ProxyNotShell, OWASSRF, TabShell: Coloque parches en sus Microsoft Exchange Servers Now
Several flaws in Microsoft Exchange Server disclosed over the last two years continue to be valuable exploits for attackers as part of ransomware and targeted attacks against organizations that have yet to patch their systems. Patching the flaws outlined below is strongly recommended....
Sandworm APT implementa el nuevo SwiftSlicer Wiper usando la directiva de grupo de Active Directory
Sandworm, the Russian-backed APT responsible for NotPetya in 2017, has recently attacked an Ukrainian organization using a new wiper, SwiftSlicer....
La actualización de parche crítico de Oracle para enero de 2023 aborda 183 CVE
Oracle addresses 183 CVEs in its first quarterly update of quarterly with 327 patches, including 71 critical updates....
El Martes de parches de Microsoft de enero de 2023 aborda 98 CVE (CVE-2023-21674)
Microsoft addresses 98 CVEs including a zero-day vulnerability that was exploited in the wild....
CVE-2022-47523: Vulnerabilidad de inyección de código SQL de Password Manager Pro, PAM360 y Access Manager Plus de ManageEngine
Zoho patches a newly disclosed high-severity SQL injection flaw in several ManageEngine products; attackers have historically targeted several ManageEngine products over the last three years....
CVE-2022-47939: Vulnerabilidad crítica RCE en Linux Kernel
A critical remote code execution vulnerability in the Linux kernel has been publicly disclosed by Trend Micro's Zero Day Initiative in its ZDI-22-1690 advisory. The vulnerability has been given a CVSSv3 of 10.0. There are no reports of active exploitation....
CVE-2022-37958: Preguntas frecuentes para vulnerabilidad crítica de Microsoft SPNEGO NEGOEX
Microsoft recently reclassified a vulnerability in SPNEGO NEGOEX, originally patched in September, after a security researcher discovered that it can lead to remote code execution. Organizations are urged to apply these patches as soon as possible....
El Martes de parches de diciembre de 2022 de Microsoft aborda 48 CVE (CVE-2022-44698)
Microsoft addresses 48 CVEs including two zero-day vulnerabilities, one that has been exploited in the wild (CVE-2022-44698) and one that was publicly disclosed prior to a patch being available (CVE-2022-44710)....
CVE-2022-27518: RCE sin autenticar en Citrix ADC y puerta de enlace
Citrix has patched a critical remote code execution vulnerability in its Gateway and ADC products. This vulnerability has reportedly been exploited as a zero day; organizations should patch urgently....
CVE-2022-42475: Fortinet coloca parches de día cero en VPN de FortiOS SSL
Fortinet has patched a zero day buffer overflow in FortiOS that could lead to remote code execution. There has been a report of active exploitation and organizations should patch urgently....
CVE-2022-27510: Critical Citrix ADC and Gateway Authentication Bypass Vulnerability
Citrix publishes an advisory to address multiple flaws in its ADC and Gateway products, including a critical vulnerability....
Microsoft’s November 2022 Patch Tuesday Addresses 62 CVEs (CVE-2022-41073)
Microsoft addresses 62 CVEs including four zero-day vulnerabilities that were exploited in the wild....