Alerts

Barracuda Security Update – 31 May 2023

Barracuda has released a security update to address a zero-day vulnerability across Email Security Gateway (ESG) appliances versions 5.1.3.001-9.2.0.006. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code on the system with the privileges of the Email Security Gateway product by attaching a specially crafted TAR archive file in the email and gain […]

Barracuda Security Update – 31 May 2023 Read More »

VMware Security Updates – 31 May 2023

VMware has released security updates to fix multiple vulnerabilities across multiple Vmware products. The addressed vulnerabilities could allow the remote attacker to perform cross-site scripting attacks, or disclose sensitive information from the affected products using a specially crafted URL to redirect the victim to the attacker-controlled domain. Sample of the addressed vulnerabilities: VMware Insecure Redirect

VMware Security Updates – 31 May 2023 Read More »

Google Chrome Security Update – 31 May 2023

Google has released an updated Chrome version (114.0.5735.90/91) for Windows and (114.0.5735.90) for Linux and Mac to fix multiple vulnerabilities. Write here analysis sectionThe addressed vulnerabilities could allow the remote attacker to gain access, execute arbitrary code on the system, or bypass security restrictions by persuading the victim to visit a specially crafted webpage. Sample

Google Chrome Security Update – 31 May 2023 Read More »

Apache Security Update – 23 May 2023

Apache has released a security update to address a vulnerability in Apache Tomcat. The addressed vulnerability could allow the remote attacker to cause a denial of service by sending a specially crafted request using query string parameters. Apache Tomcat Denial of Service Vulnerability (CVE-2023-28709): CVSS: 7.5 Attack Vector: Network Attack Complexity: Low Privileges Required: None

Apache Security Update – 23 May 2023 Read More »

Apple Security Updates – 21 May 2023

Apple has released security updates to address multiple vulnerabilities across macOS Ventura, macOS Monterey, macOS Big Sur, and Safari. The mentioned updates contain fixes for three zero-day vulnerabilities. The addressed vulnerabilities could allow the attacker to gain access, escalate privileges, bypass security restrictions, obtain information, or execute arbitrary code on the affected systems. Sample of

Apple Security Updates – 21 May 2023 Read More »

Cisco Security Updates – 18 May 2023

Cisco released security updates to address several vulnerabilities affecting multiple Cisco products. The addressed vulnerabilities could allow the attacker to execute arbitrary code, gain access, bypass security restrictions, escalate privileges, obtain sensitive information, or cause a denial of service attack on the affected systems. Sample of the addressed vulnerabilities: Cisco Small Business Series Switches Buffer

Cisco Security Updates – 18 May 2023 Read More »

Trend Micro Security Updates – 17 May 2023

Trend Micro has released security updates to fix multiple vulnerabilities across Apex One and Apex Central. The addressed vulnerabilities could allow the attacker to gain access, gain elevated privileges, or obtain sensitive information from the affected products. Sample of the addressed vulnerabilities: 1. Management Server Path Traversal Unauthenticated RCE Vulnerability (CVE-2023-32557): CVSS: 9.8 Attack Vector:

Trend Micro Security Updates – 17 May 2023 Read More »

VMware Security Update – 14 May 2023

VMware has released a security update to fix multiple vulnerabilities across VMware Aria Operations (formerly vRealize Operations) and VMware Cloud Foundation. addressed vulnerabilities could allow the authenticated attacker to gain elevated privileges on the affected system by sending a specially crafted request. Sample of the addressed vulnerabilities: VMware Aria Operations Privilege Escalation (CVE-2023-20877): CVSS: 8.8

VMware Security Update – 14 May 2023 Read More »

Palo Alto Security Updates – 11 May 2023

Palo Alto has released security updates addressing vulnerabilities in multiple products. The addressed vulnerabilities could allow the attacker to store a JavaScript payload in the web interface or export local files from the firewall through a race condition. The addressed vulnerabilities: 1. Stored Cross-Site Scripting (XSS) Vulnerability in the Panorama WebInterface (CVE-2023-0007): CVSS: 6.5 Attack

Palo Alto Security Updates – 11 May 2023 Read More »

Intel Security Updates – 10 May 2023

Intel has released security updates to fix several vulnerabilities in multiple products. addressed vulnerabilities could allow the attacker to escalate privileges, obtain sensitive information, or cause a denial of service attack on the affected products. Sample of the addressed vulnerabilities: 1- Intel i915 Graphics Drivers for Linux Privilege Escalation (CVE-2023-28410): CVSS: 8.8 Attack Vector: Local

Intel Security Updates – 10 May 2023 Read More »

Citrix Security Updates – 10 May 2023

Citrix has released security updates to address several vulnerabilities in Citrix ADC and Citrix Gateway. The addressed vulnerabilities could allow the remote attacker to gain unauthorized access to the system, or perform a cross-site scripting attack to steal the victim’s cookie-based authentication credentials. The addressed vulnerabilities: 1. Citrix ADC and Gateway Unauthorized Access (CVE-2023-24487): CVSS: 6.3

Citrix Security Updates – 10 May 2023 Read More »

Mozilla FireFox Security Updates – 10 May 2023

Mozilla has released security updates to fix vulnerabilities in Firefox 113, and Firefox ESR 102.11 The addressed vulnerabilities could allow the remote attacker to gain access, obtain sensitive information, conduct a spoofing attack, bypass security restrictions, execute arbitrary code, or cause a denial of service attack on the affected products. Sample of the addressed vulnerabilities:

Mozilla FireFox Security Updates – 10 May 2023 Read More »

Microsoft May 2023 Patch Tuesday

Microsoft has released its monthly patch of security updates, known as Patch Tuesday. The mentioned patch contains a fix for three zero-day vulnerabilities. Microsoft has fixed (38) vulnerabilities, with (6) classified as critical as they could allow the attacker to perform remote code execution on the affected products. May’s Patch Tuesday was released to fix security flaws in some

Microsoft May 2023 Patch Tuesday Read More »

SAP May 2023 Security Patch Day

SAP has released security updates to address several vulnerabilities affecting multiple products. In addition, SAP also announced (6) updates to the previously released patch day security notes. This month’s patch fixes several vulnerabilities affecting multiple SAP products such as SAP 3D Visual Enterprise License Manager, SAP BusinessObjects Intelligence Platform, SAP AS NetWeaver JAVA, SAP IBP

SAP May 2023 Security Patch Day Read More »

Microsoft Edge Security Update – 07 May 2023

Microsoft has released an updated Edge version (113.0.1774.35) to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to conduct spoofing attacks, bypass security restrictions, or gain Privileges on the affected systems by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: Microsoft Edge (Chromium-based) Privilege Escalation (CVE-2023-29350):

Microsoft Edge Security Update – 07 May 2023 Read More »

Cisco Phone Vulnerable To RCE Attacks – 07 May 2023

Cisco has disclosed a vulnerability in the web-based management interface of Cisco SPA112 2-Port phone adapters. The addressed vulnerability could allow the remote attacker to execute arbitrary code on the affected device with full privileges by upgrading the affected device to a crafted version of the firmware. The addressed vulnerability: Cisco SPA112 2-Port Phone Adapters

Cisco Phone Vulnerable To RCE Attacks – 07 May 2023 Read More »