2020

VMware security updates for ESXi, Workstation, Fusion, and Cloud Foundation (VMSA-2020-0015)

VMware issued a security advisory for ten vulnerabilities that impact VMware ESXi, Workstation, Fusion and Cloud Foundation products. An attacker could exploit one of these vulnerabilities and take control of an unpatched system.

VMware security updates for ESXi, Workstation, Fusion, and Cloud Foundation (VMSA-2020-0015) Read More »

Adobe releases security updates for Magento (APSB20-41) and EOL reminder

Adobe has released security updates to address vulnerabilities in Magento Commerce 1 and Magento Open Source 1. The company also warned that older Magento 1.x versions will be end of life (EOL) and no longer get software support after this patch update.

Adobe releases security updates for Magento (APSB20-41) and EOL reminder Read More »

Microsoft releases out-of-band patch for Windows 10 vulnerability (CVE-2020-1441)

Microsoft has released an out-of-band patch to fix a Windows 10 spatial data service vulnerability. An attacker could exploit the vulnerability to overwrite or modify a protected file leading to privilege escalation.

Microsoft releases out-of-band patch for Windows 10 vulnerability (CVE-2020-1441) Read More »

Drupal patches two critical security vulnerabilities

Drupal has released security updates to address Critical cross site request forgery (CSRF) and Arbitrary PHP code execution vulnerabilities affecting multiple versions of Drupal. A remote attacker could exploit these vulnerabilities to compromise an affected system. In the first security advisory SA-CORE-2020-004, Drupal patched one Critical CSRF vulnerability CVE-2020-13663. This issues exists when Drupal core Form

Drupal patches two critical security vulnerabilities Read More »

Cisco releases Critical Treck IP Stack advisory and 7 other High severity updates

Cisco has released a Critical security advisory for three Treck IP Stack vulnerabilities, as well as seven other High severity advisories that affect multiple products.

Cisco releases Critical Treck IP Stack advisory and 7 other High severity updates Read More »

Adobe security updates for Illustrator, After Effects and other products

Adobe has released security updates to address vulnerabilities in Adobe After Effects, Audition, Campaign Classic, Illustrator, Premiere Pro and Premiere Rush products.

Adobe security updates for Illustrator, After Effects and other products Read More »

Ripple20 zero-day vulnerabilities impact hundreds of millions of IoT devices

Security researchers have identified a series of 19 zero-day vulnerabilities in a lightweight TCP/IP stack library used in many IoT products. The vulnerabilities dubbed Ripple20 likely impact hundreds of millions of IoT devices.

Ripple20 zero-day vulnerabilities impact hundreds of millions of IoT devices Read More »