Business

Comment on vulnerabilities in VMware’s vRealize Operations 3o1o5a

“The most severe flaw, CVE-2021-21975, is a server-side request forgery (SSRF) vulnerability in the vROPs Manager API. An unauthenticated, remote attacker could exploit this vulnerability by sending a specially crafted request to the vulnerable vROPs […]

Business

Comment on Clubhouse App: Tenable 3ma5m

Clubhouse, an invite-only app available on iOS is seemingly the next big thing in social media for casual, drop-in audio conversations with anyone or sometimes even celebrities. As of Feb 2021, the app had 8 […]

Business

Comment on Vulnerabilities in F5 BIG-IP and BIG-IQ from Tenable n6u2e

“F5 recently addressed several vulnerabilities in its BIG-IP and BIG-IQ, of which four were rated critical. The most severe of these critical vulnerabilities is CVE-2021-22986, an unauthenticated remote command execution flaw in the iControl REST […]

Business

Microsoft’s March 2021 Patch Wednesday Addresses 82 CVEs 1t1m6t

This month Patch Wednesday contains 82 CVEs, a fix for CVE-2021-26411, a remote code execution flaw in Microsoft Internet Explorer and a reminder to organizations to apply patches to address the Proxylogon and other Microsoft […]

Business

Microsoft Patches Four Exchange Server Zero-Day Vulnerabilities Exploited in the Wild 223j5i

Microsoft has issued out-of-band patches for multiple zero-day vulnerabilities exploited in the wild by a nation-state threat actor called HAFNIUM. Satnam Narang, Staff Research Engineer at Tenable says that by Microsoft choosing to patch these […]

Business

Comment on vulnerabilities in VMware vCenter Server from Tenable 2q3i2a

“At least four proof-of-concept exploit scripts for CVE-2021-21972, a critical remote code execution flaw in VMWare’s vCenter Server solution are currently available. We know that the availability of proof-of-concept code or exploit scripts following the […]