+44 (0)203 88 020 88

Menu

Search

vulnerability management

OpenSSL High Severity Vulnerabilities Patched

Two new high severity vulnerabilities have been identified in the OpenSSL Software Foundation cryptographic library version 3.0.0. This open-source library is used to encrypt HTTPS connections and other communication channels, so has been relied upon by many as a security measure. These new vulnerabilities could cause denial of service or possible remote code execution to

OpenSSL High Severity Vulnerabilities Patched Read More »

Microsoft Azure Vulnerability Exploit in SF Clusters

A spoofing vulnerability in Microsoft Azure Service Fabric can be exploited by attackers to gain admin privileges and take over Service Fabric clusters. Although there are not currently reports of this vulnerability being exploited in the wild, proof of concept (PoC) code for this attack vector does exist. Cloud security platform Orca Security first discovered

Microsoft Azure Vulnerability Exploit in SF Clusters Read More »

Fortinet Critical Authentication Bypass Vulnerability

A communication has been sent by Fortinet to their customers confirming a critical severity vulnerability in FortiOS and FortiProxy. The global cyber security company have warned administrators to update FortiGate firewalls and FortiProxy web proxies to the latest available versions to address this vulnerability. Although a full security advisory has not been released yet for

Fortinet Critical Authentication Bypass Vulnerability Read More »

Microsoft Exchange Server Vulnerabilities Exploited

Two high severity zero-day vulnerabilities for the Microsoft Exchange Server have been found to be exploited in the wild. An elevation of privilege vulnerability, and a remote code execution vulnerability have been used by attackers to gain access into victim’s systems. The Cybersecurity and Infrastructure Security Agency (CISA) recently added these two flaws to their

Microsoft Exchange Server Vulnerabilities Exploited Read More »

RCE Vulnerability in Password Manager Pro

A Zoho ManageEngine vulnerability has been added to the Cybersecurity and Infrastructure Security Agency’s (CISA) known exploited vulnerabilities catalog last week. This remote code execution (RCE) vulnerability affects Password Manager Pro versions 12100 and below, Access Manager Plus versions 4302 and below, and PAM360 versions 5500 and below. Proof of concept (POC) code for an

RCE Vulnerability in Password Manager Pro Read More »

0

No products in the basket.

No products in the basket.