Skip to main content

CND News and Blog

Scammers. Societies bottom-feeders.
Jack -
Technical
Scamming is sadly a daily risk whilst navigating cyberspace. I wrote almost exactly 3 years ago in different post about a similar postal scam, masquerading as the Post Office asking for a small missed delivery fee (URL). Well this week it happened again to a family member who started to fall for it, fortunately they stopped but ...
New Vulnerabilities Friday 15 March
michele654
Vulnerabilities
New Alerts for Juniper, Microsoft Edge, Dell, HPE, NetApp, Mitel, and Linux. Juniper  Multiple vulnerabilities have been resolved in Juniper Secure Analytics. Highest CVSSv3 score of 9.8More info. Microsoft  Microsoft has updated Edge to fix chromium-based vulnerabilities as well as 3 Edge-specific vulnerabilities.More info. Dell  De...
New Vulnerabilities Thursday 14 March
michele654
Vulnerabilities
New Alerts for Cisco, Arcserve, Apache Tomcat, BD, Mitsubishi Electric, IBM, and Linux. Cisco  Cisco has published 7 new security bulletins. Highest CVSSv3 score of 7.8.More info. A vulnerability in theDHCPv4 server feature of IOS XR Software could allow a remote attacker to trigger a crash of the dhcpd process, resulting in a DoS. CVSSv3 scor...
New Vulnerabilities Wednesday 13 March
michele654
Vulnerabilities
Monthly Patches are out for Microsoft, Adobe, and Fortinet. New Alerts for Google Chrome, Bosch, Citrix, Hitachi, IBM, Intel, and Linux. Tomorrow may be Palo Alto Monthly Patches. Microsoft  Microsoft Monthly Patches include 61 vulnerabilities. Two are rated Critical. Highest CVSSv3 score of 9.8More info. And here. Adobe  Adobe Monthly Pa...
New Vulnerabilities Tuesday 12 March
michele654
Vulnerabilities
Monthly Patches are out for Siemens, Schneider Electric, and SAP. New Alerts for Phoenix Contact, Synology, and Linux. Monthly Patches for Microsoft and Adobe are expected this afternoon. Siemens  Siemens Monthly Patches are out, with 11 new bulletins and 11 updated bulletins. Of the new bulletins, highest CVSSv3 score of 10More info.RUGGEDCOM...
New Vulnerabilities Monday 11 March
michele654
Vulnerabilities
New Alerts for Dell, HPE, and Digi. Tomorrow is Patch Tuesday. Dell  Dell NetWorker vProxy remediation is available for multiple security vulnerabilities that could be exploited. Dell rates this Critical.More info. HPE  Vulnerabilities have been identified in HPE Unified OSS Console Assurance Monitoring that could allow a remote attacker ...
New Vulnerabilities Friday 08 March
michele654
Vulnerabilities
New Alerts for Apple (Exploit), Chirp Systems, Microsoft Edge, QNAP, NetApp, and Linux. Apple Exploit Apple has published updates for Safari, macOS, tvOS, watchOS, and visionOS. At least one vulnerability in each of these products is being actively exploited.More info. Chirp Systems  Chirp Access contains a Hard-coded Credentials vulnerability...
New Vulnerabilities Thursday 07 March
michele654
Vulnerabilities
New Alerts for Cisco, Pilz, IBM, Artica, Bosch, and Linux. Cisco  Cisco has published 7 new bulletins, Highest CVSSv3 score of 8.2More info.A vulnerability in the SAML authentication process of Cisco Secure Client could allow a remote attacker to conduct a CRLF injection attack against a user. CVSSv3 score of 8.2More info. Pilz  The PITre...
New Vulnerabilities Wednesday 06 March
michele654
Vulnerabilities
New Alerts for Apple (0-Day), Nice, Sophos, Moxa, Bosch, Google Chrome, HPE Aruba, and Linux. Apple 0-Day Apple has published updates for iOS fixing 4 vulnerabilities that allow privilege escalation, 2 of which have been exploited.More info. And here. Nice  Linear eMerge E3-Series contains multiple vulnerabilities, including OS command injecti...
New Vulnerabilities Tuesday 05 March
michele654
Vulnerabilities
Monthly Patches are out for Google Android, Google Pixel, and Samsung Android. New Alerts for Mozilla, Squid, and Linux. Google  Google Monthly Patches for Android are out, with 13 vulnerabilities with 2 rated Critical and 11 rated High, as well as patches for AMLogic, Arm, MediaTek, and Qualcomm. Highest CVSSv3 score of 9.8More info.Google Mo...
New Vulnerabilities Monday 04 March
michele654
Vulnerabilities
Monthly Patches are out for Qualcomm and MediaTek. New Alerts for Hikvision, Dell, Xerox, and IBM. Qualcomm  Qualcomm Monthly Patches are out, with 16 vulnerabilities, 2 rated Critical, 12 rated High, and 2 rated Medium. Highest CVSSv3 score of 9.8More info. MediaTek  MediaTek Monthly Patches include 21 vulnerabilities, 12 rated High and ...
New Vulnerabilities Friday 01 March
michele654
Vulnerabilities
New Alerts for SolarWinds, Microsoft Edge, NetApp, Ivanti, and Linux. SolarWinds  SolarWinds has updated Security Event Manager (SEM) to fix vulnerabilities in third-party software as well as one vulnerability in SEM. Highest CVSSv3 score of 9.8More info. Microsoft  Microsoft has updated Edge with the latest chromium patches and one patch...
New Vulnerabilities Thursday 29 February
michele654
Vulnerabilities
New Alerts for Cisco, Juniper Networks, BD, Dell, Mitel, IBM, and Linux. Happy Leap Day! Cisco  Cisco has published 5 new bulletins. Highest CVSSv3 score of 8.6More info.Vulnerabilities in the eBGP implementation and handling of MPLS traffic of Cisco NX-OS Software could allow a remote attacker to cause a DoS condition. CVSSv3 score of 8.6More...
New Vulnerabilities Wednesday 28 February
michele654
Vulnerabilities
New Alerts for Festo, Google Chrome, Meinberg, Hitachi Energy, and HPE/Aruba. Festo  MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 vulnerabilities. Replace XAMPP with Festo Didactic's Factory Control Panel application. Highest CVSSv3 score of 9.8More info. Google  Google has updated Chrome for Desktop t...
New Vulnerabilities Tuesday 27 February
michele654
Vulnerabilities
New Alerts for Microsoft Azure, Eclipse, SMA, Mitsubishi Electric, and Linux. Microsoft  Microsoft Azure could allow a remote attacker to execute arbitrary code on the system, caused by a search path element flaw in the installation of MCR VSTS CLI. CVSSv3 score of 9.8More info. And here. Eclipse  A vulnerability in Jetty allows a remote ...
New Vulnerabilities Monday 26 February
michele654
Vulnerabilities
New Alerts for Microsoft Edge, WithSecure, HPE, HP, F5, IBM, and Linux. Microsoft  Edge has been updated to fix the latest chromium-based vulnerabilities.Note the normal Edge announcement page doesn't yet show this update.More info. And (maybe) here. WithSecure  A DoS vulnerability was discovered in WithSecure products where the engine sc...

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/