Announcements

EG-FinCIRT Acquires the Membership of OIC-CERT

EG-FinCIRT Acquires the Membership of OIC-CERT A New Testimony on the CBE’s Compliance and Implementation of the Highest International Cybersecurity Standards The Computing Incident Response Team for the Financial Sector (EG-FinCIRT) of the Central Bank of Egypt (CBE) has successfully obtained the membership of the Organization of Islamic Cooperation – Computer Emergency Response Teams (OIC-CERT), […]

EG-FinCIRT Acquires the Membership of OIC-CERT Read More »

Oracle Security Patch Update – 18 January 2024

Oracle released its critical patch update for January 2024, containing (389) new security patches for multiple affected products in Oracle code and third-party components included in Oracle products. The addressed vulnerabilities could allow the attacker to perform various attacks such as obtaining sensitive information, performing denial of service attacks, bypassing security restrictions, executing arbitrary code, and

Oracle Security Patch Update – 18 January 2024 Read More »

VMware Security Update – 16 January 2024

VMware has released a security update to address a critical vulnerability across VMware Aria Automation (formerly vRealize Automation), and VMware Cloud Foundation (Aria Automation). The addressed vulnerability could allow the authenticated attacker to gain unauthorized access to remote organizations and workflows. VMware Aria Automation Missing Access Control Vulnerability (CVE-2023-34063): CVSS: 9.9 Attack Vector: Network Attack

VMware Security Update – 16 January 2024 Read More »

Trend Micro Security Update – 14 January 2024

Trend Micro has released a security update to address several vulnerabilities across Trend Micro Apex Central. The addressed vulnerabilities could allow the remote attacker to trigger cross-site scripting attacks, obtain sensitive information, or execute arbitrary code and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Trend Micro Apex Central Server-Side Request

Trend Micro Security Update – 14 January 2024 Read More »

Juniper Security Updates – 11 January 2024

Juniper has released security updates to fix several vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to obtain sensitive information, cause a denial of service attack, bypass security restrictions, gain elevated privileges, or execute arbitrary code and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Juniper Junos OS

Juniper Security Updates – 11 January 2024 Read More »

Ivanti Security Updates – 11 January 2024

Ivanti has released security updates to fix two zero-day vulnerabilities across Ivanti Connect Secure (ICS) and Ivanti Policy Secure. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, and bypass security restrictions on the affected systems by sending a specially crafted request. The addressed vulnerabilities: 1. Ivanti ICS and Ivanti Policy Secure

Ivanti Security Updates – 11 January 2024 Read More »

ManageEngine Security Updates – 09 January 2024

ManageEngine has released security updates to address a critical vulnerability across multiple product builds till 127259. The addressed vulnerability could allow the remote authenticated attacker to traverse directories by sending a specially crafted URL request containing “dot dot” sequences (/../) to create arbitrary files on the affected systems. ManageEngine OpManager Directory Traversal Vulnerability (CVE-2023-47211): CVSS:

ManageEngine Security Updates – 09 January 2024 Read More »

Apache Security Updates – 27 December 2023

Apache has released security updates to address several vulnerabilities across multiple versions of Apache OFBiz. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, and gain access to the affected system by sending a specially crafted request. Sample of the addressed vulnerabilities: Apache Pre-authentication Remote Code Execution (CVE-2023-51467): CVSS: 9.8 Attack Vector:

Apache Security Updates – 27 December 2023 Read More »

Barracuda Security Update – 26 December 2023

Barracuda has released a security update to address two zero-day vulnerabilities across multiple versions of Email Security Gateway (ESG) appliances. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code within a third-party library “Spreadsheet::ParseExcel” on the affected system of Barracuda ESG Appliance by deploying a specially crafted Excel email attachment. Sample of

Barracuda Security Update – 26 December 2023 Read More »

Ivanti Security Updates – 21 December 2023

Ivanti has released security updates to fix multiple vulnerabilities affecting all supported versions of Ivanti Avalanche. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, gain access, perform server-side request forgery (SSRF), or trigger denial of services attacks on the affected products. Sample of the addressed vulnerabilities: 1. Ivanti Wavelink Avalanche Premise

Ivanti Security Updates – 21 December 2023 Read More »

Fortinet Security Updates 13 December 2023

Fortinet has released security updates to fix multiple vulnerabilities across several products. The addressed vulnerabilities could allow the attacker to bypass security restrictions, obtain sensitive information, or execute arbitrary code, and gain access to the affected products. Sample of the addressed vulnerabilities: 1. FortiMail Remote Wildcard RADIUS Login Bypass (CVE-2023-47539): CVSS: 9 Attack Vector: Network

Fortinet Security Updates 13 December 2023 Read More »

Apple Security Updates – 12 December 2023

Apple has released security updates to address multiple vulnerabilities across macOS Monterey, Ventura, Sonoma and Safari. The addressed vulnerabilities could allow the attacker to bypass security restrictions, gain elevated privileges, obtain sensitive information, execute arbitrary code, and gain access to the affected systems by persuading the victim to visit a specially crafted website. Sample of

Apple Security Updates – 12 December 2023 Read More »

Microsoft Edge Security Update – 10 December 2023

Microsoft has released the latest Microsoft Edge Stable Channel (Version 120.0.2210.61) to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, bypass security, gain elevated privileges, or disclose sensitive information on the affected system. Sample of the addressed vulnerabilities: Microsoft Edge (Chromium-based) Elevation of Privilege (CVE-2023-35618): CVSS: 9.6 Attack

Microsoft Edge Security Update – 10 December 2023 Read More »

Atlassian Security Updates – 06 December 2023

Atlassian has released security updates to address several vulnerabilities across multiple products. The addressed vulnerabilities could allow the remote attacker to conduct denial of service attacks, obtain sensitive information, or execute arbitrary code, and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Atlassian Assets Discovery Remote Code Execution (CVE-2023-22523): CVSS: 9.8

Atlassian Security Updates – 06 December 2023 Read More »

Tenable Security Update – 04 December 2023

Tenable has released a security update to fix multiple vulnerabilities in Tenable’s third-party components (OpenSSL, HandlebarsJS, jquery-file-upload) across Nessus Network Monitor 6.3.0 and earlier versions. The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, execute arbitrary code, and gain access to the affected system by sending a specially crafted request. Sample of

Tenable Security Update – 04 December 2023 Read More »

VMware Security Update – 03 December 2023

VMware has released a security update to address a critical vulnerability in the VMware Cloud Director Appliance (VCD Appliance). The addressed vulnerability could allow the remote attacker to bypass login restrictions when authenticating on port 22 (SSH) or port 5480 (appliance management console) to the affected system. VMware Cloud Director Appliance Security Bypass (CVE-2023-34060): CVSS:

VMware Security Update – 03 December 2023 Read More »