Alerts

VMware Security Updates 18 December 2022

VMware has released security updates to fix vulnerabilities in VMware vRealize Operations (vROps). The severity of the addressed vulnerabilities could allow the remote authenticated attacker to gain privilege or obtain information from the affected products via sending specially-crafted requests. VMware vRealize Operations (vROps) privilege escalation vulnerability (CVE- 2022-31707): • CVSS: 7.2 • Attack Vector: Network • Attack Complexity: low […]

VMware Security Updates 18 December 2022 Read More »

Apple Security Updates 14 December 2022

Apple has released security updates to address multiple vulnerabilities in the updated version of macOS Big Sur 11.7.2, macOS Monterey 12.6.2, macOS Ventura 13.1, and Safari 16.2. In addition, the mentioned updates fix a zero-day vulnerability actively exploited in the wild. The severity of the addressed vulnerabilities could allow the remote attacker to gainaccess to sensitive information, bypass

Apple Security Updates 14 December 2022 Read More »

Aruba Security Updates 14 December 2022

Aruba has released security updates to fix vulnerabilities across multiple Aruba products. The severity of the addressed vulnerabilities could allow the remote attacker to execute code, obtain information, and bypass security controls. Samples of the addressed vulnerabilities: 1- Privilege Escalation Aruba EdgeConnect Enterprise Orchestrator Web-based Management Interface (CVE-2022-44535): • CVSS: 8.8 • Attack Vector: Network • Attack

Aruba Security Updates 14 December 2022 Read More »

VMware Security Updates 14 December 2022

VMware has released security updates to fix vulnerabilities across multiple products. severity of the addressed vulnerabilities could allow the remote attacker to execute arbitrary commands via specially crafted requests to gain access and obtain information from the affected products. Sample of the addressed vulnerabilities: 1. VMware vRealize Network Insight command execution (CVE-2022-31702) • CVSS: 9.8 • Attack Vector:

VMware Security Updates 14 December 2022 Read More »

Google Chrome Security Updates 14 December 2022

Google has released an updated Chrome version (108.0.5359.124/.125) for Windows and (108.0.5359.124) for Mac and Linux to fix multiple vulnerabilities in its Chrome desktop web browser. The severity of the addressed vulnerability could allow the remote attacker to bypass security restrictions by creating a specially crafted web page to execute arbitrary code on the affected system. Sample of the

Google Chrome Security Updates 14 December 2022 Read More »

Cisco Security Update 14 December 2022

Cisco has released a security update to fix a vulnerability in Cisco Identity Services Engine (ISE). The addressed vulnerability could allow the remote authenticated attacker to traverse directories on the system; The attacker could send a specially-crafted URL request containing “dot dot” sequences (/../) to read or delete arbitrary files on the system. Cisco Identity Services Engine (ISE) directory

Cisco Security Update 14 December 2022 Read More »

Mozilla FireFox Security Updates 14 December 2022

Mozilla has released security updates to fix vulnerabilities in Firefox 108 and Firefox ESR 102.6. The addressed vulnerabilities could allow the remote attacker to gain access to sensitive information, perform spoofing attacks, bypass security restrictions, execute arbitrary code and cause a denial of service attack on the affected products. Successful exploitation of these vulnerabilities may

Mozilla FireFox Security Updates 14 December 2022 Read More »

VMware Security Updates 13 December 2022

VMware has released security updates to fix a zero-day vulnerability across multiple products. The addressed vulnerability could allow the attacker with local administrative privileges on a virtual machine to execute code to gain access to the affected products. Heap out-of-bounds write vulnerability in EHCI controller (CVE-2022-31705) • CVSS: 9.3 • Attack Vector: Local • Attack Complexity:

VMware Security Updates 13 December 2022 Read More »

Citrix Security Updates 13 December 2022

Citrix has released security updates to fix a critical zero-day vulnerability in Citrix ADC and Citrix Gateway. The severity of the addressed vulnerability could allow the remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests to gain access to the affected products. Citrix ADC and Gateway code execution (CVE-2022-27518): • CVSS: 9.8

Citrix Security Updates 13 December 2022 Read More »

IBM Security Updates 13 December 2022

IBM has released security updates to fix third-party components vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to gain access, obtain information and cause a denial of service attack on the affected products. Sample of the addressed Vulnerabilities : 1. IBM InfoSphere Information Server Apache Commons Text code execution (CVE-2022-42889) • CVSS: 9.8

IBM Security Updates 13 December 2022 Read More »

SAP December 2022 Security Patch Day

SAP has released security updates to address several vulnerabilities affecting multiple products. In addition, SAP also announced (4) updates to the previously released patch day security notes. This month’s patch fixes several vulnerabilities affecting multiple SAP products such as SAP BusinessObjects Business Intelligence Platform (Web intelligence) and (Program Objects), SAP NetWeaver Process Integration, SAP Commerce, SAP

SAP December 2022 Security Patch Day Read More »

Fortinet Security Updates – 13 December 2022

Fortinet has released security updates to fix a critical zero-day vulnerability in FortiOS and FortiOS-6k7k. The addressed vulnerability could allow the remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests to gain access to the affected product. FortiOS heap-based buffer overflow in sslvpnd (CVE-2022-42475): • CVSS: 9.3 • Attack Vector: Network •

Fortinet Security Updates – 13 December 2022 Read More »

VMware Security Updates 11 December 2022

VMware has released security updates to fix multiple vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to execute arbitrary code, obtain information and cause a denial of service attack on the affected products. Samples of the addressed vulnerabilities: 1- VMware ESXi memory corruption vulnerability (CVE-2022-31696): CVSS: 7.5 Attack Vector: Local Attack Complexity: High

VMware Security Updates 11 December 2022 Read More »

DeathStalker Newly Janicab Variant – 11 December 2022

DeathStalker targets Financial and legal entities in the Middle East with a new Janicab malware variant. Janicab was introduced as malware that runs on macOS and Windows operating systems. DeathStalker has leveraged several malware strains and delivery chains over the years, from the Python and Visual Basic-based Janicab to the PowerShell-based Powersing and the JavaScript-based Evilnum. The

DeathStalker Newly Janicab Variant – 11 December 2022 Read More »

TrueBot Malware 11 December 2022

Silence APT group targets financial institutions in several countries around the world through delivering TrueBot malware which leveraging of Netwrix Auditor critical RCE Bug and Raspberry Robin worm. TrueBot was first identified in 2017 as downloader malware, the main goal is to infect systems, collect information to help triage interesting targets, and deploy additional payloads. Security Researchers

TrueBot Malware 11 December 2022 Read More »

Zerobot Malware – 08 December 2022

Zerobot is a Go-Based Malware that has been observed targeting devices like F5 Big-IP, Zyxel Firewalls, spring4Shell, and phpMyAdmin with almost two dozen vulnerability exploits. The Botnet’s objective is to add compromised devices to its pool to launch DDoS attacks and execute arbitrary commands.  The malware targets several system architecures including i386, AMD64, ARM, ARM64,

Zerobot Malware – 08 December 2022 Read More »

Fortinet Security Updates – 07 December 2022

Fortinet has released security updates to address multiple vulnerabilities across multiple products.  The addressed vulnerabilities could allow the remote attacker to gain access, log manipulation, and retrieve files with specific extensions from the affected products. These security updates fix several vulnerabilities affecting multiple Fortinet products such as FortiADC, FortiProxy, FortiOS, FortiSOAR, FortiDeceptor, and FortiSandbox. Sample

Fortinet Security Updates – 07 December 2022 Read More »