CVE-2024-0012, CVE-2024-9474: vulnerabilidades de día cero en Palo Alto PAN-OS explotadas en la realidad
Palo Alto Networks confirmed two zero-day vulnerabilities were exploited as part of attacks in the wild against PAN-OS devices, with one being attributed to Operation Lunar Peek....
El Martes de parches de Microsoft de noviembre de 2024 aborda 87 CVE (CVE-2024-43451, CVE-2024-49039)
Microsoft addresses 87 CVEs and one advisory (ADV240001) in its November 2024 Patch Tuesday release, with four critical vulnerabilities and four zero-day vulnerabilities, including two that were exploited in the wild....
CVE-2024-47575: preguntas frecuentes sobre FortiJump Zero-Day en FortiManager y FortiManager Cloud
Frequently asked questions about a zero-day vulnerability in Fortinet’s FortiManager that has reportedly been exploited in the wild....
Desde errores hasta vulneraciones: 25 CVE significativas mientras que la CVE de MITRE tiene 25
Twenty five years after the launch of CVE, the Tenable Security Response Team has handpicked 25 vulnerabilities that stand out for their significance....
La actualización de parche crítico de Oracle para octubre de 2024 aborda 198 CVE
Oracle addresses 198 CVEs in its fourth quarterly update of 2024 with 334 patches, including 35 critical updates....
Martes de parches de Microsoft de octubre de 2024 aborda 117 CVE (CVE-2024-43572, CVE-2024-43573)
Microsoft addresses 117 CVEs with three rated as critical and four zero-day vulnerabilities, two of which were exploited in the wild....
CVE-2024-47076, CVE-2024-47175, CVE-2024-47176, CVE-2024-47177: Frequently Asked Questions About Common UNIX Printing System (CUPS) Vulnerabilities
Frequently asked questions about multiple vulnerabilities in the Common UNIX Printing System (CUPS) that were disclosed as zero-days on September 26....
Martes de parches de Microsoft de septiembre de 2024 aborda 79 CVE (CVE-2024-43491)
Microsoft addresses 79 CVEs with seven critical vulnerabilities and four zero-day vulnerabilities, including three that were exploited in the wild....
CVE-2021-20123, CVE-2021-20124: vulnerabilidades DrayTek detectadas por Tenable Research añadidas a CISA KEV
With patches out for three years, attackers have set their sights on a pair of vulnerabilities affecting DrayTek VigorConnect....
AA24-241A : boletín de ciberseguridad conjunto sobre atacantes cibernéticos basados en Irán que van contra organizaciones estadounidenses
A joint Cybersecurity Advisory highlights Iran-based cyber actor ransomware activity targeting U.S. organizations. The advisory includes CVEs exploited, alongside techniques, tactics and procedures used by the threat actors....
CVE-2024-7593: Vulnerabilidad de evasión de autenticación de Ivanti Virtual Traffic Manager
Ivanti released a patch for a critical severity authentication bypass vulnerability and a warning that exploit code is publicly available...
El Martes de parches de Microsoft de agosto de 2024 aborda 88 CVE
Microsoft addresses 88 CVEs with seven critical vulnerabilities and 10 zero-day vulnerabilities, six of which were exploited in the wild....