Juniper Networks, a manufacturer of networking equipment, has released patches for over 30 vulnerabilities in Junos OS and Junos OS Evolved. These patches include fixes for nine high-severity vulnerabilities. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given a November 17, 2023, deadline for federal agencies and organizations to …
Read More »CISA Sets a Deadline November 17
WhatsApp privacy feature
WhatsApp Introduces new privacy feature protect IP while Calling
WhatsApp introduces a privacy feature called “Protect IP Address in Calls.” This feature masks users’ IP addresses by relaying the calls through its servers. WhatsApp stated that calls are end-to-end encrypted, meaning that even if a call goes through their servers, they cannot listen to the calls. The main idea …
Read More »
ZDI published the vulnarabilities
New Microsoft Exchange zero-days allow RCE, data theft attacks
Trend Micro’s Zero Day Initiative (ZDI) Thursday (02.11.23) published four zero days vulnerabilities of Microsoft Exchange which can exploit remotely to execute arbitrary code or disclose sensitive information on affected installations. Bleeping Computer reported, these vulnerabilities were reported to Microsoft on September 7th and 8th, 2023. Microsoft acknowledges the reports …
Read More »
NGINX Ingress Controller
Vulnerabilities Uncovered in NGINX Ingress Controller for Kubernetes
Three unpatched security flaws in the NGINX Ingress controller for Kubernetes have been revealed. These flaws have a high severity level and could be used by a malicious actor to steal secret credentials from the cluster. The vulnerabilities are as follows: CVE-2022-4886 (CVSS score: 8.8) – Ingress-nginx path sanitization can …
Read More »F5 warning customer: BIG-IP Vulnerability Allows Remote Code Execution
F5 warned customers about a serious security flaw in BIG-IP that may lead to unauthorized remote code execution. An issue has been identified in the configuration utility component. It is assigned the CVE identifier CVE-2023-46747 and has a CVSS score of 9.8 out of 10. F5 has stated that an …
Read More »CISCO Zero-Day Vulnerabilities exploitation in Bangladesh
The Cyber Threat Intelligence team of BGD e-GOV CIRT has issued a warning about ongoing attacks using two zero-day vulnerabilities in Cisco’s IOS XE Software web UI feature. Successful exploitation attempts have been observed against organizations in Bangladesh. This advisory is intended for IT teams responsible for configuring and managing …
Read More »VMware released update for PoC exploits Vulnerabilities
Multiple vulnerabilities in VMware Aria Operations for Logs were privately reported to VMware. VMware Aria Operations for Logs contains an authentication bypass vulnerability VMware has evaluated the severity of this issue to be in the Important Severity Range with a maximum CVSSv3 base score of 8.1. An unauthenticated, malicious actor …
Read More »Cisco Zero Day Bug Patch coming today
Cisco plans to release a patch for two zero-day flaws in its IOS XE devices on October 22. The first Cisco zero-day bug, which is named CVE-2023-20198, was reported on Oct. 16. By the time it was found, it had already been used by attackers to compromise over 10,000 Cisco …
Read More »Thousand Cisco devices hacked in IOS XE zero-day attacks
Orange’s CERT Coordination Center discovered over 34.5K Cisco IOS XE devices compromised in CVE-2023-20198 attacks. Hackers have used a newly discovered and very serious software vulnerability to hack and infect more than 10,000 Cisco IOS XE devices with harmful software. VulnCheck, a threat intelligence company, reported that a severe vulnerability …
Read More »Cisco warns of IOS XE zero-day actively exploited in attacks
Cisco has discovered a vulnerability in the web UI feature of Cisco IOS XE Software. This vulnerability allows remote attackers to create an account with high privileges on an affected system. They can then use this account to take control of the system. For steps to close the attack vector …
Read More »