5845.179/180) for Windows, and (116.0.5845.179) for Linux, and Mac to fix several vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, gain access, or bypass security restrictions on the affected system by persuading the victim to visit a specially crafted website. Sample of the

Google Chrome Security Update – 06 September 2023 Read More »