Cisco Patches Critical Vulnerability in Enterprise Collaboration Products

January 25, 2024 at 11:48AM Cisco announced security updates to address a critical-severity vulnerability (CVE-2024-20253, CVSS 9.9) affecting multiple Unified Communications and Contact Center Solutions products. The flaw could allow attackers to execute arbitrary commands with system privileges. Cisco advises immediate patching and mitigation using access control lists. Medium-severity flaws in Business 250/350 series switches … Read more

Windows 11 KB5034204 update fixes Bluetooth audio issues, 24 bugs

January 24, 2024 at 08:38AM Microsoft released the January 2024 preview update for Windows 11 versions 22H2 and 23H2, which includes Bluetooth audio bug fixes and addresses 24 known issues. The update, known as KB5034204, provides improvements for testing before the forthcoming February 2024 Patch Tuesday release. It is an optional update and can be … Read more

Fortra warns of new critical GoAnywhere MFT auth bypass, patch now

January 23, 2024 at 10:46AM Fortra warns of a critical authentication bypass vulnerability in GoAnywhere MFT, affecting versions prior to 7.4.1. Exploitation allows unauthorized creation of admin accounts and could lead to data breaches and malware introduction. The flaw was fixed in version 7.4.1, and users are advised to update immediately. Notably, past incidents suggest … Read more

Critical RCE Vulnerability Uncovered in Juniper SRX Firewalls and EX Switches

January 13, 2024 at 06:54AM Juniper Networks released updates to fix a critical remote code execution vulnerability in its SRX Series firewalls and EX Series switches, tracked as CVE-2024-21591 with a CVSS score of 9.8. The flaw can allow attackers to cause Denial-of-Service or Remote Code Execution, affecting specific Junos OS versions. Juniper also resolved … Read more

Windows 10 KB5034122 update released with fix for shut down bug

January 9, 2024 at 02:55PM Microsoft released KB5034122 cumulative update for Windows 10 21H2 and 22H2, containing January 2024 security updates. It’s mandatory, with limited fixes due to the holiday season. After manual installation or ‘Check for Updates,’ it’ll automatically start but can be scheduled for restart. New update for Win 10, addressing issues and … Read more

Microsoft January 2024 Patch Tuesday fixes 49 flaws, 12 RCE bugs

January 9, 2024 at 02:11PM Microsoft’s January 2024 Patch Tuesday addresses 49 flaws and 12 remote code execution vulnerabilities. Notably, a Windows Kerberos Security Feature Bypass and a Hyper-V RCE were classified as critical. Microsoft also addressed an Office Remote Code Execution Vulnerability and other flaws. Other vendors released updates, including .NET, Azure, Microsoft Edge, … Read more

Fake F5 BIG-IP zero-day warning emails push data wipers

December 20, 2023 at 04:59PM Israel National Cyber Directorate warns of phishing emails posing as F5 BIG-IP zero-day security updates, deploying data wipers for Windows and Linux. Israeli organizations targeted by pro-Palestinian and Iranian hacktivists since October. New phishing attack delivers data wipers through fake F5 update emails. Wipers communicate with a Telegram channel, posing … Read more

Ivanti releases patches for 13 critical Avalanche RCE flaws

December 20, 2023 at 01:10PM Ivanti released security updates fixing 13 critical vulnerabilities in their Avalanche enterprise mobile device management (MDM) solution. The flaws relate to buffer overflows. Unauthenticated attackers could exploit them for remote code execution. All issues were resolved in Avalanche v6.4.2.313. CISA and NCSC-NO have expressed concern about potential widespread exploitation in … Read more

Microsoft: Multiple Perforce Server Flaws Allow for Network Takeover

December 19, 2023 at 01:20PM Microsoft identified four critical vulnerabilities in the Perforce source-code management platform, allowing attackers to access a highly privileged Windows OS account, enabling remote code execution and supply chain attacks. The flaws can lead to various malicious activities, including denial-of-service attacks. Perforce has issued a patch (version 2023.1/2513900) to address these … Read more

Microsoft’s Final 2023 Patch Tuesday: 33 Flaws Fixed, Including 4 Critical

December 13, 2023 at 01:48AM Microsoft’s final 2023 Patch Tuesday update addressed 33 flaws, with 4 rated Critical and 29 rated Important. This year, they’ve patched over 900 flaws, including vulnerabilities like remote code execution and information disclosure. Akamai also discovered attacks against Active Directory domains using Microsoft DHCP servers, prompting recommendations from Microsoft. Other … Read more