Vulnerabilities & Exploits

Securezoo Cybersecurity Threat Center blog posts of new vulnerabilities and exploits.

APT41 launches broad cyber campaign with multiple exploits

Researchers from FireEye have discovered Chinese cyber threat group APT41 carry out a broad cyber campaign between January 20 and March 11, 2020. The actors have attempted to exploit vulnerabilities in Citrix NetScaler/ADC, Cisco routers, and Zoho ManageEngine Desktop Central products against 75 FireEye customers.

APT41 launches broad cyber campaign with multiple exploits Read More »

Google releases Chrome security update (80.0.3987.149)

Google has released Chrome 80.0.3987.149 for Windows, Mac and Linux, as well as a new version of Chrome for Android. The update addresses 13 security fixes to include 9 High severity vulnerabilities.

Google releases Chrome security update (80.0.3987.149) Read More »

Adobe patches ColdFusion, PhotoShop, Acrobat and Reader (and other products)

Adobe has released security updates for ColdFusion, PhotoShop, Acrobat and Reader, Genuine Integrity Service, Experience Manager and Bridge products.

Adobe patches ColdFusion, PhotoShop, Acrobat and Reader (and other products) Read More »

Trend Micro patches two zero-day vulnerabilities under active attack in the wild

Trend Micro has patched five vulnerabilities in multiple products. The updates address two zero-days – one Critical risk vulnerability CVE-2020-8467 and another High risk vulnerability CVE-2020-8468 under active attack in the wild. In addition, the company also patched three other Critical vulnerabilities that require no authentication to exploit.

Trend Micro patches two zero-day vulnerabilities under active attack in the wild Read More »

VMware patches critical vmnetdhcp vulnerability (CVE-2020-3947) in VMware Workstation and Fusion

VMware has released patches for a critical vulnerability in VMware Workstation and Fusion products. The company also fixed high severity vulnerabilities in VMware Horizon Client for Windows and VMRC for Windows.

VMware patches critical vmnetdhcp vulnerability (CVE-2020-3947) in VMware Workstation and Fusion Read More »

Organizations need heightened level of Enterprise VPN security in the wake of Coronavirus Pandemic

To prepare for possible impacts of Coronavirus Disease 2019 (COVID-19), more organizations are electing to have their employees work remotely from home. With that responsibility, more organizations will need to adopt a heightened level of security to protect themselves from attackers who look to exploit weaknesses in enterprise virtual private networks (VPNs).

Organizations need heightened level of Enterprise VPN security in the wake of Coronavirus Pandemic Read More »

Microsoft March 2020 Security Updates, fix for SMBv3 RCE vulnerability (updated)

Microsoft released the March 2020 Security Updates that include 115 unique vulnerability fixes, 26 of those rated critical. This is the largest patch release in Microsoft’s history. Microsoft also issued guidance and a new security update to fix an SMBv3 RCE vulnerability dubbed SMBGhost.

Microsoft March 2020 Security Updates, fix for SMBv3 RCE vulnerability (updated) Read More »