Alerts

Fortinet Released Security Updates – 09 October 2022

Fortinet has released security patches to fix a critical authentication bypass vulnerability across multiple products.  The mentioned vulnerability could allow the remote attacker to bypass security restrictions by sending specially crafted HTTP or HTTPS requests to log into unpatched devices and perform operations on the administrative interface. Fortinet FortiOS and Fortinet FortiProxy security bypass (CVE-2022-40684): • […]

Fortinet Released Security Updates – 09 October 2022 Read More »

Cisco Released Security Updates – 08 October 2022

Cisco has released security updates to address several vulnerabilities in multiple Cisco products The severity of the addressed vulnerabilities could allow the attacker to fully compromise the Cisco NFVIS system and cause a denial of service. Samples of the addressed vulnerabilities: 1. Cisco Enterprise NFV Infrastructure Software (NFVIS) code execution (CVE 2022-20929): • CVSS: 7.8 •

Cisco Released Security Updates – 08 October 2022 Read More »

Microsoft Edge Security Update – 04 October 2022

Microsoft has released an updated version of Microsoft Edge (Version 106.0.1370.34) to fix a vulnerability in Microsoft Edge. The remote attacker could exploit this vulnerability to take control of the affected system. The severity of the addressed vulnerability could allow the remote attacker to exploit this vulnerability by persuading a victim to visit a specially crafted Web

Microsoft Edge Security Update – 04 October 2022 Read More »

Drupal Security Update 02 October 2022

The Twig third-party library for content templating and sanitization has released a security update that affects Drupal versions (8.0.0 to 9.3.22, 9.4.0 to 9.4.7). The severity of the addressed vulnerability could allow an untrusted user to access private files, the contents of other files on the server, or database credentials.The remote attacker could exploit this vulnerability

Drupal Security Update 02 October 2022 Read More »

Microsoft Exchange Zero-Day Actively Exploited in Attacks

Security researchers have detected Microsoft Exchange zero-day vulnerabilities allowing for remote code execution. These vulnerabilities are so critical that they enable the attackers to perform RCE on the compromised systems when Powershell is accessible. Microsoft has identified two zero-day vulnerabilities, CVE-2022-41040 (Server Side Request Forgery (SSRF)) and CVE-2022-41082 (Remote Code Execution (RCE)), affecting Microsoft Exchange Server

Microsoft Exchange Zero-Day Actively Exploited in Attacks Read More »

SolarWinds Released Security Updates – 29 September 2022

SolarWinds has released security updates to address multiple vulnerabilities in SolarWinds Orion Platform “2022.2 and earlier”, and Hybrid Cloud Observability NCM “2020.2.5 and previous versions”. The addressed vulnerabilities could be exploited to allow the remote attacker to perform SQL injection or stored and DOM-based cross-site scripting attacks. Sample of the addressed vulnerabilities: 1. SQL Injection

SolarWinds Released Security Updates – 29 September 2022 Read More »

Google Chrome Security Updates-28 September 2022

Google has released an updated Chrome version (106.0.5249.61/62) for Windows and (106.0.5249.61) for Mac and Linux to fix multiple vulnerabilities. The remote attacker could exploit some of these vulnerabilities to take control of the affected system. The severity of the addressed vulnerabilities could allow the remote attacker to execute arbitrary code, bypass security restrictions by

Google Chrome Security Updates-28 September 2022 Read More »

Trend Micro Security Update – 14 September 2022

Trend Micro has released a new service pack for Apex One product that resolves multiple vulnerabilities in the product.  The addressed vulnerabilities could allow the remote attacker to perform several attacks, like bypassing security restrictions, elevating privileges, and causing a denial of service on the affected system. Sample of addressed vulnerabilities :  1 -Trend Micro

Trend Micro Security Update – 14 September 2022 Read More »

Zoom Security Updates – 14 September 2022

Zoom has released security updates to fix vulnerabilities in Zoom On-Premise Meeting Connector (MMR) products. The remote attacker could exploit these vulnerabilities to obtain information from the affected system. The severity of the addressed vulnerabilities could allow the remote attacker to obtain sensitive information, caused by improper access control and use this information to launch

Zoom Security Updates – 14 September 2022 Read More »

SAP September 2022 Security Patch Day

SAP has released security updates to address several vulnerabilities affecting multiple products. In addition, SAP also announced (5) updates to the previously released patch day security note. This month’s patch fixes several vulnerabilities affecting multiple SAP products such as SAP Business One, SAP BusinessObjects Business Intelligence Platform, SAP Access Control, SAP NetWeaver Enterprise Portal (KMC),

SAP September 2022 Security Patch Day Read More »

Cuba Ransomware – 08 September 2022

Cuba is a ransomware family that appends the .cuba file extension to encrypted files. When executed this malware terminates services associated with common server applications and encrypts files on the local filesystem and attached network drives using an embedded RSA key. Cuba ransomware operation has increased its activity recently and started to target financial organizations

Cuba Ransomware – 08 September 2022 Read More »

Cisco Released Security Updates – 8 September 2022

Cisco has released security updates to address several vulnerabilities in multiple Cisco products. The remote attacker could exploit some of these vulnerabilities to take control of the affected system. The released updates to fix multiple vulnerabilities affecting Cisco devices if they are running a vulnerable release of Cisco SD-WAN vManage Software, Cisco Catalyst 8000V Edge

Cisco Released Security Updates – 8 September 2022 Read More »

Agenda New Golang Ransomware

Agenda is a new Golang-based ransomware detected in the wild targeting entities and enterprises in Asia, Africa, and the Middle East. Security researchers spotted this ransomware to be customized per victim. Security researchers have spotted a new ransomware dupped “Agenda” that was customized for each victim, and it was written in the Go programming language,

Agenda New Golang Ransomware Read More »

Google Chrome Security Updates – 31 August 2022

Google has released an updated Chrome version (105.0.5195.52/53/54) for Windows and (105.0.5195.52) for (Mac/Linux) to fix several vulnerabilities. The remote attacker could exploit these vulnerabilities to take control of the affected system and bypass security. The severity of the addressed vulnerabilities could allow the remote attacker to execute arbitrary code or cause a denial of

Google Chrome Security Updates – 31 August 2022 Read More »

Broadcom Symantec Security Updates – 30 August 2022

Broadcom Symantec has released security updates to address a new vulnerability. The remote attacker could exploit this vulnerability to take control of the affected system and gain elevated privileges. The addressed vulnerability could allow the attacker to gain access to affected PAMconfiguration endpoints with reading and writing permissions when multi-factor authentication (MFA) is enabled. Privileged

Broadcom Symantec Security Updates – 30 August 2022 Read More »