Skip to main content

CND News and Blog

New Vulnerabilities Friday 31 March

New Alerts for Contec, Apple, IBM, NetApp, and Linux. Contec  Contec has identified several vulnerabilities in its CONPROSYS HMI System (CHS) Web HMI/SCADA software. These vulnerabilities could be exploited by a remote attacker to steal information. CVSSv3 score of 7.5More info. Apple  Apple has published an update for Xcode that fixes tw...

0
  1045 Hits

New Vulnerabilities Thursday 30 March

New Alerts for Samba, QNAP, Veritas, 3CX (Exploit), and Linux. Samba  Samba has published 3 new bulletins, highest CVSSv3 score of 7.7More info.Samba will send password information over unencrypted sessions. CVSSv3 score of 5.9More info. QNAP  QNAP is updating their products for the Samba vulnerabilities.More info. Veritas  Veritas h...

1
  809 Hits

New Vulnerabilities Wednesday 29 March

New Alerts for PowerDNS, Mozilla Thunderbird, Tenable, and Linux. PowerDNS  When the recursor detects and deters a spoofing attempt or receives certain malformed DNS packets, it throttles the server that was the target of the impersonation attempt. Unfortunately this mechanism can be used by an attacker with the ability to send queries to the ...

1
  773 Hits

New Vulnerabilities Tuesday 28 March

New Alerts for Apple (Exploit), APsystems, Hitachi Energy, Dell, and Linux. Apple Exploit Apple has published updates for Studio Display firmware, Safari, iOS, iPadOS, watchOS, tvOS, and macOS. Three vulnerabilities are rated Critical, with one in WebKit being exploited.More info. APsystems  There is a security vulnerability in Altenergy Power...

0
  1004 Hits

New Vulnerabilities Monday 27 March

New Alerts for BD, Microsoft Edge, Microsoft "Acropalypse", IBM, NetApp, and Linux. BD  BD has published updates for vulnerabilities in third-party software included in Synapsys and BD MAX.More info. Microsoft  Microsoft has updated Edge with the latest chromium security fixes.More info.Microsoft has patched the "Acropalypse" bug in their...

0
  1008 Hits

New Vulnerabilities Friday 24 March

New Alerts for ManageEngine, ProPump & Controls, SAUTER, IBM, Xerox, Tenable, and Linux. ManageEngine  ManageEngine ADSelfService Plus pertains to an OTP–brute-force issue in the Password Sync Agent that could affect integrated third-party applications. Attackers could exploit this vulnerability using specialized, highly sophisticated mach...

0
  890 Hits

New Vulnerabilities Thursday 23 March

New Alerts for Microsoft (0-Day, Acropalypse), Cisco, Varta Storage, Meinberg, OpenSSL, and Philips.  Microsoft 0-Day The vulnerability dubbed "Acropalypse" originally identified and fixed in Pixel has now cropped up (see what we did there) in Windows 11's Snipping Tool and Windows 10's Snip & Sketch tool. When editing a saved screenshot a...

0
  846 Hits

New Vulnerabilities Wednesday 22 March

New Alerts for Rockwell Automation, Delta Electronics, Google Chrome, Dell, Apache Tomcat, Veritas, and Linux. Rockwell Automation  Vulnerabilities were discovered in the ThinManager ThinServer software. Successful exploitation of this vulnerability could allow an attacker to potentially perform remote code execution on the target or crash the...

0
  969 Hits

New Vulnerabilities Tuesday 21 March

New Alerts for IBM and Linux. IBM  IBM Aspera Faspex 4.4.2 PL3 has addressed multiple vulnerabilities. Highest CVSSv3 score of 9.9More info. Linux  Red Hat has updated the kernel. More info. Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securitywizardry.com/ Security Wizardry Cyber Threat Intelligence - The Mo...

0
  1048 Hits

New Vulnerabilities Monday 20 March

New Alerts for Unify, Google Pixel (Exploit), D-Link, curl, and Linux. Unify  Three command injection vulnerabilities have been identified in the Atos Unify OpenScape 4000 Platform and the Atos Unify OpenScape 4000 Manager Platform. A remote attacker can run arbitrary commands on the platform operating system and get administrative access to t...

0
  1043 Hits

New Vulnerabilities Friday 17 March

New Alerts for Honeywell, Samsung (0-Day), IBM, NetApp, BD, and Linux. Honeywell  Honeywell OneWireless Wireless Device Manager contains several vulnerabilities, including Command Injection, Use of Insufficiently Random Values, and Missing Authentication for Critical Function. Highest CVSSv3 score of 9.8More info. Samsung 0-Day Eighteen 0-day ...

0
  922 Hits

New Vulnerabilities Thursday 16 March

New Alerts for Rockwell Automation, IBM, NETGEAR, Mozilla Thunderbird, and Linux. Rockwell Automation  Modbus TCP Server Add-On Instructions (AOI) for ControlLogix and CompactLogix controllers contains a vulnerability that would allow a remote attacker to gain information when the Modbus TCP Server AOI accepts a malformed request. CVSSv3 score...

0
  978 Hits

New Vulnerabilities Wednesday 15 March

Monthly Patches are out for Microsoft and Adobe. New Alerts for AVEVA, Moxa, Aruba, and Mozilla.   Palo Alto Networks patches are expected this afternoon. Microsoft - Exploit Microsoft Monthly Patches include 76 vulnerabiltiies, 9 rated Critical and 2 are being Exploited. Highest CVSSv3 score of 9.8More info. And here.There is a RCE affecting ...

0
  1060 Hits

New Vulnerabilities Tuesday 14 March

Monthly Patches are out for Siemens, Schneider Electric, and SAP. New Alerts for Microsoft Edge, Phoenix Contact, and Omron.     Monthly Patches for Microsoft and Adobe should be out this afternoon.    Palo Alto Networks Monthly Patches are due tomorrow.  Siemens  Siemens Monthly Patches are out, with 7 new bulletins a...

0
  872 Hits

New Vulnerabilities Monday 13 March

Updates for Dell and Linux. Tomorrow is Patch Tuesday. Dell  Dell VxRail remediation is available for multiple security vulnerabilities in third-party software. Dell rates this Critical.More info. Linux  Red Hat has updated kpatch. More info.Mageia has updated the kernel. More info. Security Wizardry Cyber Threat Intelligence - The Radar ...

0
  903 Hits

New Vulnerabilities Friday 10 March

New Alerts for Akuvox (Exploit), GE Grid Solutions, Lexmark, NetApp, and WithSecure. Akuvox - Exploit Akuvox E11, a smart intercom, contains several vulnerabilities that could cause loss of sensitive information, unauthorized access, and grant full administrative control to an attacker. Highest CVSSv3 score of 9.8More info. And here. GE Grid Soluti...

0
  970 Hits

New Vulnerabilities Thursday 09 March

New Alerts for Cisco and Linux.  Cisco  Cisco has published 2 new bulletins, Highest CVSSv3 score of 8.6More info.A vulnerability in the BFD hardware offload feature of Cisco IOS XR Software could allow a remote attacker to cause a line card to reset, resulting in a DoS. CVSSv3 score of 8.6More info. Linux  CentOS has updated the ker...

0
  866 Hits

New Vulnerabilities Wednesday 08 March

Monthly Patches are out for Fortinet. New Alerts for Google Chrome, Moxa, CODESYS, ABB, Apache, Veeam, Ivanti, and Linux. Google  Google has published a security update for Chrome for desktop that fixes 40 security vulnerabilities.More info.Microsoft is aware. More info. Fortinet  Fortinet Monthy Patches include 15 bulletins, 1 rated Crit...

0
  944 Hits

New Vulnerabilities Tuesday 07 March

Monthly Patches for Google Android and Samsung are out. New Alerts for IBM and Linux. Google  Android Monthly Patches include 31 vulnerabilities, 2 rated Critical and the rest High, along with MediaTek, Unisoc, and Qualcomm patches. The most severe vulnerabilities could lead to RCE.More info.There is currently no Pixel bulletin, maybe later to...

0
  1802 Hits

New Vulnerabilities Monday 06 March

Monthly Patches are out for Qualcomm and MediaTek. New Alert for Linux. Tomorrow is mobile patch day, including Android and Samsung. Qualcomm  Qualcomm Monthly Patches include 20 vulnerabilities, 4 rated Critical, 15 rated High, and 1 rated Medium. There are 4 additional vulnerabilities in open source software. Highest CVSSv3 score of 9.8More ...

0
  831 Hits

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/