Alerts

Fortinet Security Update – 12 June 2023

Fortinet has released a security update to fix a critical SSL-VPN RCE vulnerability in multiple FortiOS firmware versions. The addressed vulnerability could allow the attacker to execute arbitrary code, and gain access by sending a specially crafted request to the affected products. The addressed vulnerability: Fortinet FortiGate and FortiOS Code Execution (CVE-2023-27997): CVSS: 9.8 Attack […]

Fortinet Security Update – 12 June 2023 Read More »

Stealth Soldier Malware – 12 June 2023

Stealth Soldier is a newly developed and tailored malware that has been strategically deployed in recent espionage campaigns specifically focused on North Africa. Stealth Soldier is a customized malware used in targeted attacks, enabling surveillance operations with features such as keystroke logging, screenshot capturing, and microphone recording. The Tactics and Techniques of Stealth Soldier Malware:

Stealth Soldier Malware – 12 June 2023 Read More »

Cisco Security Updates – 08 June 2023

Cisco released security updates to address several vulnerabilities affecting multiple Cisco products. The addressed vulnerabilities could allow the attacker to execute arbitrary code, gain access, escalate privileges, cause a denial of service, or perform cross-site scripting on the affected products. Sample of the addressed vulnerabilities: 1. Cisco Expressway Series and Cisco TelePresence VCS Privilege Escalation

Cisco Security Updates – 08 June 2023 Read More »

VMware Security Update – 07 June 2023

VMware has released a security update to fix multiple vulnerabilities across Aria Operations for Networks (Formerly vRealize Network Insight). The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, execute arbitrary code and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Aria Operations for Networks Command Injection (CVE-2023-20887): CVSS:

VMware Security Update – 07 June 2023 Read More »

Microsoft Edge Security Update – 06 June 2023

Microsoft has released an updated Edge version to fix Microsoft Edge-specific vulnerabilities, as well as chromium-based vulnerabilities. The addressed vulnerabilities could allow the remote attacker to perform various attacks such as bypassing security restrictions, gaining elevated privileges, or gaining access to the vulnerable system. Sample of the addressed vulnerabilities: 1. Microsoft Edge Privilege Escalation Vulnerability

Microsoft Edge Security Update – 06 June 2023 Read More »

MOVEit Transfer Security Update – 04 June 2023

MOVEit Transfer has released a security update to address a zero-day vulnerability. The addressed vulnerability could allow the remote attacker to gain unauthorized access to the application’s database and execute arbitrary commands, disclose information, and alter/delete database elements. the addressed vulnerability: Progress MOVEit Transfer SQL Injection Vulnerability (CVE-2023-34362): CVSS: 9.8 Attack Vector: Network Attack Complexity:

MOVEit Transfer Security Update – 04 June 2023 Read More »

Barracuda Security Update – 31 May 2023

Barracuda has released a security update to address a zero-day vulnerability across Email Security Gateway (ESG) appliances versions 5.1.3.001-9.2.0.006. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code on the system with the privileges of the Email Security Gateway product by attaching a specially crafted TAR archive file in the email and gain

Barracuda Security Update – 31 May 2023 Read More »

VMware Security Updates – 31 May 2023

VMware has released security updates to fix multiple vulnerabilities across multiple Vmware products. The addressed vulnerabilities could allow the remote attacker to perform cross-site scripting attacks, or disclose sensitive information from the affected products using a specially crafted URL to redirect the victim to the attacker-controlled domain. Sample of the addressed vulnerabilities: VMware Insecure Redirect

VMware Security Updates – 31 May 2023 Read More »

Google Chrome Security Update – 31 May 2023

Google has released an updated Chrome version (114.0.5735.90/91) for Windows and (114.0.5735.90) for Linux and Mac to fix multiple vulnerabilities. Write here analysis sectionThe addressed vulnerabilities could allow the remote attacker to gain access, execute arbitrary code on the system, or bypass security restrictions by persuading the victim to visit a specially crafted webpage. Sample

Google Chrome Security Update – 31 May 2023 Read More »

Apache Security Update – 23 May 2023

Apache has released a security update to address a vulnerability in Apache Tomcat. The addressed vulnerability could allow the remote attacker to cause a denial of service by sending a specially crafted request using query string parameters. Apache Tomcat Denial of Service Vulnerability (CVE-2023-28709): CVSS: 7.5 Attack Vector: Network Attack Complexity: Low Privileges Required: None

Apache Security Update – 23 May 2023 Read More »

Apple Security Updates – 21 May 2023

Apple has released security updates to address multiple vulnerabilities across macOS Ventura, macOS Monterey, macOS Big Sur, and Safari. The mentioned updates contain fixes for three zero-day vulnerabilities. The addressed vulnerabilities could allow the attacker to gain access, escalate privileges, bypass security restrictions, obtain information, or execute arbitrary code on the affected systems. Sample of

Apple Security Updates – 21 May 2023 Read More »

Cisco Security Updates – 18 May 2023

Cisco released security updates to address several vulnerabilities affecting multiple Cisco products. The addressed vulnerabilities could allow the attacker to execute arbitrary code, gain access, bypass security restrictions, escalate privileges, obtain sensitive information, or cause a denial of service attack on the affected systems. Sample of the addressed vulnerabilities: Cisco Small Business Series Switches Buffer

Cisco Security Updates – 18 May 2023 Read More »

Trend Micro Security Updates – 17 May 2023

Trend Micro has released security updates to fix multiple vulnerabilities across Apex One and Apex Central. The addressed vulnerabilities could allow the attacker to gain access, gain elevated privileges, or obtain sensitive information from the affected products. Sample of the addressed vulnerabilities: 1. Management Server Path Traversal Unauthenticated RCE Vulnerability (CVE-2023-32557): CVSS: 9.8 Attack Vector:

Trend Micro Security Updates – 17 May 2023 Read More »

VMware Security Update – 14 May 2023

VMware has released a security update to fix multiple vulnerabilities across VMware Aria Operations (formerly vRealize Operations) and VMware Cloud Foundation. addressed vulnerabilities could allow the authenticated attacker to gain elevated privileges on the affected system by sending a specially crafted request. Sample of the addressed vulnerabilities: VMware Aria Operations Privilege Escalation (CVE-2023-20877): CVSS: 8.8

VMware Security Update – 14 May 2023 Read More »