DefendEdge Logo
Categories
alerts

Critical Citrix Bug Shuts Down Network, Cloud App Access

The distributed computing vendor patched the flaw, affecting Citrix ADC and Gateway, along with another flaw impacting availability for SD-WAN appliances.
Categories
alerts

Massive Zero Day Hole Found in Palo Alto Security Appliances

Researchers have a working exploit for the vulnerability (now patched), which allows for unauthenticated RCE and affects an estimated 70,000+ VPN/firewalls.
Categories
alerts

Microsoft Nov. Patch Tuesday Fixes Six Zero-Days, 55 Bugs

Experts urged users to prioritize patches for Microsoft Exchange and Excel, those favorite platforms so frequently targeted by cybercriminals and nation-state actors.
Categories
alerts

Microsoft Releases November 2021 Security Updates

Original release date: November 9, 2021

Microsoft has released updates to address multiple vulnerabilities in Microsoft software. An attacker can exploit some of these vulnerabilities to take control of an affected system.

CISA encourages users and administrators to review Microsoft’s November 2021 Security Update Summary and Deployment Information and apply the necessary updates.

This product is provided subject to this Notification and this Privacy & Use policy.

Categories
alerts

Citrix Releases Security Updates

Original release date: November 9, 2021

Citrix has released security updates to address vulnerabilities affecting multiple versions of Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP. An attacker could exploit these vulnerabilities to cause a denial-of-service condition.

CISA encourages users and administrators to review Citrix Security Bulletin CTX330728 and apply the necessary updates as soon as possible.

This product is provided subject to this Notification and this Privacy & Use policy.

Categories
alerts

12 New Flaws Used in Ransomware Attacks in Q3

The Q3 2021 report revealed a 4.5% increase in CVEs associated with ransomware and a 3.4% increase in ransomware families compared with Q2 2021.
Categories
alerts

SAP Releases November 2021 Security Updates

Original release date: November 9, 2021

SAP has released security updates to address vulnerabilities affecting multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system.

CISA encourages users and administrators to review the SAP Security Notes for November 2021 and apply the necessary updates.

This product is provided subject to this Notification and this Privacy & Use policy.

Categories
alerts

CISA Releases Security Advisory on Siemens Nucleus Real-Time Operating Systems

Original release date: November 9, 2021

CISA has released an Industrial Control Systems (ICS) advisory detailing multiple vulnerabilities found in Siemens Nucleus Real-Time Operating Systems (RTOS) and supporting libraries. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.

CISA encourages users and administrators to review ICS Advisory: ICSA-21-313-03 Siemens Nucleus RTOS TCP/IP Stack for more information and apply the necessary mitigations.

This product is provided subject to this Notification and this Privacy & Use policy.

Categories
alerts

Security Researchers Reveal Activity Targeting ManageEngine ADSelfService Plus

Original release date: November 9, 2021

On September 16, CISA released a joint alert on exploitation of a vulnerability (CVE-2021-40539) in ManageEngine ADSelfService Plus. On November 8, security researchers from Palo Alto Networks and Microsoft Threat Intelligence Center (MSTIC) released separate reports on targeted attacks against ManageEngine ADSelfService Plus.  

CISA encourages organizations to review the indicators of compromise and other technical details in the following reports to uncover any malicious activity within their networks.

This product is provided subject to this Notification and this Privacy & Use policy.

Categories
alerts

Multiple BusyBox Security Bugs Threaten Embedded Linux Devices

Researchers discovered 14 vulnerabilities in the ‘Swiss Army Knife’ of the embedded OS used in many OT and IoT environments. They allow RCE, denial of service and data leaks.

For Emergency Cyber Security Incident Response please email RedTeam@DefendEdge.com