CND News and Blog
New Alerts for Blackberry, Baxter, Microsoft Edge, Spring, NetApp, IBM, and Linux. Blackberry Multiple vulnerabilities in SecuSUITE Server could allow a remote attacker to enroll an attacker-controlled device to the victim's account and telephone number or inject script commands or other executable content into the server that would run with ...
Monthly Patches are out for Palo Alto Networks. New Alerts for Apache Traffic Server, Siemens, Dell, Mozilla, GitLab, and Linux. Palo Alto Networks Monthly Patches are out with 9 bulletins, 1 rated High, 4 rated Medium, and 4 rated Low. Several bulletins address DoS vulnerabilities in the firewall. Highest CVSSv3 score of 8.6More info. Apache...
Monthly Patches are out for Microsoft (Exploit), Adobe, and Fortinet. New Alerts for Ivanti, Google Chrome, Westermo, Rockwell Automation, HPE, Broadcom, and Linux. Microsoft Exploit Monthly Patches are out with 83 vulnerabilities, 3 rated Critical, 2 have been exploited in the wild, and another 2 have been disclosed prior to Patch Tuesday. Highest...
Monthly Patches are out for Schneider Electric, Siemens, and SAP. New Alerts for HPE, Citrix, Zoom, and Linux. Monthly Patches for Microsoft and Adobe are expected this afternoon, and Palo Alto expected tomorrow. Schneider Electric Monthly Patches include 4 new bulletins, all remotely exploitable without authentication, and 2 updated bulletin...
New Alerts for Dell, GE HealthCare, Extreme Networks, and Linux. Dell Dell has published Critical updates for NetWorker, APEX Cloud Platform, Metro node, and VxRail.More info. GE HealthCare A limited number of GE HealthCare products are impacted by vulnerabilities in Mirth Connect from 2023. CVSSv3 score of 9.8More info. Extreme N...
New Alerts for Synology, NETGEAR, SICK, Microsoft Edge, Moxa, and NetApp. Synology Synology has published 6 new bulletins identifying vulnerabilities in their products discovered during PWN2OWN. All allow remote attackers various access such as RCE and DoS.Some patches available.More info. NETGEAR NETGEAR has published 7 new bulletins f...
Monthly Patches are out for Google Pixel. New Alerts for Cisco, Eaton, Dell, HPE, Veeam, and Linux. Cisco Cisco has published 15 new bulletins, 1 rated Critical, 2 rated High, and the rest Medium. Highest CVSSv3 score of 10More info.A vulnerability in the web-based management interface of Unified Industrial Wireless Software for Ultra-Reliabl...
New Alerts for HPE, Google Chrome, Hitachi, Dell, curl, HCL, and Linux. HPE HPE Aruba Networking has released updates for Access Points running Instant AOS-8 and AOS-10. Highest CVSSv3 score of 9.8More info. Google Chrome has been updated to fix 2 security vulnerabilities.More info. Hitachi Hitachi has published updates for Cosmin...
Monthly Patches are out for Google Android and Samsung Android. New Alerts for BD, QNAP, and Linux. Google Android Monthly Patches are out with 21 vulnerabilities, all rated High, plus updates for Imagination Technologies, Mediatek, and Qualcomm patches.More info. Samsung Samsung Monthly Patches include 12 vulnerabilities, 5 rated High ...
Monthly Patches are out for Qualcomm and Mediatek. New Alerts for Broadcom, Moxa, Dell, NetApp, and Linux. Qualcomm Monthly Patches are out for Qualcomm, with 10 vulnerabilities, 1 rated Critical, 7 rated High, and 2 rated Medium. Highest CVSSv3 score of 8.2More info. Mediatek Mediatek's Monthly Patches include 11 CVEs, 2 rated High and...
New Alerts for Ricoh, Microsoft Edge, Digi, Moxa, IBM, Splunk, and Linux. Ricoh Ricoh has identified a buffer overflow vulnerability when using the Web Image Monitor that could potentially allow a DoS or RCE. CVSSv3 score of 9.8More info. Microsoft Microsoft has updated Edge with the latest chromium updates.More info. Digi Web ser...
New Alerts for D-Link, HP, Draytek, Bosch, Tenable, Splunk, and Linux. D-Link The D-Link DSL6740C modem is configured with default and predictable administrator credentials that compromise the security of the device. These credentials allow unauthorized remote access to the modem's control panel, posing a significant security risk. CVSSv3 sco...
New Alerts for Google Chrome, Hitachi Energy, Apple, QNAP, GE Vernova, Delta Electronics, and Linux. Google Chrome for Desktop has been updated to fix 2 security vulnerabilties.More info. Hitachi Energy Hitachi Energy has published updates for UNEM, FOXMAN-UM, and MicroScada Pro/X SYS600.. Highest CVSSv3 score of 10More info. Apple ...
New Alerts for Apple, Hitachi Energy, HPE, Mozilla, QNAP, and CyberPanel (Exploit). Apple Apple has published udates for macOS, iPadOS, iOS, visionOS, tvOS, and watchOS.More info. And here. Hitachi Energy There are public reports of vulnerabilities in the Hitachi Energy's MSM that could allow a remote attacker to impact the confidential...
New Alerts for F5, Squid, Ruby, Rockwell Automation, HPE, and BD. F5 libarchive has been updated in BIG-IP. Highest CVSSv3 score of 5.3More info. And here. And here. Squid Squid is vulnerable to DoS attacks by a trusted server against all clients using the proxy. CVSSv3 score of 7.5More info. Ruby There is a ReDoS vulnerability in REXML...
New Alerts for Microsoft Edge, iniNet, IBM, Dell, NetApp, and VIMESA. Microsoft Microsoft has updated Edge to fix 9 Edge-specific vulnerabilities and the latest chromium updates.More info. iniNet SpiderControl SCADA PC HMI Editor contains a Path Traversal vulnerability that could allow a remote attacker to gain remote control of the dev...
New Alerts for Fortinet (patch for the exploit), Cisco, and Siemens. Fortinet A missing authentication for critical function vulnerability in FortiManager fgfmd daemon may allow a remote attacker to execute arbitrary code or commands via specially crafted requests. CVSSv3 score of 9.8This is the fix for the Exploit reported yesterday.More inf...
New Alerts for Google Chrome, Fortinet (Exploit), IBM, Shibboleth, and Linux. Google Google has updated Chrome for Desktop to fix 3 security vulnerabilities, all rated High.More info. Fortinet Exploit FGFM has vulnerabilities that can be chained and used for exploits.More info. IBM IBM Storage Protect Server is susceptible to multiple v...
New Alert for Linux. Linux Oracle Linux has updated the kernel. More info.Mageia has updated systemd. More info. Security Wizardry Cyber Threat Intelligence - The Radar Page https://radar.securitywizardry.com/ Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page A mobile version of our Security Wizardry Radar Page, providing vu...
New Alerts for Moxa, SICK, HP, Endress+Hauser, IBM, Dell, and Linux. Moxa NE-4100, MiiNePort E1, MiiNePort E2, and MiiNePort E3 contain a vulnerability that allows a remote attacker to retrieve administration passwords without proper authentication. CVSSv3 score of 9.8More info. SICK A critical vulnerability has been discovered in the ....
By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/