CISA Releases Malware Analysis Reports on Barracuda Backdoors

CISA has published three malware analysis reports on malware variants associated with exploitation of CVE-2023-2868. CVE-2023-2868 is a remote command injection vulnerability affecting Barracuda Email Security Gateway (ESG) Appliance, versions…

Comments Off on CISA Releases Malware Analysis Reports on Barracuda Backdoors

Ivanti Releases Security Updates for EPMM to address CVE-2023-35081

Ivanti has identified and released patches for a directory traversal vulnerability (CVE-2023-35081, CWE-22) in Ivanti Endpoint Manager Mobile (EPMM). This vulnerability allows an attacker with EPMM administrator privileges to write…

Comments Off on Ivanti Releases Security Updates for EPMM to address CVE-2023-35081

MAR-10454006-r3.v1 Exploit Payload Backdoor

   Notification This report is provided "as is" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained…

Comments Off on MAR-10454006-r3.v1 Exploit Payload Backdoor

MAR-10454006-r2.v1 SEASPY Backdoor

   Notification This report is provided "as is" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained…

Comments Off on MAR-10454006-r2.v1 SEASPY Backdoor

MAR-10454006-r1.v2 SUBMARINE Backdoor

   Notification This report is provided "as is" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained…

Comments Off on MAR-10454006-r1.v2 SUBMARINE Backdoor

Preventing Web Application Access Control Abuse

SUMMARY The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), U.S. Cybersecurity and Infrastructure Security Agency (CISA), and U.S. National Security Agency (NSA) are releasing this joint Cybersecurity Advisory to…

Comments Off on Preventing Web Application Access Control Abuse

Vulnerability Summary for the Week of July 17, 2023

  High Vulnerabilities Primary Vendor -- Product Description Published CVSS Score Source & Patch Info oliva_expertise -- oliva_expertise_eks   Improper Neutralization of Special Elements used in an SQL Command ('SQL…

Comments Off on Vulnerability Summary for the Week of July 17, 2023

Atlassian Releases Security Updates

Atlassian has released its Security Bulletin for July 2023 to address vulnerabilities in Confluence Data Center & Server (CVE-2023-22505 and CVE-2023-22508) and Bamboo Data Center (CVE-2023-22506). An attacker can exploit these vulnerabilities…

Comments Off on Atlassian Releases Security Updates