VMware Workspace ONE Remote Code Execution Exploit
This Metasploit module combines two vulnerabilities in order achieve remote code execution in the context of the horizon user. The first vulnerability, CVE-2022-22956, is an authentication bypass in O ...
Continue Reading
May 01, 2023
MERCURY and DEV-1084: Destructive attack on hybrid environment
> **April 2023 update** â Microsoft Threat Intelligence has shifted to a new threat actor naming taxonomy aligned around the theme of weather. **MERCURY** is now tracked as **Mango Sandstorm** ...
Continue Reading
May 01, 2023
MERCURY and DEV-1084: Destructive attack on hybrid environment
> **April 2023 update** â Microsoft Threat Intelligence has shifted to a new threat actor naming taxonomy aligned around the theme of weather. **MERCURY** is now tracked as **Mango Sandstorm** ...
Continue Reading
May 01, 2023
Kamailio vulnerabilities
## Releases
* Ubuntu 20.04 LTS
* Ubuntu 18.04 ESM
* Ubuntu 16.04 ESM
## Packages
* kamailio - very fast, dynamic and configurable SIP server
It was discovered that Kamailio did not properly sa ...
Continue Reading
May 01, 2023
Amazon Linux 2023 : xmlrpc-c, xmlrpc-c-apps, xmlrpc-c-c++ (ALAS2023-2023-068)
It is, therefore, affected by a vulnerability as referenced in the ALAS2023-2023-068 advisory.
- xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as chec ...
Continue Reading
March 22, 2023
IBM Aspera Faspex < 4.4.2 Patch Level 2 Multiple Vulnerabilities
According to its self-reported version, the instance of IBM Aspera Faspex running on the remote web server is prior to 4.4.2 Patch Level 2. It is, therefore, affected by multiple vulnerabilities, incl ...
Continue Reading
March 20, 2023
SUSE SLED15 / SLES15 Security Update : conmon, libcontainers-common, libseccomp, podman (SUSE-SU-2022:23018-1)
The remote SUSE Linux SLED15 / SLES15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2022:23018-1 advisory.
- An information disclosure vulner ...
Continue Reading
March 10, 2023
Tenable Nessus 8.15.x >= 8.15.4 and < 8.15.9 Multiple Vulnerabilities (TNS-2023-10)
According to its self-reported version, the Tenable Nessus application running on the remote host is between 8.15.4 and 8.15.8. It is, therefore, affected by multiple vulnerabilities in OpenSSL prior ...
Continue Reading
March 09, 2023
CISA’s KEV Catalog Updated with 3 New Flaws Threatening IT Management Systems
[]()
The U.S. Cybersecurity and Infrastructure Security Agen ...
Continue Reading
March 08, 2023