Announcements

Microsoft October 2022 Patch Tuesday

Microsoft has released its monthly patch of security updates, known as Patch Tuesday, which fixestwo publicly zero-day vulnerabilities, one actively exploited in attacks and one publicly disclosed. Microsoft has fixed (84) vulnerabilities (not including Microsoft Edge vulnerabilities), with (13) classified as Critical as they allow privilege elevation, spoofing, or remote code execution. October’s Patch Tuesday […]

Microsoft October 2022 Patch Tuesday Read More »

Fortinet Released Security Updates – 10 October 2022

Fortinet has released security updates to address multiple vulnerabilities across multiple products. The remote attacker could exploit some of these vulnerabilities to take control of the affected system. The highest severity of the addressed vulnerabilities could allow the attacker to execute arbitrary commands in the underlying shell due to multiple improper neutralization of special elements

Fortinet Released Security Updates – 10 October 2022 Read More »

Trend Micro Released Security Updates – 09 October 2022

Trend Micro has released a new critical patch to address several vulnerabilities in Trend Micro Apex One SP1 and Apex One SaaS. The released security updates resolve several vulnerabilities having severity ratings from medium to critical. The remote attacker could exploit some of these vulnerabilities to gain privileged access to the affected system. Samples of the

Trend Micro Released Security Updates – 09 October 2022 Read More »

Fortinet Released Security Updates – 09 October 2022

Fortinet has released security patches to fix a critical authentication bypass vulnerability across multiple products.  The mentioned vulnerability could allow the remote attacker to bypass security restrictions by sending specially crafted HTTP or HTTPS requests to log into unpatched devices and perform operations on the administrative interface. Fortinet FortiOS and Fortinet FortiProxy security bypass (CVE-2022-40684): •

Fortinet Released Security Updates – 09 October 2022 Read More »

Microsoft Exchange Zero-Day Actively Exploited in Attacks

Security researchers have detected Microsoft Exchange zero-day vulnerabilities allowing for remote code execution. These vulnerabilities are so critical that they enable the attackers to perform RCE on the compromised systems when Powershell is accessible. Microsoft has identified two zero-day vulnerabilities, CVE-2022-41040 (Server Side Request Forgery (SSRF)) and CVE-2022-41082 (Remote Code Execution (RCE)), affecting Microsoft Exchange Server

Microsoft Exchange Zero-Day Actively Exploited in Attacks Read More »

VMware Security Update – 24 August 2022

VMware has released a security update to address a vulnerability in VMware Tools. VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. The addressed vulnerability could allow the local non-administrative attacker to escalate privileges as a root user in the virtual machine. The Addressed vulnerability: VMware Tools Local Privilege Escalation Vulnerability (CVE-2022-31676):

VMware Security Update – 24 August 2022 Read More »

FormBook Malware

FormBook is a data stealer and form grabber that was first advertised on HackForums in early 2016. The malware is associated with APT36, TEMP.Splinter and UNC2589 threat actors which target Financial Services FormBook is a self-extracting RAR file that starts an AutoIt loader. The AutoIt loader compiles and runs an AutoIt script. The script decrypts

FormBook Malware Read More »

Zoom Security Updates -14 August 2022

Zoom has released security updates to fix vulnerabilities across multiple products on Windows and macOS. The remote attacker could exploit these vulnerabilities to gain access, escalate privileges, and bypass security controls. Sample of The Addressed Vulnerabilities: Zoom Client for Meetings and VDI Windows Meeting Clients code execution (CVE-2022-28755): CVSS: 9.6 Attack Vector: Network Attack Complexity:

Zoom Security Updates -14 August 2022 Read More »

Microsoft August 2022 Patch Tuesday

Microsoft has released its monthly patch of security updates, known as Patch Tuesday, which fixes two zero-day vulnerabilities, one actively exploited known as “DogWalk”, and several critical Exchange vulnerabilities. Microsoft has fixed (121) vulnerabilities (not including Microsoft Edge vulnerabilities), with (17) classified as Critical as they allow remote code execution or elevation of privileges. August

Microsoft August 2022 Patch Tuesday Read More »

RedLine Stealer Malware 04 August 2022

RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware. Redline Stealer is malware as a service credential stealer targeting windows operation systems, with the capability of stealing credentials from web browsers, files, and FTP applications. RedLine also collects extensive

RedLine Stealer Malware 04 August 2022 Read More »

VMware Releases Security Updates 3 August 2022

VMware has released a security advisory to address critical vulnerabilities which affect multiple VMware products. The remote attacker could exploit some of these vulnerabilities to take control of the affected system. The addressed vulnerabilities could allow the attackers to perform several attacks like bypassing security restrictions, redirecting a victim to arbitrary websites, directory traversal, cross-site

VMware Releases Security Updates 3 August 2022 Read More »

Adobe Security Updates

Adobe has released security updates to address vulnerabilities affecting Adobe Acrobat and Reader. The remote attacker could exploit these vulnerabilities to gain access and disclose information on the affected system. The security updates addresses vulnerabilities in the following products: Acrobat DC, Acrobat Reader DC, Acrobat 2020, Acrobat Reader 2020, Acrobat 2017,and Acrobat Reader 2017. Sample

Adobe Security Updates Read More »