Please be advised that Microsoft has released a security advisory to address a remote code execution vulnerability, CVE-2021-1647, in Microsoft Defender. A remote attacker can exploit this vulnerability to take control of an affected system. This vulnerability was detected in exploits in the wild. TT-CSIRT is urging all entities (public and private) to download and install …
Please be advised that Microsoft has released January 2021 Security Updates which prevents remote attackers from exploiting vulnerabilities to gain control of affected systems. The following software will be updated: Microsoft Windows Microsoft Edge (EdgeHTML-based) Microsoft Office and Microsoft Office Services and Web Apps Microsoft Windows Codecs Library Visual Studio SQL Server Microsoft Malware Protection …
FireEye has uncovered a widespread campaign that they are tracking as UNC2452. The actors behind this campaign gained access to numerous public and private organizations around the world. They gained access to victims via trojanized updates to SolarWind’s Orion IT monitoring and management software. FireEye stated that this campaign may have begun as early as …
Google has released Chrome version 87.0.4280.88 for Windows, Mac, and Linux. This version addresses vulnerabilities that an attacker could exploit to take control of an affected system. It is encouraged that users and administrators review and apply the necessary updates. For further information and support, please visit:Chrome Release
Cisco has released a security advisory on an Arbitrary Code Execution vulnerability—CVE-2020-3556—affecting Cisco AnyConnect Secure Mobility Client devices. A remote attacker could exploit this vulnerability to take control of an affected system. It is encouraged that users and administrators to review and apply the necessary updates or workarounds. For further information and support, please visit the following link:Cisco …
The Apache Software Foundation has released a security advisory to address a vulnerability in Apache Tomcat. An attacker could exploit this vulnerability to cause a denial-of-service condition. It is encouraged that users and administrators review the Apache security advisory and upgrade to the appropriate version. Please visit the link below for further support:CVE-2020-17527
Mozilla has released a security update to address a vulnerability in Thunderbird. An attacker could exploit this vulnerability to take control of an affected system. It is encouraged that users and administrators to review the Mozilla Security Advisory for and apply the necessary update. Please visit the link below:Thunderbird 78.5.1
Xerox has released security updates for DocuShare 6.6.1, 7.0, and 7.5 to address a vulnerability that could allow an unauthenticated attacker to obtain sensitive information. It is urged that users and administrators review Xerox and apply the necessary updates. Please visit the link below:Mini Bulletin XRX20W
Apple has released security updates to address vulnerabilities in iCloud for Windows. An attacker could exploit some of these vulnerabilities to take control of an affected system. It is encouraged that users and administrators review the Apple security page for and apply the necessary updates. Please visit the link provided below:iCloud for Windows 11.5
VMware has released workarounds to address a vulnerability—CVE-2020-4006—in VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector. An attacker could exploit this vulnerability to take control of an affected system. It is encouraged, users and administrators review VMware Security Advisory and apply the necessary workarounds. For further information, please visit the link below:VMSA-2020-0027