Announcements

FreeBSD Security Update – 09 November 2023

FreeBSD systems have released a security update to address multiple vulnerabilities in FreeBSD libc and FreeBSD libcap_net. The addressed vulnerabilities could allow the remote attacker to overflow a buffer, execute arbitrary code, and gain access to the affected system by sending a specially crafted request. Sample of the addressed vulnerabilities: FreeBSD buffer overflow (CVE-2023-5941): CVSS: […]

FreeBSD Security Update – 09 November 2023 Read More »

WS_FTP Security Update – 09 November 2023

WS_FTP has released a security update to address a critical vulnerability affecting WS_FTP Server. The addressed vulnerability could allow the remote attacker to bypass security restrictions and upload a file to a specified location on the operating system hosting the WS_FTP Server application. WS_FTP Server Arbitrary File Upload (CVE-2023-42659): CVSS: 9.1 Attack Vector: Network Attack

WS_FTP Security Update – 09 November 2023 Read More »

Veeam Security Update – 07 November 2023

Veeam has released a security update to fix several vulnerabilities in Veeam ONE IT infrastructure monitoring and analytics platform versions 11, 11a, and 12. The addressed vulnerabilities could allow the attacker to obtain sensitive information, perform cross-site scripting attacks, execute arbitrary code, and gain access to the affected system. Sample of the addressed vulnerabilities: 1.

Veeam Security Update – 07 November 2023 Read More »

Cisco Security Updates – 02 November 2023

Cisco has released security updates to fix several vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to bypass security restrictions, obtain sensitive information, conduct cross-site scripting or perform denial of service attacks, execute arbitrary commands, and gain access to the affected system by sending a specially crafted HTTP request. Sample of the

Cisco Security Updates – 02 November 2023 Read More »

Atlassian Security Update – 31 October 2023

Atlassian has released a security update to address a critical vulnerability across all versions of Confluence Data Center and Confluence Server products. The addressed vulnerability could allow the unauthenticated remote attacker to cause significant data loss on the vulnerable Confluence Data Center and Server but there is no impact to confidentiality as the attacker cannot

Atlassian Security Update – 31 October 2023 Read More »

F5 Security Updates – 28 October 2023

F5 has released security updates to fix multiple vulnerabilities across multiple products. The addressed vulnerabilities could allow the remote attacker to perform denial of service attacks, launch SQL injection attacks, execute arbitrary commands, and gain access to the affected products by sending specially crafted requests. Sample of the addressed vulnerabilities: 1. F5 BIG-IP Command Execution

F5 Security Updates – 28 October 2023 Read More »

VMware Security Updates – 25 October 2023

VMware has released security updates to fix multiple vulnerabilities affecting VMware vCenter Server, and VMware Cloud Foundation. The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, execute arbitrary code, and gain access to the affected system by sending specially crafted requests. Sample of the addressed vulnerabilities: VMware vCenter Server Out-of-Bounds Write Vulnerability

VMware Security Updates – 25 October 2023 Read More »

Fortinet Security Updates – 15 October 2023

Fortinet has released security updates to address vulnerabilities affecting multiple products. The addressed vulnerabilities could allow the attacker to gain access, perform cross-site scripting attacks, steal the victim’s cookie-based authentication credentials, or traverse directories on the affected systems by sending specially crafted URL requests. Sample of the addressed vulnerabilities: 1. Fortinet FortiSIEM Directory Traversal Vulnerability

Fortinet Security Updates – 15 October 2023 Read More »

F5 Security Updates – 11 October 2023

F5 has released security updates to fix several vulnerabilities across multiple versions of F5 BIG-IP, BIG-IP (APM), and F5 BIG-IP Next SPK. The addressed vulnerabilities could allow the attacker to gain access, execute arbitrary commands, perform denial of service attacks, obtain sensitive information, bypass security restrictions, or gain elevated privileges on the affected systems by

F5 Security Updates – 11 October 2023 Read More »

Fortinet Security Updates – 11 October 2023

Fortinet has released security updates to address vulnerabilities affecting multiple products. The addressed vulnerabilities could allow the attacker to cause a denial of service, gain elevated privileges, disclose information, execute arbitrary commands, and gain access to the affected systems. Sample of the addressed vulnerabilities: 1. FortiSIEM – Remote Unauthenticated OS Command Injection Vulnerability (CVE-2023-34992): CVSS:

Fortinet Security Updates – 11 October 2023 Read More »

Citrix Security Updates – 11 October 2023

Citrix has released security updates to address multiple vulnerabilities across Citrix NetScaler ADC and NetScaler Gateway. The addressed vulnerabilities could allow the remote unauthenticated attacker to trigger a denial of service attack or obtain sensitive information from the affected product if configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or an

Citrix Security Updates – 11 October 2023 Read More »

Atlassian Security Update – 05 October 2023

Atlassian has released a security update to address a critical vulnerability across multiple products. The addressed vulnerability could allow the remote attacker to gain elevated privileges on the system, caused by an error related to the /setup/* endpoints on Confluence instances allowing the creation of administrator accounts that can be used to access Confluence instances. Atlassian

Atlassian Security Update – 05 October 2023 Read More »

Cisco Security Updates – 05 October 2023

Cisco has released security updates to fix several vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to execute arbitrary commands, gain elevated privileges, gain access to the affected products, or perform denial of service attacks by sending a specially crafted HTTP request to a specific API. Sample of the addressed vulnerabilities: 1.

Cisco Security Updates – 05 October 2023 Read More »

WS_FTP Security Updates – 01 October 2023

WS_FTP has released security updates to address vulnerabilities affecting WS_FTP Server Ad hoc Transfer Module and the WS_FTP Server Manager Interface. The addressed vulnerabilities could allow the remote attacker to execute arbitrary commands, perform cross-site scripting attacks, or gain access to the affected systems. Sample of the addressed vulnerabilities: 1. WS_FTP Server Command Execution Vulnerability

WS_FTP Security Updates – 01 October 2023 Read More »

Cisco Security Updates – 28 September 2023

Cisco has released security updates to fix several vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to execute arbitrary commands, perform denial of service attacks, bypass security restrictions, or gain access to the affected products by various techniques such as sending specially crafted input to the web UI or sending requests directly

Cisco Security Updates – 28 September 2023 Read More »

Trend Micro Security Updates – 20 September 2023

Trend Micro has released security updates to address a critical zero-day vulnerability across Trend Micro Apex One (on-premise, SaaS), Trend Micro Worry-Free Business Security, and Trend Micro Worry-Free Business Security SaaS. The addressed vulnerability could allow the remote authenticated attacker toexecute arbitrary code on the affected system. Trend Micro Endpoint Security Products Code Execution (CVE-2023-41179):

Trend Micro Security Updates – 20 September 2023 Read More »

SAP September 2023 Security Patch Day

SAP has released security updates to address several vulnerabilities affecting multiple products. In addition, SAP also announced (5) updates to the previously released patch day security notes. This month’s patch fixes several vulnerabilities affecting multiple SAP products such as SAP Business Objects Business Intelligence Platform (Promotion Management), SAP CommonCryptoLib, SAP PowerDesignerClient, SAP Quotation Management Insurance

SAP September 2023 Security Patch Day Read More »

Cisco Security Updates – 07 September 2023

Cisco has released security updates to fix multiple vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to gain access, execute arbitrary code, bypass security restrictions, gain elevated privileges, or perform denial of service attacks on the affected products by sending a specially crafted request. Sample of the addressed vulnerabilities: 1. Cisco BroadWorks

Cisco Security Updates – 07 September 2023 Read More »