Ivanti Patches High-Severity Vulnerability in VPN Appliances

February 9, 2024 at 04:09PM Ivanti announced patches for a high-severity vulnerability, CVE-2024-22024, affecting enterprise VPN and network access products. The XML external entity (XXE) issue in SAML component of Connect Secure, Policy Secure, and ZTA appliances could allow unauthorized access to restricted resources. Patches addressing the flaw were included in various versions. No evidence … Read more

Securing Remote Workers Through Zero Trust

November 8, 2023 at 01:10AM Zero trust has shifted from theory to implementation in recent years, particularly in the context of remote work. Many organizations are adopting a zero-trust approach to improve security. Verifying identity with each connection attempt is crucial, as it ensures device security and authentic identity. While the path to zero trust … Read more

F5 fixes BIG-IP auth bypass allowing remote code execution attacks

October 27, 2023 at 11:17AM A critical vulnerability, CVE-2023-46747, has been discovered in the F5 BIG-IP configuration utility. It allows unauthenticated remote code execution by attackers with remote access to the utility. The vulnerability has a CVSS v3.1 score of 9.8. Devices with the Traffic Management User Interface exposed to the internet are at risk. … Read more

Virtual Alarm: VMware Issues Major Security Advisory

October 25, 2023 at 03:40PM VMware has advised customers to update their vCenter Servers due to a critical flaw that could result in remote code execution. The flaw, assigned a high severity score of 9.8, allows for an out-of-bounds write vulnerability in the DCERPC protocol. It is considered a serious threat to the confidentiality, integrity, … Read more