CVE-2022-27511、CVE-2022-27512:Patches for Two Citrix Application Delivery Management Vulnerabilities
Citrix patches a “nasty bug” in its Application Delivery Management solution that is difficult to exploit.
Microsoft’s June 2022 Patch Tuesday Addresses 55 CVEs (CVE-2022-30190)
Microsoft addresses 55 CVEs in its June 2022 Patch Tuesday release, including three critical flaws.
CVE-2022-26134:Zero-Day Vulnerability in Atlassian Confluence Server and Data Center Exploited in the Wild
A critical vulnerability in Atlassian Confluence Server and Data Center has been exploited in the wild by multiple threat actors. Organizations should review and implement mitigation guidance until a patch becomes available.
CVE-2022-30190:Zero Click Zero Day in Microsoft Support Diagnostic Tool Exploited in the Wild
Microsoft confirms remote code execution vulnerability in Microsoft Windows Support Diagnostic Tool that has been exploited in the wild since at least April.
Twitter Crypto Scams: Bored Ape Yacht Club, Azuki and Other Projects Impersonated to Steal NFTs, Digital Currencies
Scammers are using verified and unverified accounts to impersonate notable NFT projects like Bored Ape Yacht Club and others, tagging Twitter users to drive them to phishing websites.
CVE-2022-22972: VMware 修補了更多 Workspace ONE 存取弱點 (VMSA-2022-0014)
我們強烈建議企業和政府機構遵循 VMware 和美國網路安全暨基礎架構安全局的警告,修補兩個最新公布的 VMware 產品弱點。
Microsoft 2022 年 5 月的 Patch Tuesday 解決了 73 個 CVE (CVE-2022-26925)
Microsoft 在其 2022 年 5 月發表的 Patch Tuesday 中解決了 73 個 CVE,包括 2 個零時差弱點,其中一個已遭到猖獗利用。
CVE-2022-1388: F5 BIG-IP 中的身分驗證迴避
CVE-2022-1388:F5 BIG-IP 中的身分驗證迴避 F5 修補了 BIG-IP 系列產品中的身分驗證迴避弱點,它會導致任意指令的執行。 This vulnerability is actively being exploited. Update May 10: The Identifying Affected Systems section now…
Hot Patches for Log4Shell Introduced Multiple Vulnerabilities in Amazon Web Services
Hot Patches for Log4Shell Introduced Multiple Vulnerabilities in Amazon Web Services Amazon Web Services has addressed vulnerabilities introduced by the hot patches released in response to the Log4Shell vulnerability in December. Background On April 19, researchers with Palo Alto’s…
Oracle April 2022 Critical Patch Update Addresses 221 CVEs
Oracle addresses 221 CVEs in its second quarterly update of 2022 with 520 patches, including 27 critical updates.
Microsoft’s April 2022 Patch Tuesday Addresses 117 CVEs (CVE-2022-24521)
Microsoft’s April 2022 Patch Tuesday Addresses 117 CVEs (CVE-2022-24521) Microsoft addresses 117 CVEs in its April 2022 Patch Tuesday release, including two zero-day vulnerabilities, one of which was exploited in the wild and reported to Microsoft by the National Security Agency. …