Alerts

Tenable Security Update 01 February 2023

Tenable has released a security update to fix a critical vulnerability in multiple products. The mentioned vulnerability could allow the authenticated remote attacker to escalate privileges by modifying environment variables and abusing the impacted plugin on the affected system. Tenable.io, Tenable.sc, and Nessus Privilege Escalation (CVE-2023-0524): CVSS: 9.1 Attack Vector: Network Attack Complexity: Low Privileges Required: High User […]

Tenable Security Update 01 February 2023 Read More »

QNAP Security Update 31 January 2023

QNAP has released a security update to address a critical vulnerability across QNAP QTS and QNAP QuTS hero. The severity of the addressed vulnerability could allow the remote unauthenticated attacker to inject and execute malicious code on the affected systems by sending specially crafted requests. QNAP running QTS and running QTS code execution (CVE-2022-27596): CVSS: 9.8 Attack Vector:

QNAP Security Update 31 January 2023 Read More »

Google Chrome Security Update 25 January 2023

Google has released an updated Chrome version (109.0.5414.119/.120) for Windows, and (109.0.5414.119) for Linux and Mac to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code or cause a denial of service on the vulnerable system, by persuading the victim to visit a specially crafted webpage. Sample of the addressed vulnerabilities: Google Chrome

Google Chrome Security Update 25 January 2023 Read More »

VMware Security Updates 25 January 2023

VMware has released security updates to fix multiple vulnerabilities in VMware vRealize Log Insight. The severity of the addressed vulnerabilities could allow the remote attacker to gain access, cause a denial of service attack, or obtain information from the affected systems. Sample of the addressed vulnerabilities: 1. VMware vRealize Log Insight Broken Access Control Vulnerability (CVE-2022-31704): • CVSS:

VMware Security Updates 25 January 2023 Read More »

ManageEngine Security Updates 25 January 2023

ManageEngine has released security updates to address multiple vulnerabilities across multiple products. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions, manipulate data, or obtain information from the affected system. Sample of the addressed vulnerabilities: 1. ManageEngine ServiceDesk Plus MSP Security Bypass Vulnerability (CVE-2023-22964): • CVSS: 8.1 • Attack Vector: Network • Attack Complexity: High

ManageEngine Security Updates 25 January 2023 Read More »

Microsoft Edge Security Update 24 January 2023

Microsoft has released an updated Microsoft Edge stable version to fix multiple vulnerabilities in Microsoft Edge (Chromium-based). The severity of the addressed vulnerabilities could allow the remote attacker to bypass security restrictions or gain elevated privileges on the affected system. Sample of the addressed vulnerabilities: 1. Microsoft Edge Elevation of Privilege Vulnerability (CVE-2023-21795): • CVSS: 8.3 •

Microsoft Edge Security Update 24 January 2023 Read More »

Apple Security Updates 24 January 2023

Apple has released security updates to address multiple vulnerabilities in the updated version of macOS Big Sur 11.7.3, macOS Monterey 12.6.3, macOS Ventura 13.2, and Safari 16.3. The severity of the addressed vulnerabilities could allow the attacker to execute arbitrary code on the affected system by mounting a maliciously crafted Samba network share or persuading a victim to open

Apple Security Updates 24 January 2023 Read More »

Tenable Nessus Security Updates 22 January 2023

Tenable Nessus has released updated versions (Nessus 10.4.2, 8.15.8) to fix a privilege escalation vulnerability. The mentioned vulnerability could allow the authenticated attacker to execute a specially crafted file to obtain root or NT AUTHORITY/SYSTEM privileges on the affected Nessus host. Tenable Nessus Privilege Escalation Vulnerability (CVE-2023-0101): • CVSS: 9.1 • Attack Vector: Network • Attack Complexity: Low

Tenable Nessus Security Updates 22 January 2023 Read More »

Cisco Security Updates 19 January 2023

Cisco has released security updates to address several vulnerabilities in multiple Cisco products. The released security updates fix several vulnerabilities affecting multiple Cisco products such as Cisco (Unified CM) and (Unified CM SME) and Email Security Appliance (ESA). The severity of the addressed vulnerability in the web-based management interface could allow the remote attacker to bypass security restrictions, conduct SQL

Cisco Security Updates 19 January 2023 Read More »

Mozilla Firefox Security Updates 18 January 2023

Mozilla has released security updates to fix vulnerabilities in Firefox 109 and Firefox ESR 102.7. The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, perform spoofing attacks, bypass security restrictions, execute arbitrary code and gain access to the affected products. Successful exploitation of these vulnerabilities may result in a complete compromise of vulnerable systems. Sample of

Mozilla Firefox Security Updates 18 January 2023 Read More »

Raccoon Stealer Malware 18 January 2023

Raccoon is a Trojan malware written in C/C++ that steals information and cryptocurrency from infected users. It is being used as Malware-as-a-service (MaaS) on underground forums by Ukrainian-speaking sellers. Raccoon enables threat actors to steal sensitive information, including credit card details, home addresses, phone numbers, email accounts, and login credentials from infected systems. The Tactics and Techniques of Raccoon

Raccoon Stealer Malware 18 January 2023 Read More »

Oracle Security Patch Updates January 2023

Oracle released its critical patch updates for January 2023, containing (327) new security patches for multiple affected products. The remote attacker could exploit some of these vulnerabilities to take control of the affected system. This critical patch update provides security updates to fix several vulnerabilities that may be remotely exploitable without authentication in a wide range of product families,

Oracle Security Patch Updates January 2023 Read More »

ManageEngine Security Update 17 January 2023

ManageEngine has released a security update to address a critical vulnerability affecting multiple products. The severity of the addressed vulnerability could allow the remote attacker to execute arbitrary code on the system by sending a specially-crafted request. It should be highlighted that the admins of ManageEngine were warned about a proof-of-concept (POC) that has been created to exploit

ManageEngine Security Update 17 January 2023 Read More »

Microsoft Edge Security Update 15 January 2023

Microsoft has released an updated Microsoft Edge Stable version (109.0.1518.49) to fix multiple vulnerabilities in Microsoft Edge (Chromium-based). The addressed vulnerabilities could allow the remote attacker to gain elevated privileges or execute arbitrary code on the affected system by persuading the victim to visit a specially-crafted webpage. Sample of the addressed vulnerabilities: 1. Chromium Remote Code Execution Vulnerability

Microsoft Edge Security Update 15 January 2023 Read More »

Cisco Security Updates 12 January 2023

Cisco has released security updates to address several vulnerabilities in multiple Cisco products. The released security updates fix several vulnerabilities affecting multiple Cisco products such as RV016, RV042, RV042G, and RV082 Routers, IP Phone 7800 and 8800 Series, Industrial Network Director (IND), and Cisco Webex Room Phone. The addressed vulnerabilities could allow the attacker to send a specially

Cisco Security Updates 12 January 2023 Read More »

Juniper Networks Security Updates 12 January 2023

Juniper Networks has released security updates to address several vulnerabilities affecting multiple products. Juniper Networks Junos OS and Junos OS Evolved are vulnerable to a denial of service. The remote attacker could exploit some of these vulnerabilities to crash the application by sending a specially-crafted request. Sample of the addressed vulnerabilities: Juniper Networks Junos OS and Junos

Juniper Networks Security Updates 12 January 2023 Read More »

Vidar Stealer Malware 12 January 2023

Vidar is a trojan malware based on a project called Arkei written in the C++ programming language that steals information and cryptocurrency from infected users. It is being used as malware-as-a-service on underground forums by Russianspeaking sellers. The Vidar stealer enables the threat actors to collect a wide range of information from compromised systems including Web browser cookies, history,

Vidar Stealer Malware 12 January 2023 Read More »

Adobe Security Updates 11 January 2023

Adobe has released security updates for Adobe Acrobat and Reader for Windows and macOS. These updates address critical and important vulnerabilities. The severity of the addressed vulnerabilities could allow the remote attacker to execute arbitrary code or cause a denial of service on the affected system. Sample of the addressed vulnerabilities: 1. Adobe Acrobat and Adobe Reader

Adobe Security Updates 11 January 2023 Read More »

Google Chrome Security Update 11 January 2023

Google has released an updated Chrome version (109.0.5414.74/.75) for Windows, (109.0.5414.74) for Linux, and (109.0.5414.87) for Mac to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, bypass security restrictions, or cause a denial of service on the vulnerable system, by persuading the victim to visit a specially crafted webpage. Sample of the

Google Chrome Security Update 11 January 2023 Read More »