Atlassian, Splunk Patch High-Severity Vulnerabilities

December 11, 2024 at 08:03AM Atlassian and Splunk issued patches for numerous vulnerabilities in their products. Atlassian fixed 10 high-severity flaws in various Data Center and Server applications, while Splunk addressed over 15 vulnerabilities, including a high-severity issue in its Secure Gateway app. Users are urged to update promptly; no exploits have been reported. **Meeting … Read more

Three more vulns spotted in Ivanti CSA, all critical, one 10/10

December 11, 2024 at 07:15AM Ivanti issued a security advisory for three critical vulnerabilities in its Cloud Services Application (CSA), including a perfect 10-rated authentication bypass flaw. These vulnerabilities could allow attackers to gain unauthorized access and execute malicious commands. Users are urged to upgrade to version 5.0.3 to mitigate risks. ### Meeting Takeaways: **Ivanti … Read more

ICS Patch Tuesday: Security Advisories Released by Siemens, Schneider, CISA, Others

December 11, 2024 at 06:34AM The December 2024 ICS Patch Tuesday featured advisories from CISA and several industrial companies, notably Schneider Electric and Siemens. Significant vulnerabilities were reported, including critical flaws in Modicon controllers and high-severity issues in various products, prompting numerous patches and mitigations for affected systems. Rockwell Automation and Phoenix Contact also released … Read more

Ivanti Patches Critical Flaws in Connect Secure, Cloud Services Application

December 11, 2024 at 06:19AM Ivanti announced patches for 11 vulnerabilities, including five critical-severity bugs affecting Cloud Services Application, Connect Secure, and Policy Secure. Notably, CVE-2024-11639, with a CVSS score of 10, allows authentication bypass. Users are urged to update their systems. No evidence of exploitation has been reported. ### Meeting Takeaways 1. **Ivanti Vulnerability … Read more

Microsoft Fixes 72 Flaws, Including Patch for Actively Exploited CLFS Vulnerability

December 11, 2024 at 02:30AM Microsoft’s October 2024 Patch Tuesday addressed 72 security flaws, including a critical privilege escalation vulnerability (CVE-2024-49138) actively exploited in the wild. The update opened paths for further security measures against threats. Additionally, Microsoft plans to phase out NTLM in favor of Kerberos to bolster security against exploitation. ### Meeting Takeaways: … Read more

U.S. Charges Chinese Hacker for Exploiting Zero-Day in 81,000 Sophos Firewalls

December 11, 2024 at 01:36AM The U.S. government charged Chinese national Guan Tianfeng for hacking thousands of Sophos firewalls in 2020, exploiting a severe zero-day vulnerability. He allegedly conspired to access and exfiltrate data, targeting critical U.S. infrastructure. Sanctions were imposed against his company, Sichuan Silence, linked to Chinese intelligence agencies. ### Meeting Takeaways from … Read more

Ivanti Issues Critical Security Updates for CSA and Connect Secure Vulnerabilities

December 10, 2024 at 10:12PM Ivanti has issued security updates for critical vulnerabilities in its Cloud Services Application and Connect Secure products, including flaws allowing privilege escalation and remote code execution. Users are urged to update to the latest versions as active exploitation has been a concern, despite Ivanti not having awareness of current attacks. … Read more

Microsoft holds last Patch Tuesday of the year with 72 gifts for admins

December 10, 2024 at 03:55PM This month, Microsoft has released 72 fixes, with CVE-2024-49138 posing an immediate risk due to active exploitation. Adobe, on the other hand, issued 167 fixes, including 91 for Adobe Experience Manager and critical updates for Adobe Connect. Users are urged to patch vulnerabilities across all platforms promptly. ### Meeting Takeaways … Read more

Adobe Patches Over 160 Vulnerabilities Across 16 Products

December 10, 2024 at 02:05PM Adobe’s December 2024 Patch Tuesday updates addressed over 160 vulnerabilities across 16 products, notably Adobe Experience Manager and Adobe Animate. The patches include medium to critical severity issues, particularly concerning arbitrary code execution. While no known exploits exist, users are urged to apply the updates promptly for security. ### Meeting … Read more

Microsoft December 2024 Patch Tuesday fixes 1 exploited zero-day, 71 flaws

December 10, 2024 at 01:38PM Several Microsoft vulnerabilities were reported, affecting various components such as Microsoft Defender, Edge, Office, SharePoint, and Windows services. Severity levels range from moderate to critical, with numerous remote code execution and elevation of privilege vulnerabilities listed, posing significant security risks to users and systems. ### Meeting Takeaways: CVE Vulnerabilities Overview … Read more