Alerts

Palo Alto Security Updates – 09 April 2026

Palo Alto has released security updates to fix several vulnerabilities affecting multiple Palo Alto products. The addressed vulnerabilities could allow the attacker to perform a denial of service attack, bypass security restrictions, obtain sensitive information, execute arbitrary commands, or bypass the authentication and gain access to the affected product. Sample of the addressed vulnerabilities: 1. […]

Palo Alto Security Updates – 09 April 2026 Read More »

Mozilla Firefox Security Updates – 08 April 2026

Mozilla has released an updated Firefox version 149.0.2, Firefox ESR versions 115.34.1 and 140.9.1 to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code and corrupt memory that could lead to full compromise of the affected system. Sample of the addressed vulnerabilities: Mozilla Firefox and Firefox ESR Memory Safety

Mozilla Firefox Security Updates – 08 April 2026 Read More »

Microsoft Security Updates – 05 April 2026

Microsoft has released security updates to address several vulnerabilities affecting multiple Microsoft products. The addressed vulnerabilities could allow the attacker to gain elevated privileges or obtain sensitive information from the affected systems. Sample of the addressed vulnerabilities: 1. Azure AI Foundry Elevation of Privilege Vulnerability (CVE-2026-32213): CVSS: 10 Attack Vector: Network Attack Complexity: Low Privileges

Microsoft Security Updates – 05 April 2026 Read More »

Fortinet Security Update – 05 April 2026

Fortinet has released a security update to address a critical vulnerability affecting FortiClient EMS versions 7.4.5 through 7.4.6 The addressed vulnerability could allow the remote attacker to gain elevated privileges, execute unauthorized code or commands via crafted requests, and gain access to the affected systems. FortiClient EMS API Authentication and Authorization Bypass Vulnerability (CVE- 2026-35616):

Fortinet Security Update – 05 April 2026 Read More »

Supply Chain Attack of Axios NPM package – 02 April 2026

A supply chain attack targeted the Axios NPM package, a widely used HTTP client in the JavaScript and Node.js ecosystem. Malicious versions of the package were published to the official npm repository. When installed, these versions resulted in the deployment of a cross-platform Remote Access Trojan (RAT) affecting Windows, Linux, and macOS systems. On March

Supply Chain Attack of Axios NPM package – 02 April 2026 Read More »

Cisco Security Updates – 02 April 2026

Cisco has released security updates to fix several vulnerabilities across multiple Cisco products. The addressed vulnerabilities could allow the attacker to bypass authentication and security restrictions, execute arbitrary commands or code, gain elevated privileges, obtain sensitive information, conduct cross-site scripting and serverside request forgery attacks, manipulate files, and gain access to the affected systems. Sample

Cisco Security Updates – 02 April 2026 Read More »

Google Chrome Security Update – 02 April 2026

Google has released an updated Chrome version 146.0.7680.177/178 for Windows/Mac and 146.0.7680.177 for Linux. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, cause memory corruption, read out-of-bounds memory, corrupt objects, cause integer overflows, or bypass security and policy restrictions across multiple browser components by persuading the victim to visit a maliciously

Google Chrome Security Update – 02 April 2026 Read More »

Ivanti Endpoint Manager Mobile (EPMM) Compromise Assessment – 01 April 2026

Investigation confirmed successful web shell execution following the exploitation of Ivanti zero-day vulnerabilities (CVE-2026-1340 and CVE-2026-1281) on multiple organizations’ internet-facing Ivanti Endpoint Manager Mobile (EPMM) servers. Reference to Alert No. 18, “Ivanti Security Update – 01 February 2026”, EGFinCIRT requests a comprehensive Compromise Assessment for Ivanti Endpoint Manager Mobile (EPMM) servers. Attackers might take advantage

Ivanti Endpoint Manager Mobile (EPMM) Compromise Assessment – 01 April 2026 Read More »

Grafana Security Updates – 31 March 2026

Grafana has released security updates to fix several vulnerabilities across multiple Grafana products. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, bypass authorization controls, disclose sensitive datasource configurations, perform cross-site scripting (XSS) attacks via Grafana Explore, or cause denial-ofservice attacks on the affected systems. Sample of the addressed vulnerabilities: 1. RCE

Grafana Security Updates – 31 March 2026 Read More »

F5 Security Update – 26 March 2026

F5 has released a security update to address several vulnerabilities affecting multiple F5 products. The addressed vulnerabilities could allow the attacker to perform denial-of-service (DoS) attacks, bypass security restrictions, execute arbitrary code or modify data by injecting arbitrary headers into SMTP upstream requests. Sample of the addressed vulnerabilities: 1. NGINX Worker Process Buffer Overflow Vulnerability

F5 Security Update – 26 March 2026 Read More »

Cisco Security Updates – 26 March 2026

Cisco has released security updates to fix several vulnerabilities across multiple Cisco products. The addressed vulnerabilities could allow the attacker to execute arbitrary code, gain elevated privileges, obtain sensitive information, bypass security restrictions, conduct cross-site scripting, and perform denial-of-service attacks on the affected systems. Sample of addressed vulnerabilities: 1. Cisco IOS, IOS XE, Secure Firewall

Cisco Security Updates – 26 March 2026 Read More »

Apple Security Updates – 24 March 2026

Apple has released security updates to address multiple vulnerabilities across macOS Tahoe, Sequoia, Sonoma, and Safari. The addressed vulnerabilities could allow the attacker to perform denial-ofservice attacks, bypass security restrictions, corrupt memory, execute arbitrary code, and gain unauthorized access to the affected systems, potentially leading to compromise of system integrity and overall security posture. Sample

Apple Security Updates – 24 March 2026 Read More »

Microsoft Security Updates – 24 March 2026

Microsoft has released security updates to address several vulnerabilities affecting multiple Microsoft products. The addressed vulnerabilities could allow the attacker to gain elevated privileges, obtain sensitive information, perform spoofing attacks, bypass security restrictions, or execute arbitrary code and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Microsoft Azure Cloud Shell Elevation

Microsoft Security Updates – 24 March 2026 Read More »

Google Chrome Security Updates – 24 March 2026

Google has released an updated Chrome version 146.0.7680.164/165 for Windows/Mac and 146.0.7680.164 for Linux. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, cause memory corruption, or bypass security restrictions by persuading the victim to visit a malicious website. Sample of the addressed vulnerabilities: 1. Google Chrome Out of Bounds Memory Access

Google Chrome Security Updates – 24 March 2026 Read More »

Oracle Security Update – 24 March 2026

Oracle has released a security update to fix a critical vulnerability affecting Oracle Identity Manager and Oracle Web Services Manager versions 12.2.1.4.0 and 14.1.2.1.0. The addressed vulnerability could allow the remote attacker to execute arbitrary code without authentication and gain access to the affected systems. Oracle Identity Manager and Oracle Web Services Manager Unauthenticated Remote

Oracle Security Update – 24 March 2026 Read More »

Citrix Security Update – 24 March 2026

Citrix has released a security update to address vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway. The addressed vulnerabilities could allow the attacker to obtain sensitive memory contents, including authentication tokens, cryptographic keys, or user credentials, or gain unauthorized access to the affected systems, leading to a user session mixup where one user’s session

Citrix Security Update – 24 March 2026 Read More »

GNU InetUtils Security Update – 18 March 2026

GNU InetUtils has addressed a critical vulnerability affecting all versions of the Telnet service implementation through 2.7. The addressed vulnerability could allow the remote attackers to perform out-ofbounds writes on systems running vulnerable versions of GNU inetutils telnetd, potentially leading to arbitrary code execution, full system compromise, or denial of service. GNU Inetutils Remote Pre-Auth

GNU InetUtils Security Update – 18 March 2026 Read More »

Splunk Security Updates – 15 March 2026

Splunk has released security updates to fix several vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. The addressed vulnerabilities could allow the attacker to execute arbitrary shell commands, obtain sensitive information, conduct cross-site scripting attacks, and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. Splunk Enterprise Remote Command Execution Vulnerability (CVE-2026-20163):

Splunk Security Updates – 15 March 2026 Read More »

Veeam Security Updates – 15 March 2026

Veeam has released security updates to fix several vulnerabilities across Veeam Backup & Replication version 13.0.1.1071 and all earlier version 13 builds and version 12.3.2.4165 and all earlier version 12 builds. The addressed vulnerabilities could allow the attacker to bypass security restrictions, manipulate repository files, extract stored credentials, escalate privileges, or execute arbitrary code, and

Veeam Security Updates – 15 March 2026 Read More »