View Post

Microsoft Security Advisory (HAFNIUM) – 2021 Mar 3rd

In Cyber Security by Matsco Engineering Team

Microsoft has detected multiple 0-day exploits being used to attack on-premises versions of Microsoft Exchange Server in limited and targeted attacks. In the attacks observed, the threat actor used these vulnerabilities to access on-premises Exchange servers which enabled access to email accounts, and allowed installation of additional malware to facilitate long-term access to victim environments.

View Post

VMware Security Advisory – 2021 Feb 24th

In Cyber Security by Matsco Engineering Team

Multiple vulnerabilities were identified in VMware products, a malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.

View Post

Apple Security Advisory – 2021 Jan 27th

In Cyber Security by Matsco Engineering Team

Multiple vulnerabilities were identified in Apple products, a remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution, information disclosure and elevation of privilege on the targeted system. Some vulnerabilities are being exploited in the wild.