Security News > 2020 > October

How to download the Windows 10 20H2 ISO from Microsoft
2020-10-20 14:20

In this article we will explain how to download the Windows 10 20H2 ISO directly from Microsoft. How to download a Windows 10 20H2 ISO from Microsoft.

Adobe fixes 18 critical bugs affecting its Windows, macOS apps
2020-10-20 13:55

Adobe has released security updates to address critical vulnerabilities affecting ten of its Windows and macOS products that could allow attackers to execute arbitrary code on devices running vulnerable software versions. Adobe has released a security update for Adobe InDesign that fixes an Uncontrolled Search Path vulnerability in the Creative Cloud Desktop Application installer for Windows that could lead to arbitrary code execution.

Identity-Focused Intelligence Firm 4iQ Raises $30 Million
2020-10-20 13:28

Identity-focused intelligence company 4iQ on Tuesday announced that it has raised $30 million in a Series C funding round led by ForgePoint Capital and Benhamou Global Ventures. 4iQ told SecurityWeek that it will use the money to scale go-to-market activities and look at opportunities to build out its portfolio, either organically, through added investments, or inorganically, through partnerships and/or acquisitions.

The new Microsoft Edge is now mandatory in Windows 10 20H2
2020-10-20 13:11

Today's release of Windows 10 20H2 is the first release to automatically replace Microsoft Edge Legacy with the new Chromium-based Microsoft Edge regardless of any policies you have in place. When installed, Microsoft Edge Legacy will automatically be removed and be replaced with the new Microsoft Edge.

Mobile Browser Bugs Open Safari, Opera Users to Malware
2020-10-20 13:00

A set of address-bar spoofing vulnerabilities that affect a number of mobile browsers open the door for malware delivery, phishing and disinformation campaigns. "Essentially, if your browser tells you that a pop-up notification or a page is 'from' your bank, your healthcare provider or some other critical service you depend on, you really should have some mechanism of validating that source. In mobile browsers, that source begins and ends with the URL as shown in the address bar. The fact of the matter is, we really don't have much else to rely on."

Confronting Data Risk in the New World of Work
2020-10-20 13:00

As we move from "Just make it work" to embracing this new world of work, we've got to also confront a whole new world of risk. Users intending to make folders shareable instead made them publicly accessible, unwittingly exposing all manner of sensitive, regulated and highly valuable data to anyone who had the right URL. What's Being Exposed? Valuable Data.

Windows 10 20H2 is released, here are the new features
2020-10-20 13:00

Microsoft is rolling out the next version of Windows 10 called "20H2" and the update is available for those who manually check for updates using the Settings app. 20H2 Update is not a huge release and it does not bring a major overall to key features of Windows 10, but Microsoft says this update comes with a lot of improvements that should improve overall user experience.

Homebrew: How to install reconnaissance tools on macOS
2020-10-20 12:58

We'll guide you through the process of using Homebrew package manager to install security tools on macOS to perform reconnaissance, discovery, and fingerprinting of the devices on your network. Evidenced through the classic "I'm a Mac" ads, Macs were not immune to malware: It's just that with such a negligible market share, threat actors did not really target Apple devices as much as devices running Windows, which posed a much larger target-with greater rewards for their efforts.

How to Seize the OT Security Opportunity and Accelerate Your Digital Transformation
2020-10-20 12:45

A few months ago, the U.S. National Security Agency and Cybersecurity and Infrastructure Security Agency issued an alert stating, "We are in a state of heightened tensions and additional risk and exposure" across OT and control systems, which are critical to operations and therefore valuable for attackers. While we've quickly pivoted to put in new solutions and processes to address a new, distributed model, what do we do next? How do we take what we've learned this year, capitalize on the change in mindset that it is possible to move fast, and apply it to seize the OT security opportunity in 2021? Here are three areas of focus to help you build on your progress.

Serious Vulnerability in GitHub Enterprise Earns Researcher $20,000
2020-10-20 12:33

A security researcher says he has earned $20,000 for a high-severity GitHub Enterprise vulnerability that might have allowed an attacker to execute arbitrary commands. GitHub Enterprise, the on-premises version of GitHub.com, is designed to make it easier for large enterprise software development teams to collaborate.