Martes de parches de Microsoft de septiembre de 2023 aborda 61 CVE (CVE-2023-36761)
Microsoft addresses 61 CVEs including two vulnerabilities that were exploited in the wild
AA23-250A: Múltiples agentes maliciosos de estados nación explotan CVE-2022-47966 y CVE-2022-42475
A joint Cybersecurity Advisory examines the exploitation of two critical vulnerabilities by nation-state threat actors.
AA23-215A: Principales vulnerabilidades explotadas de forma rutinaria en 2022
A joint Cybersecurity Advisory collaborated on by multiple international agencies highlights the top routinely exploited vulnerabilities of 2022.
CVE-2023-35078: Vulnerabilidad de acceso API no autenticada de Ivanti Endpoint Manager Mobile (EPMM) / MobileIron Core
Critical vulnerability in a popular mobile device management solution from Ivanti has been exploited in the wild in limited attacks
Preguntas frecuentes de vulnerabilidades de transferencias MOVEit y CL0P Ransomware Gang
Frequently asked questions relating to vulnerabilities in MOVEit Transfer, including one that was exploited by the prolific CL0P ransomware gang.
CVE-2023-20887: VMware Aria Operations para inyección de comandos de redes
VMware issues advisory to address three flaws in its VMware Aria Operations for Networks solution, including a critical command injection flaw assigned a CVSSv3 score of 9.8.
El Martes de parches de Microsoft de junio de 2023 aborda 70 CVE (CVE-2023-29357)
Microsoft addresses 70 CVEs in its June 2023 Patch Tuesday update including six rated as critical.
Volt Typhoon: las autoridades internacionales de ciberseguridad detallan actividad vinculada a agente malicioso patrocinado por el Estado chino
Several international cybersecurity authorities from the United States, United Kingdom, Australia, Canada and New Zealand issue a joint advisory detailing tactics, techniques and procedures used in recent attacks by a Chinese state-sponsored threat actor.
El Martes de parches de Microsoft de mayo de 2023 aborda 38 CVE (CVE-2023-29336)
Microsoft addresses 38 CVEs including three zero-day vulnerabilities, two of which were exploited in the wild.
CVE-2023-20864: VMware Aria Operations para vulnerabilidad de deserialización de registros
VMware issues advisory to address two flaws in its VMware Aria Operations for Logs solution, including a critical deserialization flaw assigned a CVSSv3 score of 9.8.
El Martes de parches de Microsoft de abril de 2023 aborda 97 CVE (CVE-2023-28252)
Microsoft addresses 97 CVEs, including one that was exploited in the wild as a zero day.
El Martes de parches de febrero de 2023 de Microsoft aborda 75 CVE (CVE-2023-23376)
Microsoft addresses 75 CVEs including three zero-day vulnerabilities that were exploited in the wild.