Skip to main content

CND News and Blog

New Vulnerabilities Tuesday 16 January

Oracle Quarterly Patches are out this afternoon. New Alerts for Atlassian and Citrix. Oracle  Oracle's Quarterly Critical Patch Update is out today, pre-release notice reports 387 new security patches, 243 remotely exploitable without authentication. Highest CVSSv3 score of 9.8The Pre-release announcement becomes the regular announcement, so t...

0
  599 Hits

New Vulnerabilities Monday 15 January

New Alert for Linux. Tomorrow Oracle Quarterly Critical Patch Update is out. Linux  CentOS 7 has updated the kernel-firmware. More info. Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securitywizardry.com/ Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page A mobile version of our Security Wizardry R...

0
  575 Hits

New Vulnerabilities Friday 12 January

New Alerts for Rapid Software, Microsoft Edge, D-Link (Exploit), GitLab, TRENDnet, NetApp, and Linux. Rapid Software  Successful exploitation of vulnerabilities in Rapid SCADA could result in a remote attacker connecting to the server and perfoming attacks using the high privileges of a service, obtaining administrator passwords, learning sens...

0
  606 Hits

New Vulnerabilities Thursday 11 January

Monthly Patches are out for Juniper Networks. New Alerts for Ivanti (Exploit), Cisco, BD, and NVIDIA. Ivanti Exploit Vulnerabilities have been discovered in Ivanti Connect Secure (ICS). These vulnerabilities used together allow a remote attacker to craft malicious requests and execute arbitrary commands on the system. Highest CVSSv3 score of 9.1Pat...

0
  585 Hits

New Vulnerabilities Wednesday 10 January

Monthly Patches are out for Microsoft, Adobe, and Fortinet. Quarterly Patches are out for Splunk. New Alerts for Google Chrome, HPE, IBM, and Linux. Microsoft  Microsoft Monthly Patches are out with 48 patched vulnerabilities plus chromium updates for Edge. Of the Microsoft vulnerabilities, 2 are rated Critical. Highest CVSSv3 score of 9.1More...

0
  726 Hits

New Vulnerabilities Tuesday 09 January

Monthly Patches are out for Siemens, Schneider Electric, and SAP. New Alerts for Palo Alto Networks, BD, Google ChromeOS, and Linux. Microsoft and Adobe Monthly Patches are expected this afternoon.  Siemens  Siemens has published their Monthly Patches, with 6 new bulletins and 11 updated bulletins. Of the new bulletins, highest CVSSv3 sco...

0
  673 Hits

New Vulnerabilities Monday 08 January

New Alerts for QNAP, Bosch, Microsoft, HPE, HP, NetApp, and Linux. QNAP  A vulnerability has been reported in Netatalk which affects QNAP OS. CVSSv3 score of 9.8More info.A prototype pollution vulnerability affects QNAP OS. The vulnerability allows a remote attacker to override existing attributes which causes the system to crash. CVSSv3 score...

0
  629 Hits

New Vulnerabilities Friday 05 January

New Alerts for BD, Moxa, and Linux. BD  BD has published security updates for Alaris, Data Agent, Pyxis, Identity Provider Manager, Care Coordination Engine, EpiCenter, and Max.More info. Moxa  Moxa has added PT-7728 and PT-7828 series products to a bulletin from Nov 2023. Highest CVSSv3 score of 6.9More info. Linux  Ubuntu has updat...

0
  729 Hits

New Vulnerabilities Thursday 04 January

Monthly Patches are out for Google Android, Google Pixel, and Samsung. New Alerts for Google Chrome, Dell, Wireshark, and HPE. Google  Google has updated Chrome for Desktop to fix 6 security vulnerabilities.More info.Google has published the Monthly Android patches with 11 addressed vulnerabilities, all rated High, plus Arm, Imagination Techno...

0
  689 Hits

New Vulnerabilities Wednesday 03 January

New Alerts for MediaTek, IBM, and ASUS. MediaTek  MediaTek Monthly Patches are out, with 20 addressed vulnerabilities, with 2 rated High, and 18 rated Medium. More info. IBM  Security QRadar Analyst Workflow app for QRadar SIEM is vulnerable to using components with known vulnerabilities. Highest CVSSv3 score of 9.8More info.A PyTorch vul...

0
  635 Hits

New Vulnerabilities Tuesday 02 January

New Alerts for Qualcomm, IBM, and Linux. Qualcomm  Qualcomm Monthly Patches are out, with 16 addressed vulnerabilities, 2 rated Critical, 12 rated High, and 2 rated Medium. Highest CVSSv3 score of 9.8More info. IBM  Vulnerabilities in Golang Go affect Cloud Pak System Software. Highest CVSSv3 score of 9.8More info. Linux  Debian has ...

0
  676 Hits

New Vulnerabilities Monday 01 January

New Alerts for IBM and Juniper Networks. IBM  IBM Storage Protect Server uses IBM Db2 and is affected by multiple vulnerabilities including DoS, RCE, or loss of confidentiality, integrity or availability. CVSSv3 score of 9.8More info. Juniper  Multiple vulnerabilities have been resolved in Juniper Secure Analytics. Highest CVSSv3 score of...

0
  730 Hits
radar Cyber Threat Intelligence, or the Radar Page

About the Radar Page and Vulnerabilities

The Cyber Threat Intelligence page, affectionately known as the Radar Page by some (or maybe just me), has been around for over 13 years.  See the Daily Mail article below for the sensational history.  :)  It has been through several redesigns, but retains a similar look and feel across the versions. Where to find the Radar Page: The...

5
  7042 Hits

New Vulnerabilities Friday 29 December

New Alerts for Moxa, IBM, and Progress. Moxa  The OnCell G3150A-LTE Series is affected by multiple web application vulnerabilities caused by applying weak cryptographic algorithms and cipher suites. Successful exploitation could allow a remote attacker unauthorized access and unexpected user interaction with the web application. Highest CVSSv3...

0
  644 Hits

New Vulnerabilities Thursday 28 December

New Alert for D-Link. D-Link  A security issue exists in D-Link D-View 8 prior that could allow a remote attacker to manipulate the probe inventory of the D-View service and result in the disclosure of information or DoS. Tenable rates this Critical.No response from D-Link to Tenable. PoC exists.More info. Security Wizardry Cyber Threat Intell...

0
  678 Hits

New Vulnerabilities Wednesday 27 December

New Alerts for BD, NetApp, and D-Link. BD  BD has published security patches for BACTEC FX40, Phoenix M50, Assurity Linc, Accuri C6 Plus, ViperLT, FocalPoint, BACTEC FX, and Totalys.More info. NetApp  NetApp has published 11 new bulletins identifying vulnerabilities in third-party software included in their products. Highest CVSSv3 score ...

0
  678 Hits

New Vulnerabilities Tuesday 26 December

New Alerts for Barracuda (Exploit), Moxa, IBM, NetApp, Apache OFBiz, and Linux. Barracuda Exploit Another vulnerability in third party software has been identified in the ESG appliance that could allow Arbitrary code execution. CVSSv3 score of 9.8More info. And here. Moxa Web vulnerabilities have been identified in ioLogik E1200 Series firmware. Hi...

0
  637 Hits

New Vulnerabilities Friday 22 December

New Alerts for ProFTPD, BD, GE Gas Power, Microsoft (Exploit), HPE, and NetApp.Have a wonderful holiday season! ProFTPD  A vulnerability in ProFTPD allows a DoS. Probably a CVSSv3 score of 7.5More info. BD  BD has published security patches to fix vulnerabilities in third-party software in Kiestra TLA Track, Kiestra InoqulA+, and Kiestra ...

0
  700 Hits

New Vulnerabilities Thursday 21 December

New Alerts for Ivanti, Google Chrome (Exploit), Mitsubishi Electric, Dell, Asterisk, and Voltronic Power (0-Day). Ivanti  Avalanche has addressed several security vulnerabilities. Highest CVSSv3 score of 9.8More info. Google Exploit Google has updated Chrome for Desktop with one security fix, rated High.This has been exploited in the wild.More...

0
  757 Hits

New Vulnerabilities Wednesday 20 December

New Alerts for EuroTel (Exploit), Eaton, IBM, Dell, and HPE. EuroTel Exploit EuroTel ETL3100 radio transmitters contains several vulnerabilities that could allow a remote attacker to gain full access to the system, disclose sensitive information, or access hidden resources. Highest CVSSv3 score of 9.8No patches are available.More info. Eaton  ...

0
  784 Hits

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/