El Martes de parches de diciembre de 2023 de Microsoft aborda 33 CVE (CVE-2023-36019)
Microsoft addresses 33 CVEs in its December 2023 Patch Tuesday release, with no zero-day vulnerabilities disclosed this month....
CVE-2023-4966 (CitrixBleed): invalide las sesiones activas o persistentes para evitar un mayor riesgo
Patching CitrixBleed isn’t enough; organizations need to invalidate active or persistent session tokens as the these tokens can be used to compromise networks and bypass authentication measures including multifactor authentication...
Preguntas frecuentes para CitrixBleed (CVE-2023-4966)
Frequently asked questions relating to a critical vulnerability in Citrix NetScaler that has been under active exploitation for over a month, including by ransomware groups....
El Martes de parches de Microsoft de noviembre de 2023 aborda 57 CVE (CVE-2023-36025)
Microsoft addresses 57 CVEs, including three zero-day vulnerabilities that were exploited in the wild....
CVE-2023-22518: vulnerabilidad crítica de autorización inadecuada en Confluence Data Center and Server de Atlassian
Atlassian warns of public vulnerability details for a critical flaw in Confluence Data Center and Server, as its CISO urges organizations to apply patches immediately....
CVE-2023-46747: vulnerabilidad crítica de evasión de autenticación en F5 BIG-IP
A critical authentication bypass vulnerability in F5’s BIG-IP could allow remote, unauthenticated attackers to execute system commands. Organizations are encouraged to apply patches as soon as possible....
La actualización de parche crítico de Oracle para octubre de 2023 aborda 176 CVE
Oracle addresses 176 CVEs in its fourth quarterly update of 2023 with 387 patches, including 46 critical updates....
CVE-2023-4966: divulgación de información de Citrix NetScaler ADC y NetScaler Gateway explotada en la realidad
A critical information disclosure vulnerability in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway has been exploited in the wild as a zero-day vulnerability. Organizations are urged to patch immediately....
CVE-2023-20198: Vulnerabilidad de día cero en Cisco IOS XE explotada en la realidad
A maximum severity CVSS 10 zero-day vulnerability in Cisco IOS XE has been exploited in the wild. Organizations should apply the mitigation steps from Cisco as soon as possible until patches are released....
Martes de parches de Microsoft de octubre de 2023 aborda 103 CVE (CVE-2023-36563, CVE-2023-41763)
Microsoft addresses 103 CVEs including two vulnerabilities that were exploited in the wild....
CVE-2023-38545, CVE-2023-38546: preguntas frecuentes sobre nuevas vulnerabilidades
Frequently asked questions relating to two vulnerabilities patched in curl version 8.4.0...
Estafas de MrBeast: cuentas verificadas, DeepFakes usados en suplantaciones de identidad para promover obsequios falsos en YouTube y TikTok
MrBeast, the most popular YouTube creator as of October 2023, has been impersonated in a variety of scams on YouTube and TikTok, including a recent deepfake promoting a free iPhone giveaway...