Apache Log4j Deserialization Remote Code Execution (CVE-2019-17571) Vulnerability Threat Alert

Vulnerability Description On December 19 local time, Apache Software Foundation (ASF) officially released a security advisory, announcing that Apache Log4j has a deserialization issue that could cause remote code execution (CVE-2019-17571). Log4j is a Java-based open-source logging tool from the Apache Software Foundation. Log4j 1.2 includes a SocketServer class which...

Advisory: Drupal fixes multiple vulnerabilities

Overview On December 18, local time, Drupal officially issued a security advisory to announce multiple vulnerabilities in its core products, including one critical vulnerability and three medium-risk vulnerabilities. (mais…)

Microsoft’s December 2019 Security Update Fixes 38 Security Vulnerabilities

Overview Microsoft released 2019 December security update on Tuesday that fixes 38 security issues ranging from simple spoofing attacks to remote code execution in various products, including End of Life Software, Microsoft Graphics Component, Microsoft Office, Microsoft Scripting Engine, Microsoft Windows, None, Open Source Software, Servicing Stack Updates, Skype for...

Adobe Security Advisory for December Security Updates

Overview On December 11, local time, Adobe officially released a December security update that fixes multiple vulnerabilities in Adobe's many products, including Adobe Photoshop CC, Adobe Acrobat and Reader, Brackets, and Adobe ColdFusion. For details, visit the following link: https://helpx.adobe.com/security.html (mais…)