Announcements

ConnectWise Security Updates – 21 February 2024

ConnectWise has released security updates to fix multiple vulnerabilities across ConnectWise ScreenConnect 23.9.7 and prior. The addressed vulnerabilities could allow the remote attacker to bypass security restrictions and obtain administrative access, or traverse directories and obtain sensitive information by sending a specially crafted URL request containing “dot dot” sequences (/../) to view arbitrary files on […]

ConnectWise Security Updates – 21 February 2024 Read More »

VMware Security Updates – 21 February 2024

VMware has released security updates to address several vulnerabilities in multiple VMware products. The addressed vulnerabilities could allow the attacker to bypass security restrictions to request and relay service tickets for arbitrary Active Directory Service Principal Names (SPNs), or hijack the user’s session cookie to hijack a privileged EAP session, or gain elevated privileges to

VMware Security Updates – 21 February 2024 Read More »

SolarWinds Security Updates – 16 February 2024

SolarWinds has released security updates to address several vulnerabilities affecting SolarWinds Platform and SolarWinds Access Rights Manager (ARM). The addressed vulnerabilities could allow the attacker to bypass security restrictions, or execute arbitrary code and gain access to the affected products by sending a specially crafted request. Sample of the addressed vulnerabilities: 1. SolarWinds Access Rights

SolarWinds Security Updates – 16 February 2024 Read More »

Zoom Security Updates – 14 February 2024

Zoom has released security updates to fix several vulnerabilities in multiple products such as Zoom Clients, Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. The addressed vulnerabilities could allow the attacker to obtain sensitive information, trigger denial of service attacks, gain elevated privileges, execute arbitrary code, and

Zoom Security Updates – 14 February 2024 Read More »

Microsoft February 2024 Patch Tuesday

Microsoft has released its monthly patch of security updates, known as Patch Tuesday. The mentioned patch addressed two actively exploited zero-day vulnerabilities. Microsoft has fixed (73) vulnerabilities, with (5) classified as critical as they could allow the attacker to perform denial of service attacks, gain elevated privileges, obtain sensitive information, or remote code execution on

Microsoft February 2024 Patch Tuesday Read More »

Adobe Security Updates – 14 February 2024

Adobe has released security updates to fix several vulnerabilities across multiple Adobe products. The addressed vulnerabilities could allow the attacker to bypass security restrictions, obtain sensitive information, trigger denial of services attacks, execute arbitrary code, and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Adobe Commerce Code Execution Vulnerability (CVE-2024-20719): CVSS:

Adobe Security Updates – 14 February 2024 Read More »

Report Summary SAP February 2024 Security Patch Day

SAP has released security updates to address several vulnerabilities affecting multiple products. SAP has released a patch that fixes several vulnerabilities affecting multiple SAP products such as SAP ABA, SAP NetWeaver AS Java, SAP CRM WebClient UI, SAP IDES Systems, SAP Cloud Connector, SAP GUI, SAP Bank Account Management, SAPCompanion, SAP NetWeaver Application Server ABAP

Report Summary SAP February 2024 Security Patch Day Read More »

Ivanti Security Updates – 10 February 2024

Ivanti has released security updates to a zero-day vulnerability across multiple versions of Ivanti Connect Secure, Policy Secure, and ZTA products. The addressed vulnerability could allow the remote attacker to gain access to restricted resources on unpatched appliances in low-complexity attacks without requiring user interaction or authentication to the affected systems. The addressed vulnerability: Ivanti

Ivanti Security Updates – 10 February 2024 Read More »

Fortinet Security Updates – 09 February 2024

Fortinet has released security updates to fix several vulnerabilities across multiple Fortinet products. The addressed vulnerabilities could allow the remote attacker to perform denial of service attacks, conduct cross-site scripting attacks, gain elevated privileges, obtain sensitive information, execute arbitrary code, and gain access to the affected products by sending specially crafted HTTP requests. Sample of

Fortinet Security Updates – 09 February 2024 Read More »

Cisco Security Updates – 08 February 2024

Cisco has released security updates to fix several vulnerabilities across multiple Cisco products. The addressed vulnerabilities could allow the remote attacker to conduct crosssite scripting attacks, cause web cache poisoning by persuading the authenticated user to visit a malicious website, or perform denial of service attacks by submitting a crafted file containing OLE2 content to

Cisco Security Updates – 08 February 2024 Read More »

Juniper Security Updates – 04 February 2024

Juniper has released security updates to fix multiple vulnerabilities affecting Juniper Secure Analytics (JSA) Applications. The addressed vulnerabilities could allow the attacker to obtain sensitive information, manipulate files, trigger cross-site scripting, perform denial of service attacks, or execute arbitrary code and gain access to the affected products. Sample of the addressed vulnerabilities: Juniper Netlib LAPACK

Juniper Security Updates – 04 February 2024 Read More »

Symantec Security Vulnerabilities – 30 January 2024

Symantec has published several critical vulnerabilities in end-of-life versions across multiple products. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code or cause a buffer overflow and gain access to the affected products by sending specially crafted requests or persuading the victim to open a crafted document. Sample of the addressed vulnerabilities:

Symantec Security Vulnerabilities – 30 January 2024 Read More »

Microsoft Edge Security Update – 28 January 2024

Microsoft has released an updated Microsoft Edge Stable Channel (121.0.2277.83) and Microsoft Edge Extended Stable Channel (120.0.2210.160) to fix multiple vulnerabilities. The addressed vulnerabilities could allow the attacker to gain elevated privilege, bypass security restrictions, execute arbitrary code, and gain access to the affected system by persuading the victim to open a malicious file. Sample

Microsoft Edge Security Update – 28 January 2024 Read More »

Cisco Security Updates – 25 January 2024

Cisco has released security updates to fix several vulnerabilities across multiple Cisco products.  The addressed vulnerabilities could allow the attacker to bypass security restrictions, gain elevated privileges, trigger cross-site scripting attacks, or execute arbitrary code and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Cisco Unified Communications Products Remote Code Execution

Cisco Security Updates – 25 January 2024 Read More »

Fortra Security Update – 24 January 2024

Fortra has released a security update to address a critical vulnerability in multiple versions of Fortra GoAnywhere MFT (Managed File Transfer). The addressed vulnerability could allow the unauthorized remote attacker to create admin users via the administration portal which could lead to a complete device takeover, access sensitive data, introduce malware, and potentially enable further

Fortra Security Update – 24 January 2024 Read More »

Atlassian Security Update – 22 January 2024

Atlassian has released a security update to address a critical vulnerability in Atlassian Confluence Data Center and Server out-of-date versions (8.0.x, 8.1.x, 8.2.x, 8.3.x, 8.4.x, 8.5.0-8.5.3). The addressed vulnerability is described as a template injection weakness that could allow the unauthenticated remote attacker to execute arbitrary code and gain access to the affected system. Atlassian

Atlassian Security Update – 22 January 2024 Read More »

EG-FinCIRT Acquires the Membership of OIC-CERT

EG-FinCIRT Acquires the Membership of OIC-CERT A New Testimony on the CBE’s Compliance and Implementation of the Highest International Cybersecurity Standards The Computing Incident Response Team for the Financial Sector (EG-FinCIRT) of the Central Bank of Egypt (CBE) has successfully obtained the membership of the Organization of Islamic Cooperation – Computer Emergency Response Teams (OIC-CERT),

EG-FinCIRT Acquires the Membership of OIC-CERT Read More »

Oracle Security Patch Update – 18 January 2024

Oracle released its critical patch update for January 2024, containing (389) new security patches for multiple affected products in Oracle code and third-party components included in Oracle products. The addressed vulnerabilities could allow the attacker to perform various attacks such as obtaining sensitive information, performing denial of service attacks, bypassing security restrictions, executing arbitrary code, and

Oracle Security Patch Update – 18 January 2024 Read More »

VMware Security Update – 16 January 2024

VMware has released a security update to address a critical vulnerability across VMware Aria Automation (formerly vRealize Automation), and VMware Cloud Foundation (Aria Automation). The addressed vulnerability could allow the authenticated attacker to gain unauthorized access to remote organizations and workflows. VMware Aria Automation Missing Access Control Vulnerability (CVE-2023-34063): CVSS: 9.9 Attack Vector: Network Attack

VMware Security Update – 16 January 2024 Read More »

Trend Micro Security Update – 14 January 2024

Trend Micro has released a security update to address several vulnerabilities across Trend Micro Apex Central. The addressed vulnerabilities could allow the remote attacker to trigger cross-site scripting attacks, obtain sensitive information, or execute arbitrary code and gain access to the affected system. Sample of the addressed vulnerabilities: 1. Trend Micro Apex Central Server-Side Request

Trend Micro Security Update – 14 January 2024 Read More »