Advisories

Critical Vulnerability in Ivanti EPM (CVE-2024-29847)

On September 10th, 2024, Ivanti published an advisory detailing multiple critical severity vulnerabilities in their Endpoint Management (EPM) product. The EPM product manages IT assets, troubleshooting, and deployment of software and operating systems.

Sep 13, 2024 - 2 Min Read

Critical Vulnerability in OpenSSH (CVE-2024-6387)

On July 1st, Qualys Security publicly disclosed details regarding an impactful vulnerability in OpenSSH, an essential software tool used globally for secure network communications and remote system administration. OpenSSH is integral to maintaining confidentiality and control over remote sessions, underpinning a vast array of critical infrastructure across the internet.

Jul 6, 2024 - 6 Min Read

Critical Vulnerability in FileCatalyst Workflow (CVE-2024-5276)

On June 25th, software company Fortra disclosed a critical severity vulnerability in their managed file transfer software application, FileCatalyst Workflow. The vulnerability is being tracked as CVE-2024-5276 which is an SQL Injection vulnerability that allows an attacker to modify application data.

Jun 29, 2024 - 2 Min Read

Critical Vulnerability in MOVEit Transfer (CVE-2024-5806)

On June 25th, software company Progress publicly disclosed a critical severity vulnerability in their managed file transfer software application, MOVEit Transfer. The vulnerability is being tracked as CVE-2024-5806 and allows a remote attacker to bypass authentication and log in as any valid user on the system.

Jun 26, 2024 - 6 Min Read

Multiple Critical Vulnerbailities in Adobe Magento, Commerce, and Commerce Webhooks Plugin

On June 11th, Adobe released a security bulletin covering several vulnerabilities in their Magento, Commerce, and Commerce Webhooks Plugin software. There were ten vulnerabilities, seven of which had a CVSS severity of “critical”, with scores of 8 or above.

Jun 13, 2024 - 2 Min Read

Critical Vulnerability in Outlook (CVE-2024-30103)

On June 11th, cybersecurity firm Morphisec published an article detailing a critical vulnerability in Microsoft Outlook. Successful exploitation of this vulnerability will enable attackers to run arbitrary code by sending a specially designed email.

Jun 12, 2024 - 2 Min Read

Critical Vulnerability in PHP CGI (CVE-2024-4577)

On June 6th, cybersecurity firm Devcore published an advisory detailing a critical bug in the widely used web framework PHP-CGI. Successful exploitation of this vulnerability allows a remote attacker without credentials to perform remote code execution (RCE) on a targeted machine.

Jun 11, 2024 - 3 Min Read

High Severity Vulnerability in SolarWinds Serv-U (CVE-2024-28995)

On June 5th, SolarWinds disclosed a vulnerability in their file transfer application Serv-U. The vulnerability is being tracked as CVE-2024-28995 and is a directory transversal vulnerability that would allow an attacker to read sensitive files on the target machine.

Jun 7, 2024 - 2 Min Read

Snowflake Data Breach

On May 31st, cybercrime intelligence firm Hudson Rock published a report detailing communications with a threat actor behind recent high-profile, high-impact breaches of Ticketmaster and Santander Bank. In their conversation, the threat actor revealed they were able to compromise Ticketmaster and Santander data due to an initial breach they executed against cloud data services company Snowflake.

May 31, 2024 - 2 Min Read

Critical Vulnerability in CheckPoint Quantum (CVE-2024-24919)

On May 27th, the Check Point Research Division reported a vulnerability in certain Check Point Quantum Security Gateway devices. The vulnerability is being tracked as CVE-2024-24919, which provides a remote attacker the ability to access protected information on an affected device without credentials.

May 29, 2024 - 2 Min Read