Security Updates & Patches

Securezoo Cybersecurity Threat Center blog posts of new security updates and patches.

Microsoft August 2022 Security Updates addresses 121 vulnerabilities (17 Critical and 1 zero-day)

The Microsoft August 2022 Security Updates includes patches and advisories for 121 vulnerabilities, 17 of those rated Critical severity and one zero-day CVE-2022-34713 exploited in the wild.

Microsoft August 2022 Security Updates addresses 121 vulnerabilities (17 Critical and 1 zero-day) Read More »

CISA adds Zimbra vulnerability (CVE-2022-27924) to Known Exploited Vulnerabilities Catalog

The Cybersecurity and Infrastructure Security Agency (CISA) has added one Zimbra vulnerability to its Known Exploited Vulnerabilities Catalog based on evidence that cyber criminals are actively exploiting the vulnerabilities.

CISA adds Zimbra vulnerability (CVE-2022-27924) to Known Exploited Vulnerabilities Catalog Read More »

Cisco releases Critical advisory for Small Business RV routers

Cisco has released a Critical security update for three vulnerabilities in Small Business RV Routers.  An unauthenticated, remote attacker could execute arbitrary code or cause a denial of service (DoS) condition on an unpatched device.

Cisco releases Critical advisory for Small Business RV routers Read More »

Google releases Chrome 104 security update with fixes for 27 vulnerabilities (7 High severity)

Google has released Chrome 104.0.5112.79 (Mac/Linux) and 104.0.5112.79/80/81 (Windows), with fixes for 27 vulnerabilities (7 rated High severity). Additionally, Google also published new Chrome security updates for iOS and Android.

Google releases Chrome 104 security update with fixes for 27 vulnerabilities (7 High severity) Read More »

Knotweed threat actors exploit Microsoft and Adobe 0-days and deliver Subzero malware

Knotweed threat actors have exploited Microsoft and Adobe 0-day vulnerabilities in targeted attacks against European and Central American customers. The actors also developed Subzero malware used in these attacks.

Knotweed threat actors exploit Microsoft and Adobe 0-days and deliver Subzero malware Read More »

CISA adds Questions for Confluence App Hard-coded Credentials Vulnerability (CVE-2022-26138) to Known Exploited Vulnerabilities Catalog

The Cybersecurity and Infrastructure Security Agency (CISA) has added a Critical Questions for Confluence App Hard-coded Credentials Vulnerability (CVE-2022-26138) to its Known Exploited Vulnerabilities Catalog.

CISA adds Questions for Confluence App Hard-coded Credentials Vulnerability (CVE-2022-26138) to Known Exploited Vulnerabilities Catalog Read More »

Samba patches 5 vulnerabilities, 1 rated High severity (CVE-2022-32744)

Samba has released software updates to fix five vulnerabilities in multiple Samba software products. One of the fixed issues could allow Samba AD users to forge password change requests for any user.

Samba patches 5 vulnerabilities, 1 rated High severity (CVE-2022-32744) Read More »

PrestaShop websites vulnerable to major SQL Injection attacks

PrestaShop websites are reported vulnerable to a major SQL Injection vulnerability (tracked as CVE-2022-36408) and have been exploited in the wild since July 2022.

PrestaShop websites vulnerable to major SQL Injection attacks Read More »