Alerts

Ivanti Security Update – 09 April 2025

Ivanti has released a security update to fix several vulnerabilities affecting multiple Ivanti products. The addressed vulnerabilities could allow the attacker to conduct cross-site scripting attacks, obtain sensitive information, perform denial of service attacks, gain elevated privileges, or execute arbitrary code and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Ivanti […]

Ivanti Security Update – 09 April 2025 Read More »

Fortinet Security Updates – 09 April 2025

Fortinet has released security updates to fix several vulnerabilities across multiple Fortinet products. The addressed vulnerabilities could allow the attacker to perform denial of service attacks, gain elevated privileges, bypass security restrictions, or execute arbitrary code, and gain access to the affected product. Sample of the addressed vulnerabilities: 1. FortiSwitch Unverified Password Change Escalation of

Fortinet Security Updates – 09 April 2025 Read More »

Microsoft April 2025 Patch Tuesday

Microsoft has released its monthly patch of security updates, known as Patch Tuesday. The mentioned patch addressed one actively exploited zero-day vulnerability. Microsoft has fixed (134) vulnerabilities as they could allow the attacker to gain elevated privileges, bypass security restrictions, disclose sensitive information, perform spoofing or execute arbitrary code, and gain access to the affected

Microsoft April 2025 Patch Tuesday Read More »

SAP April 2025 Security Patch Day

SAP has released security updates to address several vulnerabilities affecting multiple SAP products. SAP has released a critical patch that fixes several vulnerabilities affecting multiple SAP products such as SAP S/4HANA (Private Cloud), SAP Financial Consolidation, SAP BusinessObjects Business Intelligence platform (Central Management Console), and SAP Landscape Transformation (Analysis Platform). The attacker could exploit some

SAP April 2025 Security Patch Day Read More »

Microsoft Edge Security Update – 06 April 2025

Microsoft has released an updated Microsoft Edge stable channel “135.0.3179.54” to address multiple vulnerabilities. The addressed vulnerabilities could allow the attacker to bypass security restrictions, gain elevated privileges, or execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: 1.

Microsoft Edge Security Update – 06 April 2025 Read More »

Ivanti Security Update – 06 April 2025

Ivanti has released security updates to address a critical vulnerability affecting multiple Ivanti products. The vulnerability could allow the remote unauthenticated attacker to execute arbitrary code through a stack-based buffer overflow and gain access to the affected product. Ivanti Connect Secure, Policy Secure, and ZTA Gateways Remote Code Execution Vulnerability (CVE-2025-22457): CVSS: 9 Attack Vector:

Ivanti Security Update – 06 April 2025 Read More »

Apple Security Updates – 03 April 2025

Apple has released security updates to address multiple vulnerabilities across macOS Sequoia, Sonoma, Ventura, and Safari. The addressed vulnerabilities could allow the attacker to perform denial of service attacks, bypass security restrictions, obtain sensitive information, gain elevated privileges, execute arbitrary code, and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Apple

Apple Security Updates – 03 April 2025 Read More »

Google Chrome Security Update – 03 April 2025

Google has released an updated Chrome version “135.0.7049.52” for Linux and version “135.0.7049.41/42” for Windows and Mac The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, gain elevated privileges, or access sensitive information through malicious web pages. Sample of the addressed vulnerabilities: 1. Google Chrome Use After Free in Navigations Vulnerability (CVE-2025-3066):

Google Chrome Security Update – 03 April 2025 Read More »

Mozilla FireFox Security Updates – 03 April 2025

Mozilla has released an updated Firefox version 137, Firefox ESR versions 128.9, and 115.2 to fix multiple vulnerabilities. The addressed vulnerabilities could allow the attacker to bypass security restrictions, conduct exploitable crashes, or execute arbitrary code and gain access to the affected systems. Sample of the addressed vulnerabilities:  1. Mozilla Firefox Sandbox Escape Vulnerability (CVE-2025-2857):

Mozilla FireFox Security Updates – 03 April 2025 Read More »

Cisco Security Updates – 03 April 2025

Cisco has released security updates to fix several vulnerabilities affecting multiple Cisco products. The addressed vulnerabilities could allow the attacker to conduct cross-site scripting attacks or perform denial of service attacks on the affected product. Sample of the addressed vulnerabilities: 1. Cisco Meraki MX and Z Series AnyConnect VPN Denial of Service Vulnerability (CVE-2025-20212): CVSS:

Cisco Security Updates – 03 April 2025 Read More »

Splunk Security Updates – 27 March 2025

Splunk has released security updates to fix multiple vulnerabilities affecting several Splunk products and third-party components. The addressed vulnerabilities could allow the attacker to bypass security restrictions, obtain sensitive information, gain elevated privileges, or execute arbitrary code and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Code Execution Vulnerability through File

Splunk Security Updates – 27 March 2025 Read More »

Google Chrome Security Update – 27 March 2025

Google has released an updated Chrome version “134.0.6998.177/.178” for Windows to fix a zero-day vulnerability. The addressed vulnerability could allow the remote attacker to bypass Chrome sandbox protections and infect systems with sophisticated malware. Google Chrome Browser’s Sandbox Security Bypass (CVE-2025-2783): CVSS: 8.3 Attack Vector: Network Attack Complexity: High Privileges Required: None User Interaction: Required

Google Chrome Security Update – 27 March 2025 Read More »

VMware Security Update – 26 March 2025

VMware has released a security update to fix a vulnerability across VMware Tools for Windows. The addressed vulnerability could allow the attacker with non-administrative privileges on a Windows guest VM to bypass security restrictions and gain the ability to perform certain high-privilege operations within that VM. VMware Tools Authentication Bypass Vulnerability (CVE-2025-22230): CVSS: 7.8 Attack

VMware Security Update – 26 March 2025 Read More »

Microsoft Edge Security Update – 23 March 2025

Microsoft has released an updated Microsoft Edge stable channel “134.0.3124.83” to address multiple vulnerabilities. The addressed vulnerabilities could allow the attacker to gain elevated privileges or execute arbitrary code and gain access to the affected systems by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: 1. Microsoft Edge (Chromium-based)

Microsoft Edge Security Update – 23 March 2025 Read More »

Veeam Security Update – 20 March 2025

Veeam has released a security update to fix a critical vulnerability across Veeam Backup & Replication systems. The addressed vulnerability could allow the remote attacker to execute arbitrary code and gain access to the affected system. Veeam Backup Arbitrary Code Execution Vulnerability (CVE-2025-23120): CVSS: 9.9 Attack Vector: Network Attack Complexity: Low Privileges Required: Low User

Veeam Security Update – 20 March 2025 Read More »

Apache Tomcat Security Update – 18 March 2025

Apache has released a security update to address a vulnerability affecting multiple versions of Apache Tomcat. The addressed vulnerability could allow the remote attacker to obtain sensitive information, manipulate data, or execute arbitrary code and gain access to the affected systems. Apache Tomcat Code Execution Vulnerability (CVE-2025-24813): CVSS: 8.6 Attack Vector: Network Attack Complexity: Low

Apache Tomcat Security Update – 18 March 2025 Read More »

Microsoft Edge Security Update – 13 March 2025

Microsoft has released an updated Microsoft Edge version “134.0.3124.66” to address multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to obtain sensitive information or execute arbitrary code and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: 1. Microsoft Edge Code

Microsoft Edge Security Update – 13 March 2025 Read More »

Fortinet Security Updates – 12 March 2025

Fortinet has released security updates to fix several vulnerabilities across multiple Fortinet products. The addressed vulnerabilities could allow the attacker to perform denial of service attacks, gain elevated privileges, obtain sensitive information, bypass security restrictions, conduct cross-site scripting attacks, conduct cross-site request forgery attacks, or execute arbitrary code and gain access to the affected product.

Fortinet Security Updates – 12 March 2025 Read More »