Posts for category: Vulnerabilities Weekly Summaries

VMware vCenter Server Vulnerability

(By: Frank Wood on September 30, 2021) Executive Summary VMware vCenter is a server management software that is “centrally visible, simplified and efficient management at scale, and ...

Zoho ManageEngine ADSelfService Plus Vulnerability

(By: Frank Wood on September 26, 2021) Executive Summary Zoho’s ManageEngine ADSelfService Plus is an active directory (AD) password management and single sign on utility that allows users ...

HAProxy Vulnerability

(By: Frank Wood on September 17, 2021) Executive Summary HAProxy is one of the most widely used open-source software load balancer proxy servers for Hypertext Transfer Protocol (HTTP) and ...

Atlassian Confluence Server and Data Center Vulnerability

(By: Frank Wood on September 10, 2021) Executive Summary Atlassian Confluence is a service that allows users within an organization to share, collaborate, and organize projects with each ...

Pulse VPN Vulnerability

(By: William Beard on August 10, 2021) Executive Summary FireEye and Pulse Secure are currently investigating a new vulnerability in the Pulse Connect Secure Virtual Private Network (VPN), ...

Cring Ransomware Attack

(By: William Beard on April 29, 2021) Executive Summary Kaspersky reported that several European industrial enterprises were attacked using the Cring ransomware in early 2021.  These ...

Microsoft Exchange Server Zero-Days

(By: William Beard on March 25, 2021) Executive Summary CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-26865 are four zero-day vulnerabilites that were used recently by the ...

SolarWinds Hack

(By: William Beard on February 18, 2021) Introduction In June 2020, SolarWinds, a software development company based out of Austin, Texas, reported a breach in their supply chain for Orion ...

Comcast TV Remote “WarezTheRemote” Vulnerability can Turn into a Listening Device

Introduction Comcast security researcher team disclosed a vulnerability found in the Comcast XR11 TV remote called “WarezTheRemote” allowing an attacker to record audio without the user’s ...

Microsoft Windows “ZeroLogon” Vulnerability Impacts Samba

Introduction Earlier this month Microsoft announced a privilege-escalation vulnerability or “ZeroLogon” with a Common Vulnerability Scoring System (CVSS) score of 10.0 of 10.0 making it ...