Advisory: Ruckus ICX switch XSS and CSRF vulnerability

Last updated on September 1, 2023 at 10:44 am

We’re aware of a vulnerability (CVE-2023-39904, CVE-2023-39905, CVE-2023-39906) in the web-based management interface of the Ruckus ICX switch product line that could allow a remote attacker to execute XSS and CSRF attacks against the user of the interface. To exploit...

Advisory: Google ChromeOS vulnerabilities (MS-ISAC 2023-095)

Last updated on September 1, 2023 at 10:44 am

We’re aware of multiple vulnerabilities that have been discovered in Google ChromeOS, the most severe of which could allow a remote attacker to conduct arbitrary code execution. Depending on the privileges associated with the targeted user, an attacker could install...

Advisory: New vulnerabilities affecting PaperCut MF/NG

Last updated on August 16, 2023 at 05:19 pm

PaperCut have released a new patch for Papercut NG/MF to address multiple vulnerabilities which are currently being exploited. If you are using this product, we recommend you upgrade your PaperCut application to version 22.1.3. Please follow the instructions on...

Advisory: Fortinet SSL VPN vulnerability – CVE 2023-27997

Last updated on August 14, 2023 at 06:35 pm

We’re aware of a critical Remove Code Execution (RCE) vulnerability affecting Fortinet’s SSL VPN functionality. This vulnerability can be exploited without credentials and affects all SSL VPN appliances, even if multi-factor authentication is enabled. Due to the...

Advisory: cPanel admin console vulnerability CVE-2023-29489 

Last updated on August 14, 2023 at 06:34 pm

We're aware of a cPanel admin console vulnerability with a severity rating of medium. cPanel is a common website and server management software. Exploitation of this vulnerability could allow a malicious actor to perform remote code execution against any user who...

Advisory: Critical vulnerability affecting PaperCut MF/NG

Last updated on August 14, 2023 at 04:20 pm

We’re aware of a critical Remote Code Execution (RCE) vulnerability affecting PaperCut MF or NG. This vulnerability is currently exploited in the wild. The affected PaperCut products are: PaperCut MF or NG version 8.0 or later, on all OS platforms PaperCut MF or NG...

Advisory: Security issue with 3CX desktop application

Last updated on August 14, 2023 at 04:19 pm

3CX, a company that supplies telephony solutions, has been affected by a supply chain attack affecting software downloaded from their website. This attack can affect users running the 3CX desktop clients for MacOS and Windows. The recommended action is to remove these...