Alerts

SolarWinds Security Updates 16 February 2023

SolarWinds has released security updates to fix multiple vulnerabilities in SolarWinds Platform and Server & Application Monitor. The severity of the addressed vulnerabilities could allow the attacker with privileges to execute arbitrary commands on the affected product. Sample of the addressed vulnerabilities: 1. SolarWinds Platform Deserialization of Untrusted Data Vulnerability (CVE-2023-23836): • CVSS: 8.8 • Attack Vector: […]

SolarWinds Security Updates 16 February 2023 Read More »

Microsoft February 2023 Patch Tuesday

Microsoft has released its monthly patch of security updates, known as Patch Tuesday. The mentioned patch contains a fix for three actively exploited zero-day vulnerabilities. Microsoft has fixed (77) vulnerabilities, with (9) classified as critical as they could allow the attacker to perform code execution, bypass security features, elevate privileges, or cause a denial of service. February’s Patch Tuesday

Microsoft February 2023 Patch Tuesday Read More »

Mozilla FireFox Security Updates 15 February 2023

Mozilla has released security updates to fix vulnerabilities in Firefox 110 and Firefox ESR 102.8. The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, perform spoofing attacks, bypass security restrictions, execute arbitrary code, or cause a denial of service attack on the affected products. Sample of the addressed vulnerabilities: 1. Mozilla Firefox Weak Security (CVE-2023-25737):

Mozilla FireFox Security Updates 15 February 2023 Read More »

Apple Security Updates 14 February 2023

Apple has released security updates to address multiple vulnerabilities including a zero-day vulnerability in Safari 16.3, and macOS Ventura 13.2.1. The addressed vulnerabilities could allow the attacker to obtain information, escalate privileges, or gain access to the affected system by persuading a victim to open specially crafted web content. The actively exploited zero-day vulnerability tracked as (CVE-2023-23529) is

Apple Security Updates 14 February 2023 Read More »

SAP February 2023 Security Patch Day

SAP has released security updates to address several vulnerabilities affecting multiple products. In addition, SAP also announced (5) updates to the previously released patch day security notes. This month’s patch fixes several vulnerabilities affecting multiple SAP products such as SAP BPC MS 10.0, SAP BusinessObjects Business Intelligence platform, SAP NetWeaver Process Integration, SAP NetWeaver AS for Java, SAP NetWeaver

SAP February 2023 Security Patch Day Read More »

Microsoft Edge Security Update 12 February 2023

Microsoft has released an updated Microsoft Edge stable version (110.0.1587.41) to fix multiple vulnerabilities in Microsoft Edge (Chromium-based). The severity of the addressed vulnerabilities could allow the remote attacker to gain access, or perform denial of service or spoofing attacks on the affected system. Sample of the addressed vulnerabilities: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability (CVE-2023-23374): •

Microsoft Edge Security Update 12 February 2023 Read More »

Redhat Security Updates 12 February 2023

Redhat has released security updates to address multiple vulnerabilities across multiple products. The addressed vulnerabilities could allow the remote attacker to perform various attacks such as denial of service attacks, execute arbitrary code, or escalate privileges on the affected system. Sample of the addressed vulnerabilities: 1. Apache MINA SSHD Code Execution (CVE-2022-45047): • CVSS: 9.8 • Attack Vector:

Redhat Security Updates 12 February 2023 Read More »

Palo Alto Security Updates 09 February 2023

Palo Alto has released security updates to fix multiple vulnerabilities in Cortex XSOAR, and Cortex XDR Agent. The severity of the addressed vulnerabilities could allow the attacker to obtain information or cause a denial of service on the affected systems. Sample of the addressed vulnerabilities: Cortex XSOAR Server Local File Disclosure Vulnerability (CVE-2023-0003): • CVSS: 6.5 •

Palo Alto Security Updates 09 February 2023 Read More »

Google Chrome Security Update 08 February 2023

Google has released an updated Chrome version (110.0.5481.77/.78) for Windows and (110.0.5481.77) for Linux and Mac to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code on the system, bypass security restrictions, or cause a denial of service by persuading the victim to visit a specially crafted webpage on the affected system. Sample

Google Chrome Security Update 08 February 2023 Read More »

OpenSSL Security Update 08 February 2023

OpenSSL has released security updates to fix multiple vulnerabilities in multiple versions. The addressed vulnerability could allow the remote attacker to obtain sensitive information, or cause a denial of service attack by passing arbitrary pointers to a memcmp call or sending an overly large number of trial messages for decryption on the affected systems. Sample of the addressed vulnerabilities:

OpenSSL Security Update 08 February 2023 Read More »

VMware Security Updates 5 February 2023

VMware has released a security update to fix vulnerabilities in VMware Workstation 17 and vRealize Operations (vROps). The addressed vulnerabilities could allow the authenticated attacker to bypass security restrictions, gain access to the affected systems by sending a speciallycrafted or malicious HTTP request to trick the authenticated user into visiting a harmful website, allowing the attacker to perform a

VMware Security Updates 5 February 2023 Read More »

Cisco Security Updates 02 February 2023

Cisco has released security updates to address several vulnerabilities in multiple Cisco products. The released security updates fix several vulnerabilities affecting multiple Cisco products such as Cisco IOS XE Software, 800 Series Industrial ISRs, Catalyst Access Points (COS-APs), CGR1000 Compute Modules, RV340 Dual WAN Gigabit VPN Routers, RV340W Dual WAN Gigabit Wireless-AC VPN Routers, RV345 Dual WAN Gigabit VPN Routers,

Cisco Security Updates 02 February 2023 Read More »

F5 Security Updates 02 February 2023

F5 has released security updates to fix several vulnerabilities across multiple F5 products. The addressed vulnerabilities could allow the attacker to take control of the affected system by sending a specially crafted request to disclose information, escalate privileges, or cause a denial of service attack. Samples of the addressed vulnerabilities: 1. iControl SOAP Vulnerability (CVE-2023-22374): • CVSS: 8.5

F5 Security Updates 02 February 2023 Read More »

Atlassian Security Updates 02 February 2023

Atlassian has released a security update to fix a critical vulnerability in multiple versions of the Jira Service Management Server and Data Center. The mentioned vulnerability could allow the attacker to impersonate another user and gain access to the Jira Service Management instance under certain circumstances: • Write access to the User Directory is enabled. • Outgoing email

Atlassian Security Updates 02 February 2023 Read More »

Tenable Security Update 01 February 2023

Tenable has released a security update to fix a critical vulnerability in multiple products. The mentioned vulnerability could allow the authenticated remote attacker to escalate privileges by modifying environment variables and abusing the impacted plugin on the affected system. Tenable.io, Tenable.sc, and Nessus Privilege Escalation (CVE-2023-0524): CVSS: 9.1 Attack Vector: Network Attack Complexity: Low Privileges Required: High User

Tenable Security Update 01 February 2023 Read More »

QNAP Security Update 31 January 2023

QNAP has released a security update to address a critical vulnerability across QNAP QTS and QNAP QuTS hero. The severity of the addressed vulnerability could allow the remote unauthenticated attacker to inject and execute malicious code on the affected systems by sending specially crafted requests. QNAP running QTS and running QTS code execution (CVE-2022-27596): CVSS: 9.8 Attack Vector:

QNAP Security Update 31 January 2023 Read More »

Google Chrome Security Update 25 January 2023

Google has released an updated Chrome version (109.0.5414.119/.120) for Windows, and (109.0.5414.119) for Linux and Mac to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code or cause a denial of service on the vulnerable system, by persuading the victim to visit a specially crafted webpage. Sample of the addressed vulnerabilities: Google Chrome

Google Chrome Security Update 25 January 2023 Read More »

VMware Security Updates 25 January 2023

VMware has released security updates to fix multiple vulnerabilities in VMware vRealize Log Insight. The severity of the addressed vulnerabilities could allow the remote attacker to gain access, cause a denial of service attack, or obtain information from the affected systems. Sample of the addressed vulnerabilities: 1. VMware vRealize Log Insight Broken Access Control Vulnerability (CVE-2022-31704): • CVSS:

VMware Security Updates 25 January 2023 Read More »

ManageEngine Security Updates 25 January 2023

ManageEngine has released security updates to address multiple vulnerabilities across multiple products. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, manipulate data, or obtain information from the affected system. Sample of the addressed vulnerabilities: 1. ManageEngine ServiceDesk Plus MSP Security Bypass Vulnerability (CVE-2023-22964): • CVSS: 8.1 • Attack Vector: Network • Attack Complexity: High

ManageEngine Security Updates 25 January 2023 Read More »