DefendEdge Logo
Categories
alerts

30M Dell Devices at Risk for Remote BIOS Attacks, RCE

Four separate security bugs would give attackers almost complete control and persistence over targeted devices, thanks to a faulty update mechanism.
Categories
alerts

Critical Palo Alto Cyber-Defense Bug Allows Remote ‘War Room’ Access

Remote, unauthenticated cyberattackers can infiltrate and take over the Cortex XSOAR platform, which anchors unified threat intelligence and incident responses.
Categories
alerts

VMware Releases Security Updates

Original release date: June 23, 2021

VMware has released security updates to address vulnerabilities in the VMware Carbon Black App Control management server as well as VMware Tools for Windows, VMware Remote Console for Windows, and VMware App Volumes. An attacker could exploit these vulnerabilities to take control of an affected system.

CISA encourages users and administrators to review VMware Security Advisory Advisories VMSA-2021-0012 and VMSA-2021-0013 and apply the necessary updates.

This product is provided subject to this Notification and this Privacy & Use policy.

Categories
alerts

Unpatched Linux Marketplace Bugs Allow Wormable Attacks, Drive-By RCE

A pair of zero-days affecting Pling-based marketplaces could allow for some ugly attacks on unsuspecting Linux enthusiasts — with no patches in sight.
Categories
alerts

SonicWall ‘Botches’ October Patch for Critical VPN Bug

Company finally rolls out the complete fix this week for an RCE flaw affecting some 800,000 devices that could result in crashes or prevent users from connecting to corporate resources.
Categories
alerts

Cryptominers Slither into Python Projects in Supply-Chain Campaign

These code bombs lurk in the PyPI package repository, waiting to be inadvertently baked into software developers’ applications.
Categories
alerts

Email Bug Allows Message Snooping, Credential Theft

A year-old proof-of-concept attack that allows an attacker to bypass TLS email protections to snoop on messages has been patched.
Categories
alerts

Lexmark Printers Open to Arbitrary Code-Execution Zero-Day

“No remedy available as of June 21, 2021,” according to the researcher who discovered the easy-to-exploit, no-user-action-required bug.
Categories
alerts

Bugs in NVIDIA’s Jetson Chipset Opens Door to DoS Attacks, Data Theft

Chipmaker patches nine high-severity bugs in its Jetson SoC framework tied to the way it handles low-level cryptographic algorithms.
Categories
alerts

Agent Tesla RAT Returns in COVID-19 Vax Phish

An unsophisticated campaign shows that the pandemic still has long legs when it comes to being social-engineering bait.

For Emergency Cyber Security Incident Response please email RedTeam@DefendEdge.com