SonicWall Issues Patches for a New Critical Flaw in SMA 100 Series Devices – Tempemail

Network security company SonicWall has addressed a critical security vulnerability affecting its Secure Mobile Access (SMA) 100 series appliances that can permit remote, unauthenticated attackers to gain administrator access on targeted devices remotely. Tracked as CVE-2021-20034, the arbitrary file deletion flaw is rated 9.1 out of a maximum of 10 Continue Reading

Apple Issues Urgent Updates to Fix New Zero-Day Linked to Pegasus Spyware – Tempemail

Apple has released iOS 14.8, iPadOS 14.8, watchOS 7.6.2, macOS Big Sur 11.6, and Safari 14.1.2 to fix two actively exploited vulnerabilities, one of which defeated extra security protections built into the operating system. The list of two flaws is as follows – CVE-2021-30858 (WebKit) – A use after free Continue Reading

Cisco Issues Patch for Critical Enterprise NFVIS Flaw — PoC Exploit Available – Tempemail

Cisco has patched a critical security vulnerability impacting its Enterprise Network Function Virtualization Infrastructure Software (NFVIS) that could be exploited by an attacker to take control of an affected system. Tracked as CVE-2021-34746, the weakness has been rated 9.8 out of a maximum of 10 on the Common Vulnerability Scoring Continue Reading

Kaseya Issues Patches for Two New 0-Day Flaws Affecting Unitrends Servers – Tempemail

U.S. technology firm Kaseya has released security patches to address two zero-day vulnerabilities affecting its Unitrends enterprise backup and continuity solution that could result in privilege escalation and authenticated remote code execution. The two weaknesses are part of a trio of vulnerabilities discovered and reported by researchers at the Dutch Continue Reading

VMware Issues Patches to Fix New Flaws Affecting Multiple Products – Tempemail

VMware on Wednesday shipped security updates to address vulnerabilities in multiple products that could be potentially exploited by an attacker to take control of an affected system. The six security weaknesses (from CVE-2021-22022 through CVE-2021-22027, CVSS scores: 4.4 – 8.6) affect VMware vRealize Operations (prior to version 8.5.0), VMware Cloud Continue Reading

VMware Issues Patches to Fix Critical Bugs Affecting Multiple Products – Tempemail

VMware has released security updates for multiple products to address a critical vulnerability that could be exploited to gain access to confidential information. Tracked as CVE-2021-22002 (CVSS score: 8.6) and CVE-2021-22003 (CVSS score: 3.7), the flaws affect VMware Workspace One Access (Access), VMware Identity Manager (vIDM), VMware vRealize Automation (vRA), Continue Reading

Cisco Issues Critical Security Patches to Fix Small Business VPN Router Bugs – Tempemail

Networking equipment major Cisco has rolled out patches to address critical vulnerabilities impacting its Small Business VPN routers that could be abused by a remote attacker to execute arbitrary code and even cause a denial-of-service (DoS) condition. The issues, tracked as CVE-2021-1609 (CVSS score: 9.8) and CVE-2021-1610 (CVSS score: 7.2), Continue Reading

US surgeon general issues official warning over vaccine misinformation but won’t pinpoint culprits- Tempemail

US Surgeon General Vivek Murthy has issued a warning that misinformation is now the main public health threat driving the United States’ ongoing Covid-19 outbreak. The US’ top doctor issued an official warning about the spread of false information on Thursday, and appeared at the daily White House press briefing Continue Reading

Microsoft Issues Emergency Patch for Critical Windows PrintNightmare Vulnerability – Tempemail

Microsoft has shipped an emergency out-of-band security update to address a critical zero-day vulnerability — known as “PrintNightmare” — that affects the Windows Print Spooler service and can permit remote threat actors to run arbitrary code and take over vulnerable systems. Tracked as CVE-2021-34527 (CVSS score: 8.8), the remote code Continue Reading

Apple Issues Urgent Patches for 2 Zero-Day Flaws Exploited in the Wild – Tempemail

Apple on Monday shipped out-of-band security patches to address two zero-day vulnerabilities in iOS 12.5.3 that it says are being actively exploited in the wild. The latest update, iOS 12.5.4, comes with three security fixes, including a memory corruption issue in the ASN.1 decoder (CVE-2021-30737) and two flaws concerning the Continue Reading