A Patch Tuesday da Microsoft de julho de 2023 aborda 130 CVEs (CVE-2023-36884)
Microsoft addresses 130 CVEs including five that were exploited in the wild as zero-day vulnerabilities and guidance on the malicious use of Microsoft signed drivers.
CVE-2023-33299: Vulnerabilidade crítica de execução remota de código no FortiNAC
Fortinet has released a patch fixing a remote code execution vulnerability in several versions of FortiNAC
Perguntas frequentes sobre vulnerabilidades de transferência do MOVEit e gangue CL0P Ransomware
Frequently asked questions relating to vulnerabilities in MOVEit Transfer, including one that was exploited by the prolific CL0P ransomware gang.
CVE-2023-20887: Operações do VMware Aria para injeção de comando nas redes
VMware issues advisory to address three flaws in its VMware Aria Operations for Networks solution, including a critical command injection flaw assigned a CVSSv3 score of 9.8.
Patch Tuesday da Microsoft de Junho de 2023 aborda 70 CVEs (CVE-2023-29357)
Microsoft addresses 70 CVEs in its June 2023 Patch Tuesday update including six rated as critical.
CVE-2023-27997: Heap-Based Buffer Overflow in Fortinet FortiOS and FortiProxy SSL-VPN (XORtigate)
Fortinet says a critical flaw in its SSL-VPN product may have been exploited in the wild in a limited number of cases. Organizations are strongly encouraged to apply these patches immediately.
CVE-2023-34362: MOVEIt transfere vulnerabilidade crítica de dia zero explorada na natureza
Discovery of a new zero-day vulnerability in MOVEit Transfer becomes the second zero-day disclosed in a managed file transfer solution in 2023, with reports suggesting that threat actors have stolen data from a number of organizations.
Volt Typhoon: International Cybersecurity Authorities Detail Activity Linked to Chinese-State Sponsored Threat Actor
Several international cybersecurity authorities from the United States, United Kingdom, Australia, Canada and New Zealand issue a joint advisory detailing tactics, techniques and procedures used in recent attacks by a Chinese state-sponsored threat actor.
Agências da Austrália e dos EUA publicam aviso conjunto de segurança cibernética sobre grupo BianLian Ransomware
The FBI, ACSC and CISA have released a joint cybersecurity advisory discussing the BianLian ransomware group.
Patch Tuesday de Maio de 2023 da Microsoft lista 38 CVEs (CVE-2023-29336)
Microsoft addresses 38 CVEs including three zero-day vulnerabilities, two of which were exploited in the wild.
CVE-2023-20864: VMware Aria Operations for Logs Deserialization Vulnerability
VMware issues advisory to address two flaws in its VMware Aria Operations for Logs solution, including a critical deserialization flaw assigned a CVSSv3 score of 9.8.
Oracle April 2023 Critical Patch Update Addresses 231 CVEs
Oracle addresses 231 CVEs in its second quarterly update of 2023 with 433 patches, including 74 critical updates.