Systems Engineering is aware of the vulnerabilities recently found in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). Exploits on unmitigated appliances have been observed.
SECURITY ALERT: FortiOS & FortiProxy heap-based buffer overflow vulnerability: FG-IR-23-097
Systems Engineering is aware of the following vulnerability in FortiOS.
CVE-2023-27997/ FG-IR-23-097: FortiOS & FortiProxy - Heap buffer overflow in Secure Socket Layer Virtual Private Network (SSL-VPN) pre-authentication.
FortiGuard has rated this vulnerability as a Critical risk.
Apple has released a critical security update to address zero-day vulnerabilities in both iPhone and iPad, as well as Mac devices. If you have not already installed the most recent version to your Apple devices (16.4.1 for the iPhone and iPad, and Ventura 13.3.1 for Mac computers), please complete this update as soon as possible.
Beginning May 8, 2023, Microsoft will implement a security upgrade within its Microsoft Authenticator application for multifactor authentication (MFA). Current users of "push notifications" within the authenticator app (our recommended method) will move to a number-matching procedure for improved sign-in security.
SECURITY ALERT: Microsoft has released information on a recent vulnerability in the Outlook client on Windows devices CVE-2023-23397
Systems Engineering is aware of the following vulnerability in Microsoft Outlook, Elevation of Privilege Vulnerability CVE-2023-23397.
Microsoft rates this vulnerability as CRITICAL.
Systems Engineering is aware of the following vulnerability in FortiGate Firewalls, FortiOS: CVE-2023-25610 / FG-IR-23-001 | FortiOS / FortiProxy - Heap buffer underflow in the administrative interface.
FortiGuard rates this vulnerability as a CRITICAL RISK.
Systems Engineering is aware of the major security flaw affecting Citrix Virtual Apps and Desktops: CVE-2023-24483.
The vulnerability's severity is rated as HIGH.