Alerts

SAP December 2022 Security Patch Day

SAP has released security updates to address several vulnerabilities affecting multiple products. In addition, SAP also announced (4) updates to the previously released patch day security notes. This month’s patch fixes several vulnerabilities affecting multiple SAP products such as SAP BusinessObjects Business Intelligence Platform (Web intelligence) and (Program Objects), SAP NetWeaver Process Integration, SAP Commerce, SAP […]

SAP December 2022 Security Patch Day Read More »

Fortinet Security Updates – 13 December 2022

Fortinet has released security updates to fix a critical zero-day vulnerability in FortiOS and FortiOS-6k7k. The addressed vulnerability could allow the remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests to gain access to the affected product. FortiOS heap-based buffer overflow in sslvpnd (CVE-2022-42475): • CVSS: 9.3 • Attack Vector: Network •

Fortinet Security Updates – 13 December 2022 Read More »

VMware Security Updates 11 December 2022

VMware has released security updates to fix multiple vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to execute arbitrary code, obtain information and cause a denial of service attack on the affected products. Samples of the addressed vulnerabilities: 1- VMware ESXi memory corruption vulnerability (CVE-2022-31696): CVSS: 7.5 Attack Vector: Local Attack Complexity: High

VMware Security Updates 11 December 2022 Read More »

DeathStalker Newly Janicab Variant – 11 December 2022

DeathStalker targets Financial and legal entities in the Middle East with a new Janicab malware variant. Janicab was introduced as malware that runs on macOS and Windows operating systems. DeathStalker has leveraged several malware strains and delivery chains over the years, from the Python and Visual Basic-based Janicab to the PowerShell-based Powersing and the JavaScript-based Evilnum. The

DeathStalker Newly Janicab Variant – 11 December 2022 Read More »

TrueBot Malware 11 December 2022

Silence APT group targets financial institutions in several countries around the world through delivering TrueBot malware which leveraging of Netwrix Auditor critical RCE Bug and Raspberry Robin worm. TrueBot was first identified in 2017 as downloader malware, the main goal is to infect systems, collect information to help triage interesting targets, and deploy additional payloads. Security Researchers

TrueBot Malware 11 December 2022 Read More »

Zerobot Malware – 08 December 2022

Zerobot is a Go-Based Malware that has been observed targeting devices like F5 Big-IP, Zyxel Firewalls, spring4Shell, and phpMyAdmin with almost two dozen vulnerability exploits. The Botnet’s objective is to add compromised devices to its pool to launch DDoS attacks and execute arbitrary commands.  The malware targets several system architecures including i386, AMD64, ARM, ARM64,

Zerobot Malware – 08 December 2022 Read More »

Fortinet Security Updates – 07 December 2022

Fortinet has released security updates to address multiple vulnerabilities across multiple products.  The addressed vulnerabilities could allow the remote attacker to gain access, log manipulation, and retrieve files with specific extensions from the affected products. These security updates fix several vulnerabilities affecting multiple Fortinet products such as FortiADC, FortiProxy, FortiOS, FortiSOAR, FortiDeceptor, and FortiSandbox. Sample

Fortinet Security Updates – 07 December 2022 Read More »

Zoom Security Updates -16 November 2022

 Zoom has released security updates to fix vulnerabilities in multiple products. The severity of the addressed vulnerabilities could allow the local attacker to execute arbitrary code or gain privileges. Samples of the addressed vulnerabilities: 1. DLL injection in Zoom Windows Clients (CVE-2022-28766): CVSS: 8.1 Attack Vector: Local Attack Complexity: Low Privileges Required: Low User Interaction:

Zoom Security Updates -16 November 2022 Read More »

Intel Security Updates – 14 November 2022

Intel releases security updates to address several vulnerabilities in multiple Intel products.  The severity of the addressed vulnerabilities could allow the locally authenticated attacker to gain elevated privileges on the system by improper input validation in the BIOS firmware or improper access control.  Samples of the addressed vulnerabilities:  1. Intel Privilege Escalation (CVE-2022-26006):  • CVSS:

Intel Security Updates – 14 November 2022 Read More »

Grafana Security Updates – 14 November 2022

Grafana has released security updates (Grafana 9.2.4, Grafana 8.5.15) to fix several vulnerabilities. The severity of the addressed vulnerabilities could allow the remote attacker to gain elevated privileges on the system by sending specially-crafted requests or obtaining sensitive information. Samples of the addressed vulnerabilities: 1. Privilege Escalation: Unauthorized access to arbitrary endpoints (CVE-2022- 39328): •

Grafana Security Updates – 14 November 2022 Read More »

IBM Security Update -13 November 2022

IBM has released a security update to fix a critical vulnerability that affects IBM InfoSphere Information Server. IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability. The addressed vulnerability could allow the remote attacker to execute an arbitrary command due to improper neutralization of special elements on the affected system of IBM InfoSphere DataStage.

IBM Security Update -13 November 2022 Read More »

Dell Security Update -14 November 2022

Dell has released a security update to fix a critical vulnerability that affects Connectrix (Brocade) FOS. Brocade Fabric OS versions before v9.1.1_01, v9.0.1e1, v8.2.3c1, and v7.4.2j1 could allow the unauthenticated remote attacker to execute on a Brocade Fabric OS switch commands capable of modifying zoning, disabling the switch, disabling ports, and modifying the switch IP address.Brocade

Dell Security Update -14 November 2022 Read More »

Microsoft Edge Security Updates -13 November 2022

Microsoft has released an updated Microsoft Edge (Version 107.0.1418.42) to fix several vulnerabilities. The severity of the addressed vulnerabilities could allow the remote attacker to execute arbitrary code on the affected system by persuading the victim to visit a specially crafted webpage. Samples of the addressed vulnerabilities: 1. Chromium V8 Code Execution (CVE-2022-3889): CVSS: 8.8

Microsoft Edge Security Updates -13 November 2022 Read More »

Cisco Released Security Updates -10 November 2022

Cisco has released security updates to address several vulnerabilities in multiple products. The released security updates fix several vulnerabilities affecting multiple Cisco products such as Cisco ASA Software, Cisco FTD Software, Cisco FMC Software, Cisco FirePOWER Software and Cisco Secure Firewalls 3100 Series. The severity of the addressed vulnerabilities could allow the remote attacker to

Cisco Released Security Updates -10 November 2022 Read More »

Trend Micro Released Security Updates -10 November 2022

Trend Micro has released new patches to address several vulnerabilities in Trend Micro Apex One and Apex One as a Service. The released security updates resolve several vulnerabilities having severity ratings from medium to high. The attacker could exploit some of these vulnerabilities to obtain sensitive information or gain privileged access on the affected system.

Trend Micro Released Security Updates -10 November 2022 Read More »

Google Chrome Security Updates -10 November 2022

Google has released an updated Chrome version (107.0.5304.110) for Mac and Linux and (107.0.5304.106/.107) for Windows, to fix several vulnerabilities, The remote attacker could exploit these vulnerabilities to take control of the affected system. The severity of the addressed vulnerabilities could allow the remote attacker to execute arbitrary code on the affected system by persuading

Google Chrome Security Updates -10 November 2022 Read More »

SAP November 2022 – Security Patch Day

SAP has released security updates to address several vulnerabilities affecting multiple products. In addition, SAP also announced (2) updates to the previously released patch day security notes. This month’s patch fixes several vulnerabilities affecting multiple SAP products such as SAP BusinessObjects Business Intelligence Platform (Central Management Console and BI Launchpad), SAPUI5 CLIENT RUNTIME, SAP NetWeaver

SAP November 2022 – Security Patch Day Read More »

Redhat Security Updates – 09 November 2022

Redhat has released security updates to address multiple vulnerabilities across multiple products. The severity of the addressed vulnerabilities could allow the attacker to gain access, leak kernel information, gain Privileges, and cause a denial of service on the affected system. Sample of the addressed vulnerabilities: GnuPG Libksba buffer overflow (CVE-2022-3515): CVSS: 9.8 Attack Vector: Network

Redhat Security Updates – 09 November 2022 Read More »