Skip to main content

CND News and Blog

New Vulnerabilities Wednesday 23 October

New Alerts for Google Chrome, Fortinet (Exploit), IBM, Shibboleth, and Linux. Google  Google has updated Chrome for Desktop to fix 3 security vulnerabilities, all rated High.More info. Fortinet Exploit FGFM has vulnerabilities that can be chained and used for exploits.More info. IBM  IBM Storage Protect Server is susceptible to multiple v...

0
  302 Hits

New Vulnerabilities Tuesday 22 October

New Alert for Linux. Linux  Oracle Linux has updated the kernel. More info.Mageia has updated systemd. More info. Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securitywizardry.com/ Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page A mobile version of our Security Wizardry Radar Page, providing vu...

0
  286 Hits

New Vulnerabilities Monday 21 October

New Alerts for Moxa, SICK, HP, Endress+Hauser, IBM, Dell, and Linux. Moxa  NE-4100, MiiNePort E1, MiiNePort E2, and MiiNePort E3 contain a vulnerability that allows a remote attacker to retrieve administration passwords without proper authentication. CVSSv3 score of 9.8More info. SICK  A critical vulnerability has been discovered in the ....

0
  377 Hits

New Vulnerabilities Friday 18 October

New Alerts for Microsoft Edge, Synology, Kieback&Peter, Spring, Belden, OPC Foundation, Hikvision, Moxa, and NetApp. Microsoft  Microsoft has updated Edge to include the latest chromium fixes and 9 Edge-specific vulnerabilities.More info. Synology  Synology Camera BC500, TC500, and CC400W contain vulnerabilities that allow remote atta...

0
  409 Hits

New Vulnerabilities Thursday 16 October

New Alerts for Cisco, Mitsubishi Electric, Meinberg, Elvaco, LCDS, and Linux. Cisco  Cisco has published 3 new bulletins. Highest CVSSv3 score of 8.2More info.Multiple vulnerabilities in Cisco ATA 190 Series Analog Telephone Adapter firmwarecould allow a remote attacker to delete or change the configuration, execute commands as the root user, ...

0
  261 Hits

New Vulnerabilities Wednesday 16 October

Monthly Patches are out for Google Pixel. New Alerts for Google Chrome, SolarWinds, Microsoft, HP, Bosch, IBM, and Linux. Google  Google has updated Chrome for Desktop to fix 17 security vulnerabilities.More info.Google has published the Monthly Patches for Pixel, with 29 vulnerabilities and patches for Android.More info. SolarWinds  Sola...

0
  384 Hits

New Vulnerabilities Tuesday 15 October

Quarterly Patches are out for Splunk, and will be out shortly for Oracle. New Alerts for TAI, MB Connect, Helmholz, Kubernetes, Mbed TLS, BD, Mozilla Firefox, and Linux. Oracle  Oracle Quarterly Patches are expected out this afternoon. The pre-release lists 329 new security patches, 204 of which are remotely exploitable without authentication....

0
  414 Hits

New Vulnerabilities Monday 14 October

New Alerts for Mozilla Thunderbird, Moxa, and NetApp. Mozilla  Thunderbird has been updated to fix a critical vulnerability.More info. Moxa  Moxa's cellular routers, secure routers, and network security appliances are affected by two critical vulnerabilities that could lead to unauthorized access and system compromise. Highest CVSSv4 scor...

0
  285 Hits

New Vulnerabilities Friday 11 October

New Alerts for Wireshark, Microsoft Edge, HPE, Rockwell Automation, IBM, Dell, and Linux. Oracle Quarterly Patches are next week, the pre-release notice is out, here. Wireshark  Wireshark has been updated to fix 2 DoS vulnerabilities. CVSSv3 score of 7.5More info. Microsoft  Microsoft has updated Edge with the latest chromium updates.More...

0
  386 Hits

New Vulnerabilities Thursday 10 October

Monthly Patches are out for Palo Alto Networks and Juniper Networks. New Alerts for Progress, PEPPERL+FUCHS, GitLab, Ruckus, and Linux. Palo Alto Networks  Monthly Patches include 7 bulletins, 1 rated Critical, 2 rated High, and 4 rated Medium. Highest CVSSv4 score of 9.9More info.Multiple vulnerabilities in Expedition allow a remote attacker ...

0
  361 Hits

New Vulnerabilities Wednesday 09 October

Monthly Patches are out for Microsoft, Adobe, and Ivanti. New Alerts for Mozilla, Rockwell Automation, Mitel, and Linux. Microsoft  Monthly Patches include 117 vulnerabilities, 3 are rated Critical, 5 have been previously disclosed, 2 of those are being exploited. Updates include the latest chromium updates for Edge.More info. And here. And he...

0
  271 Hits

New Vulnerabilities Tuesday 08 October

Monthly Patches are out for Google Android, Samsung, SAP, Siemens, and Schneider Electric. New Alert for Phoenix Contact. Monthly Patches will be out for Microsoft and Adobe this afternoon. Google  Monthly Patches for Android include 9 vulnerabilities, all rated High, plus updates from Imagination Technologies, MediaTek, and Qualcomm. More inf...

0
  393 Hits

New Vulnerabilities Monday 07 October

Monthly Patches are out for Qualcomm and MediaTek. New Alerts for Moxa, NetApp, IBM, Dell, and Linux. Tomorrow is Patch Tuesday for at least 7 vendors. Qualcomm  Monthly Patches include 20 vulnerabilities, 1 rated Critical, 12 rated High, and 7 rated Medium. Highest CVSSv3 score of 9.8More info. MediaTek  Monthly Security Bulletin include...

0
  351 Hits

New Vulnerabilities Friday 04 October

New Alerts for Delta Electronics, Subnet Solutions, TEM, Xerox, Microsoft Edge, CUPS, and Linux. Delta Electronics  DIAEnergie contains a SQL Injection vulnerability that could allow a remote attacker to retrieve records or cause a DoS. Highest CVSSv4 score of 9.3More info. And here. Subnet Solutions  PowerSYSTEM Center contains several v...

0
  374 Hits

New Vulnerabilities Thursday 03 October

New Alerts for PowerDNS, WithSecure, Cisco, Flexera, DrayTek, and Linux. PowerDNS  An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for these sets can lead to a DoS. CVSSv3 score of 7.5More info. WithSecure  A DoS vulnerability was discovered in WithSecure Atlant Product th...

0
  310 Hits

New Vulnerabilities Wednesday 02 October

New Alerts for Google Chrome, Mitsubishi Electric, Optigo Networks, Mozilla, Bosch, and Linux. Google  Google has updated Chrome for Desktop to fix 4 security vulnerabilities.More info. Mitsubishi Electric  A DoS vulnerability due to OpenSSL vulnerability exists in MELSEC iQ-F OPC UA Unit. A remote attacker could cause DoS by getting a le...

0
  313 Hits

New Vulnerabilities Tuesday 01 October

New Alerts for Diffie-Hellman, Splunk, Hitachi, F5, IBM, and Juniper Networks. Diffie-Hellman  D(HE)at Attack allows a remote attacker to overheat the CPU with computations, resulting in a DoS.More info. Splunk  Splunk has updated the plug-in for AWS to fix a DoS.More info. Hitachi  Cosminexus Component Container has been updated to ...

0
  300 Hits

New Vulnerabilities Monday 30 September

New Alerts for CUPS, Microsoft Edge, HPE, Atelmo, Progress What's Up Gold, Synology and Linux. CUPS  Linux CUPS has a chain of vulnerabilities that can be used to achieve RCE. Patches are rolling out in the various distros.More info. And here. Microsoft  Microsoft has updated Edge with the latest chromium updates.More info. HPE  Secu...

0
  404 Hits

New Vulnerabilities Thursday 26 September

New Alerts for Cisco, BD, IBM, NetApp, GitLab, PHP, Veritas, Franklin Fueling, and Linux. Cisco  Cisco has published 15 new bulletins, 8 rated High and 7 rated Medium. Updates for IOS and IOS XE Software, Catalyst SD-WAN Routers, Catalyst Center, Catalyst 9000, and SD-WAN vEdge. Highest CVSSv3 score of 8.6More info. BD  BD has published t...

0
  358 Hits

New Vulnerabilities Wednesday 25 September

New Alerts for Nessus, Google Chrome, HPE, WatchGuard, Dover Fueling, Alisonic, OMNTEC, RAISECOM, and Linux. Nessus  Nessus Network Monitor has been updated to fix vulnerabilities in third-party software. Highest CVSSv3 core of 9.8More info. Google  Google has updated Chrome for Desktop to fix 5 security vulnerabilities.More info. HPE&nbs...

0
  446 Hits

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/