Security News > 2021

Adobe Patches Reader Vulnerability Exploited in the Wild
2021-02-09 18:29

Adobe on Tuesday announced the availability of patches for 50 vulnerabilities across six of its products, including a zero-day vulnerability in Reader that has been exploited in the wild. The exploited vulnerability is tracked as CVE-2021-21017 and it was reported to Adobe anonymously.

Windows 10 Cumulative Updates KB4601315 & KB4601319 released
2021-02-09 18:29

As part of the February Patch cycle, Microsoft is rolling out a new cumulative update for all supported version of Windows. The cumulative update with security fixes is rolling out to PCs with October 2020 Update, May 2020 Update, November 2019 Update, and May 2019 Update.

Microsoft February 2021 Patch Tuesday fixes 56 flaws, 1 zero-day
2021-02-09 18:25

Today is Microsoft's February 2021 Patch Tuesday, so please be buy your Windows administrators some snacks to keep their energy up throughout the day. With today's update, Microsoft has fixed for 56 vulnerabilities, with eleven classified as Critical, two as Moderate, and 43 as Important.

New BendyBear APT malware gets linked to Chinese hacking group
2021-02-09 18:09

Unit 42 researchers today have shared info on a new polymorphic and "Highly sophisticated" malware dubbed BendyBear, linked to a hacking group with known ties to the Chinese government. The malware has features and behavior that strongly resemble those of the WaterBear malware family, active since at least as early 2009.

Researcher hacks over 35 tech firms in novel supply chain attack
2021-02-09 18:04

A researcher managed to breach over 35 major companies' internal systems, including Microsoft, Apple, PayPal, Shopify, Netflix, Yelp, Tesla, and Uber, in a novel software supply chain attack. Unlike traditional typosquatting attacks that rely on social engineering tactics or the victim misspelling a package name, this particular supply chain attack is more sophisticated as it needed no action by the victim, who automatically received the malicious packages.

Researcher hacks Microsoft, Apple, more in novel supply chain attack
2021-02-09 18:04

A researcher managed to breach over 35 major companies' internal systems, including Microsoft, Apple, PayPal, Shopify, Netflix, Yelp, Tesla, and Uber, in a novel software supply chain attack. Unlike traditional typosquatting attacks that rely on social engineering tactics or the victim misspelling a package name, this particular supply chain attack is more sophisticated as it needed no action by the victim, who automatically received the malicious packages.

Adobe fixes critical Reader vulnerability exploited in the wild
2021-02-09 17:30

Adobe has released security updates that address an actively exploited vulnerability in Adobe Reader and other critical bugs in Adobe Acrobat, Magento, Photoshop, Animate, Illustrator, and Dreamweaver. In total, the company addressed fifty security vulnerabilities affecting seven products, with many of them rated as critical as they allow local arbitrary code execution.

SentinelOne Snaps up Scalyr in $155M Deal
2021-02-09 17:10

SentinelOne, a late-stage startup jostling for a share of the expanding anti-malware market, expects the Scalyr deal to speed up its push into the lucrative XDR category. SentinelOne said its data services team will continue selling log management, observability, and event data cloud solutions in conjunction with the upcoming Scalyr integration.

Misplaced expectations securing water treatment systems
2021-02-09 17:06

The cyber attack that tried to poison the drinking water system in Oldsmar, Florida is similar to last year's attack on small water systems in Israel. Both attacks tried to tamper with water treatment facilities to produce drinking water containing dangerous amounts of chemicals.

Office 365 will help admins find impersonation attack targets
2021-02-09 17:05

Microsoft will make it easier for Defender for Office 365 customers to identify users and domains targeted in impersonation-based phishing attacks as recently revealed on the Microsoft 365 roadmap. Defender for Office 365 protects the emails of Office 365 enterprise accounts from various threats including but not limited to credential phishing and business email compromise.