HIGH risk OpenSSH vulnerability – CVE-2024-6387

OpenSSH has a high-risk vulnerability, allowing an Unauthenticated Remote Code Execution due to a race condition in signal handling. The vulnerability only affects RHEL9 and derivates. Check our SVG Advisory to learn more about this vulnerability.

read more

HIGH risk OpenStack arbitrary file access vulnerability

A vulnerability CVE-2024-32498 has been found in QCOW2 image processing for Cinder, Glance and Nova. By supplying a specially created QCOW2 image which references a specific data file path, an authenticated user may convince systems to return a copy of that file...

read more

Docker and API security

Many sites use Docker for development or to provide automated deployment of software or containers via Gitlab runners or similar solutions. In the past weeks have seen some incidents related to Docker API misconfiguration and would like to address the security...

read more

Apptainer github/containers/image Vulnerability CVE-2024-3727

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks. For further details, please...

read more

Critical vulnerability in Microsoft Outlook

There is a critical zero click vulnerability in Microsoft Outlook, CVE-2024-30103, which enables remote code execution. When exploited, this vulnerability can enable an attacker to execute arbitrary code on the system, leading to data breaches, unauthorised access and...

read more
Trusted Introducer