+44 (0)203 88 020 88

Menu

Search

Vulnerabilities

Microsoft and Adobe release patches for zero day vulnerabilities

May Patch Tuesday sees four critical vulnerabilities patched by Microsoft and Adobe ships a fix for an Acrobat Reader zero-day that is under attack in the wild. Microsoft Patch Tuesday May 2021 55 vulnerabilities, 4 critical, are resolved in the May security patch bundle from Microsoft.  Of particular note are: CVE-2021-31166 which is a Windows

Microsoft and Adobe release patches for zero day vulnerabilities Read More »

Exim Mail Server 21Nails critical vulnerabilities

21 critical vulnerabilities have been discovered in the Exim Email server, some of which can be exploited to perform full remote unauthenticated code execution and gain root privilege on the server. Called 21Nails, this set of vulnerabilities is, to the Unix world, as serious as the ProxyLogon vulnerabilities recently discovered in Microsoft Exchange Server. The

Exim Mail Server 21Nails critical vulnerabilities Read More »

Compromise of Codecov dev tools affects thousands of customers

An unauthorised change to a script used by Codecov customers to upload software test results has stolen the credentials and API tokens for thousands of organisation’s development environments. Codecov is a tool used to track what percentage of an application’s source code has been exercised during software testing. To do this, it is integrated into the

Compromise of Codecov dev tools affects thousands of customers Read More »

SonicWall and Pulse Secure zero-day attacks

Security networking vendors SonicWall and Pulse Secure have both issued urgent alerts to customers regarding active zero-day attacks exploiting vulnerabilities in their products. SonicWall 3 zero-day vulnerabilities SonicWall has patched three zero-day vulnerabilities that affect their Email Security product. When chained together the vulnerabilities could allow an attacker to create a new administrator account on

SonicWall and Pulse Secure zero-day attacks Read More »

NCSC Warns of Critical Risk to unpatched Fortinet VPN devices

The UK National Cyber Security Centre has issued an alert warning organisation to urgently identify and patch Fortinet VPN devices on their networks. The NCSC alert warns : The NCSC is concerned that a significant number of organisations in the UK have not patched the Fortinet VPN vulnerability CVE-2018-13379. This continues to be actively exploited

NCSC Warns of Critical Risk to unpatched Fortinet VPN devices Read More »

SAP systems under active attack via unpatched vulnerabilities

SAP has issued an urgent security report after an increase in attacks against unpatched SAP systems using a variety of attack vectors. A new report from SAP and security firm Onapsis details how criminals are targeting mission critical SAP systems which are vulnerable due to security patches not being applied in a timely manner.  The

SAP systems under active attack via unpatched vulnerabilities Read More »

0

No products in the basket.

No products in the basket.