Alerts

Cisco Released Security Updates – 8 September 2022

Cisco has released security updates to address several vulnerabilities in multiple Cisco products. The remote attacker could exploit some of these vulnerabilities to take control of the affected system. The released updates to fix multiple vulnerabilities affecting Cisco devices if they are running a vulnerable release of Cisco SD-WAN vManage Software, Cisco Catalyst 8000V Edge […]

Cisco Released Security Updates – 8 September 2022 Read More »

Agenda New Golang Ransomware

Agenda is a new Golang-based ransomware detected in the wild targeting entities and enterprises in Asia, Africa, and the Middle East. Security researchers spotted this ransomware to be customized per victim. Security researchers have spotted a new ransomware dupped “Agenda” that was customized for each victim, and it was written in the Go programming language,

Agenda New Golang Ransomware Read More »

Google Chrome Security Updates – 31 August 2022

Google has released an updated Chrome version (105.0.5195.52/53/54) for Windows and (105.0.5195.52) for (Mac/Linux) to fix several vulnerabilities. The remote attacker could exploit these vulnerabilities to take control of the affected system and bypass security. The severity of the addressed vulnerabilities could allow the remote attacker to execute arbitrary code or cause a denial of

Google Chrome Security Updates – 31 August 2022 Read More »

Broadcom Symantec Security Updates – 30 August 2022

Broadcom Symantec has released security updates to address a new vulnerability. The remote attacker could exploit this vulnerability to take control of the affected system and gain elevated privileges. The addressed vulnerability could allow the attacker to gain access to affected PAMconfiguration endpoints with reading and writing permissions when multi-factor authentication (MFA) is enabled. Privileged

Broadcom Symantec Security Updates – 30 August 2022 Read More »

Cisco Released Security Updates – 25 August 2022

Cisco has released security updates to address several vulnerabilities in multiple Cisco products. The remote attacker could exploit some of these vulnerabilities to take control of the affected system. The released updates to fix multiple vulnerabilities affecting Cisco FXOS Software, Cisco NX-OS Software and Cisco ACI Multi-Site Orchestrator (MSO). The addressed vulnerabilities could allow the

Cisco Released Security Updates – 25 August 2022 Read More »

VMware Security Update – 24 August 2022

VMware has released a security update to address a vulnerability in VMware Tools. VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. The addressed vulnerability could allow the local non-administrative attacker to escalate privileges as a root user in the virtual machine. The Addressed vulnerability: VMware Tools Local Privilege Escalation Vulnerability (CVE-2022-31676):

VMware Security Update – 24 August 2022 Read More »

Mozilla Security Updates – 24 August 2022

Mozilla has released security updates to fix vulnerabilities in Firefox , Firefox ESR and Thunderbird. The remote attacker could exploit these vulnerabilities to gain access, escalate privileges, and bypass security controls. Sample of The Addressed Vulnerabilities: Mozilla Firefox security bypass (CVE-2022-38473): CVSS: 8.8 Attack Vector: Network Attack Complexity: Low Privileges Required: None User Interaction: Required

Mozilla Security Updates – 24 August 2022 Read More »

Apple macOS Security Updates – 18 August 2022

Apple has released security updates to address multiple vulnerabilities in the updated version of macOS Monterey 12.5.1. The remote attacker could exploit these vulnerabilities to take control of the affected system. The severity of the addressed vulnerabilities could allow the attackers to perform several attacks like elevating privileges, and executing arbitrary code on the affected

Apple macOS Security Updates – 18 August 2022 Read More »

FormBook Malware

FormBook is a data stealer and form grabber that was first advertised on HackForums in early 2016. The malware is associated with APT36, TEMP.Splinter and UNC2589 threat actors which target Financial Services FormBook is a self-extracting RAR file that starts an AutoIt loader. The AutoIt loader compiles and runs an AutoIt script. The script decrypts

FormBook Malware Read More »

Google Chrome Security Updates – 17 August 2022

Google has released an updated Chrome version (104.0.5112.101) for Windows, Mac and Linux to fix several vulnerabilities, including a zero-day flaw that is being exploited in the wild. The remote attacker could exploit these vulnerabilities to takecontrol of the affected system. The severity of the addressed vulnerabilities could allow the remote attacker to execute arbitrary code on

Google Chrome Security Updates – 17 August 2022 Read More »

Zoom Security Updates -14 August 2022

Zoom has released security updates to fix vulnerabilities across multiple products on Windows and macOS. The remote attacker could exploit these vulnerabilities to gain access, escalate privileges, and bypass security controls. Sample of The Addressed Vulnerabilities: Zoom Client for Meetings and VDI Windows Meeting Clients code execution (CVE-2022-28755): CVSS: 9.6 Attack Vector: Network Attack Complexity:

Zoom Security Updates -14 August 2022 Read More »

Yanluowang Ransomware 11 August 2022

Yanluowang is a targeted Ransomware for multiple critical infrastructure sectors, including the hardware, information technology, software, and high-tech sectors. Yanluowang was first discovered in mid-October 2021. Yanluowang group uses to publish the data stolen from ransomware victims. Yanluowang is ransomware that encrypts (and renames) files, ends all running processes, stops services, and creates the “README.txt”

Yanluowang Ransomware 11 August 2022 Read More »

SAP August 2022 Security Patch Day 11 August 2022

SAP has released security updates to address several vulnerabilities affecting multiple products. SAP also announced (2) updates to the previously released patch day security note. This month’s patch fixes several vulnerabilities affecting multiple SAP products such as SAP BusinessObjects Business Intelligence (Open Document, Monitoring DB, Commentary DB), SAP Enable Now Manager, SAP NetWeaver, and SAP

SAP August 2022 Security Patch Day 11 August 2022 Read More »

Phishing Campaign – 10 August 2022

EG-FinCIRT has detected a massive phishing campaign focused on collecting credentials of financial institutions’ employees. The detected phishing campaign targets the organizations’ employees by sending a phishing email from a newly created domain to ensure they have clean records to alert the targeted users about “E-mail Storage Full” and persuade them to enter their username

Phishing Campaign – 10 August 2022 Read More »

Tenable Nessus Released Security Updates – 11 August 2022

Tenable Nessus has released an updated version (Nessus 8.15.6) to fix multiple vulnerabilities. The remote attacker could exploit these vulnerabilities to execute commands with administrator privileges and read arbitrary files without providing any valid SSH credentials. The most severe of the addressed vulnerability could allow the remote attacker to trick the victim to open a

Tenable Nessus Released Security Updates – 11 August 2022 Read More »