Today Microsoft released patches to fix 94 vulnerabilities out of which 27 fix remote code execution issues which can allow an attackers to remotely take control of victim machines. This is a massive update and fixes more than double the number of vulnerabilities as compared to the last two months. Top priority goes to a vulnerability […]
from Microsoft Fixes 94 Security Issues in Massive June Update
Showing posts with label amolsarwate. Show all posts
Showing posts with label amolsarwate. Show all posts
Tuesday, June 13, 2017
Wednesday, May 10, 2017
Adobe Fixes Half a Dozen Flash Vulnerabilities and More
Flash has been the top target for exploit kits and we have observed that defender behavior, i.e. how fast patches are applied along with other factors in the threat landscape could have led to a decline in the number of Flash vulnerabilities being weaponized in exploit kits. In 2016, the time to patch 80% of Flash vulnerabilities […]
from Adobe Fixes Half a Dozen Flash Vulnerabilities and More
from Adobe Fixes Half a Dozen Flash Vulnerabilities and More
Tuesday, May 9, 2017
Microsoft Fixes Malware Protection Engine and Several 0-Day Vulnerabilities, and Deprecates SHA-1
Hours before today’s Patch Tuesday release on the eve of May 8, Microsoft released an emergency updated to fix a vulnerability in their Malware Protection Engine. This critical vulnerability allows an attacker to take complete control of the victim’s machine by just sending an e-mail attachment. When the malware protection engine scans the attachment the […]
from Microsoft Fixes Malware Protection Engine and Several 0-Day Vulnerabilities, and Deprecates SHA-1
from Microsoft Fixes Malware Protection Engine and Several 0-Day Vulnerabilities, and Deprecates SHA-1
Tuesday, April 25, 2017
Shadow Brokers Fix for IBM Lotus Domino Released
IBM has released a patch for Lotus Domino to plug a security flaw which was disclosed in the latest Shadow Broker revelations. Lotus Domino includes an IMAP server. IMAP or Internet Message Access Protocol is an Internet standard protocol used by e-mail clients to retrieve e-mail messages from the mail server over a TCP/IP connection. […]
from Shadow Brokers Fix for IBM Lotus Domino Released
from Shadow Brokers Fix for IBM Lotus Domino Released
Wednesday, April 19, 2017
Oracle Plugs Struts hole along with 299 Total Vulnerabilities
Today Oracle released a total of 299 new security fixes across all product families. It is important to note that it fixed 25 instances of the infamous Apache Struts vulnerability which could allow a remote attacker to take complete control of the server running Struts. The struts fix was applied to 19 instances of Oracle […]
from Oracle Plugs Struts hole along with 299 Total Vulnerabilities
from Oracle Plugs Struts hole along with 299 Total Vulnerabilities
Wednesday, April 12, 2017
April 2017 Patch Tuesday Video Highlights
Microsoft Fixes 45 Vulnerabilities with new Security Update Guide and says goodbye to Security Bulletins. Adobe Fixes Flash, PDF reader and Photoshop.
from April 2017 Patch Tuesday Video Highlights
from April 2017 Patch Tuesday Video Highlights
Tuesday, April 11, 2017
Microsoft Fixes 45 Vulnerabilities with new Security Update Guide – says goodbye to Security Bulletins
Today is the first month since 1998 in which Microsoft stopped releasing security bulletins with the familiar MSxx-xxx format and replaced it with the new security update guide. We talked about this change earlier in a few blog posts and finally today it’s time to say good bye to security bulletins which essentially combined related […]
from Microsoft Fixes 45 Vulnerabilities with new Security Update Guide – says goodbye to Security Bulletins
from Microsoft Fixes 45 Vulnerabilities with new Security Update Guide – says goodbye to Security Bulletins
Tuesday, March 14, 2017
Massive Security Update from Microsoft for March
Today Microsoft released a massive security update consisting of 17 security bulletins that fixed a total of 134 vulnerabilities. Out of the 17 security bulletins 8 were marked as Critical which could lead to remote code execution while the remaining were marked as Important. Since there were no patches released for February, in one way, […]
from Massive Security Update from Microsoft for March
from Massive Security Update from Microsoft for March
Sunday, March 12, 2017
Apache Struts Jakarta QID 11771 for detecting CVE-2017-5638
Today we released a new update to QID 11771 for detecting Apache Struts vulnerability CVE-2017-5638. The QID was released earlier this week and today’s blog post is about the new update. This update has a unique detection method which makes it more reliable and less prone to false negatives. The update is based on web server capabilities and removes the dependency on index.action […]
from Apache Struts Jakarta QID 11771 for detecting CVE-2017-5638
from Apache Struts Jakarta QID 11771 for detecting CVE-2017-5638
Wednesday, March 8, 2017
Apache Struts Jakarta Multipart parser Remote Code Execution
A remote code execution vulnerability exists in Apache Jakarta multipart parser. If exploited, this issue can allow attacker to remotely and without need of any credentials take complete control of the system. Needless to say we think this is a high priority issue and the consequence of a successful attack is dire. The issue is […]
from Apache Struts Jakarta Multipart parser Remote Code Execution
from Apache Struts Jakarta Multipart parser Remote Code Execution
Tuesday, January 10, 2017
January 2017 Patch Tuesday Video Highlights
Adobe started 2017 with release of two security bulletins – one for Flash and the other for Acrobat and Reader. Microsoft released three security updates for Office, Edge and LSASS.
from January 2017 Patch Tuesday Video Highlights
from January 2017 Patch Tuesday Video Highlights
Adobe Security Update for January: Flash and Acrobat Fixed
Adobe started 2017 with release of two security bulletins – one for Flash and the other for Acrobat and Reader. Since Flash vulnerabilities have a high potential of being weaponized in exploit kits, organizations should apply both the updates as soon as possible. A total of 13 vulnerabilities were fixed in the Flash update, while […]
from Adobe Security Update for January: Flash and Acrobat Fixed
from Adobe Security Update for January: Flash and Acrobat Fixed
Monday, September 26, 2016
Problem with OpenSSL Patches of September 22, 2016
Today, OpenSSL has released an update advising of a problem with patches that was released last week on September 22. The first offending patch was for CVE-2016-6309, and it could result in a crash or even execution of attacker-supplied code resulting in compromise of the patched machine. This issue only affects OpenSSL 1.1.0a, released on 22nd September […]
from Problem with OpenSSL Patches of September 22, 2016
from Problem with OpenSSL Patches of September 22, 2016
Subscribe to:
Posts (Atom)