Advisories

JetBrains TeamCity Critical Vulnerability (CVE-2024-27198 and CVE-2024-27199)

On March 4th, 2024, software development company JetBrains disclosed two critical vulnerabilities (CVE-2024-27198 and CVE-2024-27199) in their Continuous Integration / Continuous Deliver (CI/CD) product, TeamCity.

Mar 8, 2024 - 1 Min Read

Severe ConnectWise ScreenConnect Vulnerability (CVE-2024-1709 & CVE-2024-1708)

On February 19th, 2024, ConnectWise published a security bulletin reporting two impactful vulnerabilities in their product ConnectWise.  One of these vulnerabilities is particularly severe, with a critical rating of 10.0 on the CVSS scale, indicating the highest level of risk when successfully exploited.

Feb 20, 2024 - 2 Min Read

Microsoft Outlook Critical Vulnerability Under Active Exploitation (CVE-2024-21410)

On February 13th, 2024, Microsoft addressed several vulnerabilities as part of its monthly Patch Tuesday.  One of those vulnerabilities was in Microsoft Exchange Server and was reported as critical because the attack vector is 1) remote, 2) unauthenticated, and 3) low complexity. 

Feb 14, 2024 - 2 Min Read

Ivanti Critical Vulnerabilities Under Active Exploitation (CVE-2023-46805, CVE-2024-21887)

On January 10th, 2024, Ivanti published a vulnerability report for two products: Ivanti Connect Secure and Ivanti Policy Secure Gateways.  The two vulnerabilities (CVE-2023-46805, CVE-2024-21887) are reported to be under active exploitation at this time, according to joint reporting from Volexity who discovered the attacks. 

Jan 24, 2024 - 1 Min Read