+44 (0)203 88 020 88

Menu

Search

Vulnerabilities

NCSC alerts over MobileIron vulnerability

The UK National Cyber Security Centre has issued an alert warning that multiple actors are attempting to exploit a MobileIron vulnerability to compromise the networks of UK organisations. MobileIron issued a security patch in June 2020 for their Mobile Device Management system to resolve several vulnerabilities in their software.  Included was a critical remote code […]

NCSC alerts over MobileIron vulnerability Read More »

SAD DNS vulnerability revives risk of DNS poisoning

An award winning security paper published this week explains a newly discovered vulnerability called SAD DNS which leaves many websites vulnerable to man-in-the-middle and impersonation attacks. DNS is the system that converts friendly website addresses (www.secureteam.co.uk) into the numeric IP addresses used by TCP/IP.  SAD DNS is a flaw discovered in the DNS protocol which

SAD DNS vulnerability revives risk of DNS poisoning Read More »

November Patch Tuesday fixes 12 RCE vulnerabilities

The November security patch bundle from Microsoft fixes 112 security vulnerabilities in their products, including 12 Remote Code Execution vulnerabilities. Noteworthy vulnerabilities fixed this month include:   Windows Kernel Local Elevation of Privilege:  CVE-2020-17087 Observed under active attack in the wild by Google, CVE-2020-17087 is an elevation of privilege vulnerability that was being used in

November Patch Tuesday fixes 12 RCE vulnerabilities Read More »

Sonicwall critical Firewall RCE vulnerability

Sonicwall has released patches to fix a denial of service and remote code execution vulnerability in their Network Application Security appliances (virtual firewalls).  The vulnerability exists in the code which handles SSL VPN access – meaning it is usually exposed to the public internet. The vulnerability was discovered by researchers at Tripwire who describe the

Sonicwall critical Firewall RCE vulnerability Read More »

October Patch Tuesday includes critical Windows TCP/IP vulnerability

October’s security patch bundle from Microsoft resolves 87 vulnerabilities, 12 rated as critical.  One of these is a flaw in the Windows TCP/IP stack which can result in a server crash or remote code execution simply by sending a specially crafted ICMPv6 request. While it is technically challenging to achieve a remote code execution, the

October Patch Tuesday includes critical Windows TCP/IP vulnerability Read More »

0

No products in the basket.

No products in the basket.