Security Announcement:

November 3, 2022

Early November Security Alerts You Must Be Aware of – Dropbox and Fortinet

Updated on November 8th, 2022

Security Issues

November 2022 kicks off with a cluster of cybersecurity alerts. Two of the most prominent ones we have identified this week include Dropbox and Fortinet

Dropbox

Issue

A successful phishing campaign accessed Dropbox code stored in GitHub.

The issue has been resolved and no content, passwords, or payment information was accessed.

What should you do?

If you notice something suspicious with your Dropbox – report it!

To get the complete story read the original post here: https://dropbox.tech/security/a-recent-phishing-campaign-targeting-dropbox

Fortinet

Issue

Over a dozen Fortinet product vulnerabilities have been discovered with 6 of them being flagged as high severity.

Read the full article by Eduard Kovacs here: https://www.securityweek.com/fortinet-patches-6-high-severity-vulnerabilities

Citrix

Issue

On Nov. 8, 2022, Citrix published a security bulletin for Citrix ADC and Citrix Gateway that covers three vulnerabilities — one a critical severity vulnerability. If exploited, these vulnerabilities could result in the following security issues:

  • Critical Severity – Unauthorized access to Gateway user capabilities – CVE-2022-27510 
    • Affected products: Citrix ADC and Citrix Gateway
  • High Severity – Remote desktop takeover via phishing – CVE-2022-27513
    • Affected products: Citrix ADC and Citrix Gateway
  • Medium Severity — User login brute force protection functionality bypass – CVE-2022-27516
    • Affected products: Citrix ADC and Citrix Gateway

The bulletin can be found here: https://support.citrix.com/article/CTX463706

For detailed information read our November 9th blog post.

Contact Cornerstone.IT with any questions or assistance regarding these updates.

Cornerstone.IT