TTCSIRT-238.101819: TT-CSIRT ADVISORY – BIND SECURITY UPDATES

TTCSIRT-238.101819: TT-CSIRT ADVISORY – BIND SECURITY UPDATES

The Internet Systems Consortium (ISC) has released security advisories that address vulnerabilities affecting multiple versions of ISC Berkeley Internet Name Domain (BIND). BIND is the most common implementation of the DNS protocol on the Internet. A remote attacker could exploit one of these vulnerabilities to obtain sensitive information or cause a denial of service. TTCSIRT […]

TTCSIRT-237.101619: TT-CSIRT ADVISORY – WORDPRESS SECURITY UPDATES

WordPress version 5.2.4 has been released. WordPress 5.2.3 and prior versions are affected by multiple vulnerabilities. An attacker could exploit some of these vulnerabilities to take control of an affected website. TTCSIRT encourages users and administrators to review the following publications from WordPress and update your website forthwith: New Release Blog Post: https://wordpress.org/news/2019/10/wordpress-5-2-4-security-release/ How to […]

TTCSIRT-236.101619: TT-CSIRT ADVISORY – ADOBE SECURITY UPDATES

Adobe has released security updates to address vulnerabilities in multiple Adobe products. An attacker could exploit some of these vulnerabilities to take control of an affected system. TTCSIRT encourages users and administrators to review the following advisories from Adobe and apply the necessary remediation actions forthwith: Adobe Acrobat and Reader for Windows and macOS https://helpx.adobe.com/security/products/acrobat/apsb19-49.html Adobe […]

TTCSIRT-235.101619: TT-CSIRT ADVISORY – ORACLE SECURITY UPDATES

Oracle has released its Critical Patch Update for October 2019 to address 219 vulnerabilities across multiple products. A remote attacker could exploit some of these vulnerabilities to take control of an affected system. Due to the threat posed by a successful attack, TTCSIRT strongly recommends that administrators apply the Critical Security Patch Update as soon […]

TTCSIRT-234.101419: TT-CSIRT ADVISORY – CHROME SECURITY UPDATES

Google has released Chrome version 77.0.3865.120 for Windows, Mac, and Linux. This new version addresses vulnerabilities that an attacker could exploit to take control of an affected system. TTCSIRT encourages users and administrators to review the following blog post from Google and update to the latest version of Chrome on all devices. Issues addressed include […]

TTCSIRT-233.101019: TT-CSIRT ADVISORY – INTEL SECURITY UPDATES

Intel has released security updates to address vulnerabilities in multiple products. An attacker could exploit some of these vulnerabilities to gain an escalation of privileges on a previously infected machine. TTCSIRT encourages users and administrators to review the following advisories from Intel and apply the necessary remediation actions: CVE-2019-14569 – Potential security vulnerabilities in system […]

TTCSIRT-232.100719: TT-CSIRT ADVISORY – VPN SECURITY UPDATES

The United Kingdom (UK) National Cyber Security Centre (NCSC) has released an alert on advanced persistent threat (APT) actors exploiting vulnerabilities in Virtual Private Network (VPN) applications. Affected applications include those by Fortinet, Palo Alto and Pulse Secure. TTCSIRT encourages users and administrators to read the NCSC alert for more information and see the following […]

TTCSIRT-231.100219: TT-CSIRT ADVISORY – ANDROID SECURITY UPDATES

Please be advised that multiple vulnerabilities have been discovered in the Google Android 10 operating system (OS), the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of a privileged process. These vulnerabilities could be exploited […]

TTCSIRT-230.100219: TT-CSIRT ADVISORY – PHP SECURITY VULNERABILITY

A vulnerability has been discovered in PHP, which could allow an attacker to execute arbitrary code. PHP is a programming language originally designed for use in web-based applications with HTML content. It supports a wide variety of platforms and is used by numerous web-based software applications. Successfully exploiting this vulnerability could allow for arbitrary code […]

TTCSIRT-229.092719: TT-CSIRT ADVISORY – APPLE SECURITY UPDATES

Apple has released security updates to address vulnerabilities in multiple products. An attacker could exploit one of these vulnerabilities to obtain access to sensitive information. TTCSIRT encourages users and administrators to review Apple’s security updates page and apply the necessary updates: https://support.apple.com/en-us/HT201222   1) CVE-2019-8641 – A remote attacker may be able to cause unexpected […]