+44 (0)203 88 020 88

Vulnerabilities

Cisco patches critical switch flaws

Several critical switch vulnerabilities that could allow an attacker to break network segmentation have been patched by Cisco. Dubbed CDPwn by the researchers at Armis who discovered the flaws, the vulnerabilities exists in a Level 2 networking protocol called Cisco Discovery Protocol (CDP). Network segmentation is an effective security strategy that isolates data and systems […]

Cisco patches critical switch flaws Read More »

Ragnarok ransomware exploits Citrix vulnerability

Ragnarok ransomware is leveraging unpatched Citrix ADC servers and Windows computers to attack its victims. Citrix have now released a patch for CVE-2019-19781 and made it available to all clients – regardless of the status of their support contract. However, unpatched Citrix systems are being actively targeted with Ragnarok according to security firm Fireye. CVE-2019-19781 is

Ragnarok ransomware exploits Citrix vulnerability Read More »

Final Windows 7 Patches and critical security bug fixed

The last ever Windows 7 Patch Tuesday update also includes a fix to a long standing bug in the Windows cryptographic library (CryptoAPI) which could allow attackers to spoof digital certificates and conduct man-in-the-middle attacks. Microsoft has long warned that January 2020 was the end of support for Windows 7, meaning that this is expected

Final Windows 7 Patches and critical security bug fixed Read More »

SQLite remote code execution vulnerability

A remote code execution vulnerability has been discovered in SQLite, dubbed Magellan 2.0 by the research team that discovered it. Tencent’s Blade security research team has published some details of a remote code execution vulnerability that affects all version of SQLite prior to the latest patch issued on 13 December 2019.   SQLite is a widely used

SQLite remote code execution vulnerability Read More »

Citrix users face attack as RCE vulnerability is probed

When Positive Technologies reported a serious flaw in a core element of the Citrix architecture just before Christmas, they predicted up to 80,000 businesses could be at risk. If that vulnerability is exploited, attackers obtain direct access to the company’s local network from the Internet. This attack does not require access to any accounts, and therefore

Citrix users face attack as RCE vulnerability is probed Read More »

Critical Oracle EBS vulnerabilities remain unpatched

Flaws in the Oracle Thin Client Framework API used in the General Ledger and Work in Progress modules of Oracle EBS leave thousands of firms vulnerable to financial fraud. Specialist Oracle security firm Onapsis has released a summary of exploits based on these vulnerabilities which they name Payday. One proof of concept demonstration shows how an

Critical Oracle EBS vulnerabilities remain unpatched Read More »

Scroll to Top