• Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution

    Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution

    MS-ISAC ADVISORY NUMBER: 2023-094 DATE(S) ISSUED: 08/23/2023 OVERVIEW: Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Google Chrome is a web browser used to access the internet. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the…

    Continue Reading

  • VMSA-2023-0017

    VMSA-2023-0017

    Moderate Advisory ID: VMSA-2023-0017 CVSSv3 Range: 5.3 Issue Date: 2023-08-03 Updated On: 2023-08-03 (Initial Advisory) CVE(s): CVE-2023-34037, CVE-2023-34038 Synopsis: VMware Horizon Server updates address multiple security vulnerabilities (CVE-2023-34037, CVE-2023-34038) 1. Impacted Products VMware Horizon Server 2. Introduction Multiple vulnerabilities in VMware Horizon Server were responsibly reported to VMware. Updates are available to remediate these vulnerabilities…

    Continue Reading

  • 2022 Top Routinely Exploited Vulnerabilities

    2022 Top Routinely Exploited Vulnerabilities

    SUMMARY The following cybersecurity agencies coauthored this joint Cybersecurity Advisory (CSA): United States: The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Federal Bureau of Investigation (FBI) Australia: Australian Signals Directorates Australian Cyber Security Centre (ACSC) Canada: Canadian Centre for Cyber Security (CCCS) New Zealand: New Zealand National Cyber Security Centre (NCSC-NZ)…

    Continue Reading

  • Threat Actors Exploiting Ivanti EPMM Vulnerabilities

    Threat Actors Exploiting Ivanti EPMM Vulnerabilities

    SUMMARY The Cybersecurity and Infrastructure Security Agency (CISA) and the Norwegian National Cyber Security Centre (NCSC-NO) are releasing this joint Cybersecurity Advisory (CSA) in response to active exploitation of CVE-2023-35078 and CVE-2023-35081. Advanced persistent threat (APT) actors exploited CVE-2023-35078 as a zero day from at least April 2023 through July 2023 to gather information from…

    Continue Reading