Alerts

Aruba Security Updates – 09 July 2023

Aruba has released security updates to fix several vulnerabilities in multiple versions of Aruba Networks ArubaOS. The addressed vulnerabilities could allow the attacker to execute arbitrary commands, directory traversal, obtain sensitive information, cause a cross-site scripting attack, or gain access to the affected software versions. Sample of the addressed vulnerabilities: 1. Aruba Networks ArubaOS Cross-Site […]

Aruba Security Updates – 09 July 2023 Read More »

MOVEit Transfer Security Update – 08 July 2023

MOVEit Transfer has released a security update to address multiple vulnerabilities in multiple versions of Progress MOVEit Transfer. The addressed vulnerabilities could allow the remote attacker to cause a denial of service, or SQL injection attacks to view, add, modify, or delete information in the back-end database on the affected system. Sample of the addressed

MOVEit Transfer Security Update – 08 July 2023 Read More »

Akira Ransomware – 06 July 2023

Akira ransomware operation has increased its activity recently and first emerged in April 2023 targeting finance, education, real estate, manufacturing, and consulting sectors organizations around the world. Akira is based on the source code of Conti ransomware. Akira is a ransomware written in C++ that encrypts local files. Encrypted files have the extension “.akira” appended

Akira Ransomware – 06 July 2023 Read More »

Cisco Security Updates – 06 July 2023

Cisco has released security updates to fix multiple vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to perform a cross-site scripting attack, gain elevated privileges, obtain sensitive information by reading or modifying the traffic transmitted between the sites, or gain access to the affected products. Sample of the addressed vulnerabilities: 1. Cisco

Cisco Security Updates – 06 July 2023 Read More »

Mozilla FireFox Security Updates – 05 July 2023

Mozilla has released an updated Firefox version 115, and Firefox ESR version 102.13 to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to gain access, conduct a spoofing attack, bypass security restrictions, or execute arbitrary code by sending a specially crafted request to the affected system. Sample of the addressed vulnerabilities: Mozilla

Mozilla FireFox Security Updates – 05 July 2023 Read More »

Microsoft Teams IDOR Vulnerability – 25 June 2023

Security researchers have discovered an unpatched vulnerability in Microsoft Teams that could allow remote attackers to send malware to unsuspecting employees. Microsoft Teams’ default configuration allows users from outside (external tenants) of their organization to reach out to their staff members. The application doesn’t allow external tenants from sending files. However, security researchers discovered an

Microsoft Teams IDOR Vulnerability – 25 June 2023 Read More »

Fortinet Security Updates – 23 June 2023

Fortinet has released security updates to fix two vulnerabilities in FortiNAC affecting multiple versions. The addressed critical vulnerability could allow the remote attacker to execute unauthorized code or commands via specifically crafted requests to the TCP/1050 service. Sample of the addressed vulnerabilities: FortiNAC – Java Untrusted Object Deserialization RCE (CVE-2023-33299): CVSS: 9.6 Attack Vector: Network

Fortinet Security Updates – 23 June 2023 Read More »

Apache Security Updates – 22 June 2023

Apache has released security updates to address a vulnerability in multiple Apache Tomcat versions. The addressed vulnerability could allow the remote attacker to obtain sensitive information by sending a specially crafted HTTP request to the affected versions. Apache Tomcat Information Disclosure (CVE-2023-34981): CVSS: 7.5 Attack Vector: Network Attack Complexity: Low Privileges Required: None User Interaction:

Apache Security Updates – 22 June 2023 Read More »

VMware Security Updates – 22 June 2023

VMware has released security updates to fix multiple vulnerabilities in VMware vCenter Server and Cloud Foundation. The addressed vulnerabilities could allow the attacker to execute arbitrary code, cause memory corruption, a denial of services attack, or an out-of-bound write/read on the affected system. Sample of the addressed vulnerabilities: 1. VMware vCenter Server heap-overflow Vulnerability (CVE-2023-20892):

VMware Security Updates – 22 June 2023 Read More »

MOVEit Transfer Security Update – 20 June 2023

MOVEit Transfer has released a security update to address a critical vulnerability. The addressed vulnerability could allow the remote attacker to submit a crafted payload to a MOVEit Transfer application endpoint which could result in modification and disclosure of MOVEit database content. The addressed vulnerability: Progress MOVEit Transfer SQL Injection Vulnerability (CVE-2023-35708): CVSS: 9.8 Attack

MOVEit Transfer Security Update – 20 June 2023 Read More »

Palo Alto Security Updates – 15 June 2023

Palo Alto has released security updates to fix several vulnerabilities in PAN-OS and GlobalProtect App. The addressed vulnerabilities could allow the attacker to execute a JavaScript payload in the context of an authenticated Captive Portal user’s browser or gain elevated privileges on the affected system. The addressed vulnerabilities: 1. GlobalProtect App: Local Privilege Escalation Vulnerability

Palo Alto Security Updates – 15 June 2023 Read More »

VMware Security Update -14 June 2023

VMware has released a security update to fix a vulnerability in VMware Tools. The addressed vulnerability could allow the attacker to bypass security restrictions and obtain access to the guest virtual machine of the affected versions. the addressed vulnerability: VMware Tools Security Bypass Vulnerability (CVE-2023-20867): CVSS: 3.9 Attack Vector: Local Attack Complexity: High Privileges Required:

VMware Security Update -14 June 2023 Read More »

Zoom Security Updates – 14 June 2023

Zoom has released security updates to address several vulnerabilities in Windows, MacOS, and Linux. The addressed vulnerabilities could allow the attacker to cause a denial of service, gain privileges, bypass security restrictions, obtain information, and perform cross-site scripting on the affected systems. Sample of the addressed vulnerabilities: 1. Zoom for Windows, Zoom Rooms for Windows,

Zoom Security Updates – 14 June 2023 Read More »

Citrix Security Updates – 14 June 2023

Citrix has released security updates to address several vulnerabilities in CVAD, Citrix DaaS, and ShareFile StorageZones Controller. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, and obtain administrative access by sending a specially crafted request to the affected system. The addressed vulnerabilities: 1. ShareFile StorageZones Controller Vulnerability (CVE-2023-24489): CVSS: 9.1 Attack

Citrix Security Updates – 14 June 2023 Read More »