Security News > 2022 > July

Microsoft fixes dozens of Azure Site Recovery privilege escalation bugs
2022-07-12 22:19

Microsoft has fixed 32 vulnerabilities in the Azure Site Recovery suite that could have allowed attackers to gain elevated privileges or perform remote code execution.The Azure Site Recovery service is a disaster recovery service that will automatically fail-over workloads to secondary locations when a problem is detected.

Microsoft's July Patch Tuesday fixes actively exploited bug
2022-07-12 22:11

Despite worries that Patch Tuesday may not be as exciting now that Microsoft's Windows Autopatch is live - with a slew of caveats - the second Tuesday of this month arrived with 84 security fixes, including 4 critical bugs and one that's under active exploit. Microsoft deemed it an "Important" security issue, with low complexity and low privileges required to exploit.

CISA orders agencies to patch new Windows zero-day used in attacks
2022-07-12 21:10

CISA has added an actively exploited local privilege escalation vulnerability in the Windows Client/Server Runtime Subsystem to its list of bugs abused in the wild.This high severity security flaw impacts both server and client Windows platforms, including the latest Windows 11 and Windows Server 2022 releases.

TikTok Postpones Privacy Policy Update in Europe After Italy Warns of GDPR Breach
2022-07-12 20:44

The reversal, reported by TechCrunch, comes a day after the Italian data protection authority - the Garante per la Protezione dei Dati Personali - warned the company against the change, citing violations of data protection laws. "The personal data stored in users' devices may not be used to profile those users and send personalized ads without their explicit consent," the Garante said.

Hackers impersonate cybersecurity firms in callback phishing attacks
2022-07-12 19:54

Hackers are impersonating well-known cybersecurity companies, such as CrowdStrike, in callback phishing emails to gain initial access to corporate networks. Over the past year, threat actors have increasingly used "Callback" phishing campaigns that impersonate well-known companies requesting you call a number to resolve a problem, cancel a subscription renewal, or discuss another issue.

Microsoft fixes exploited zero-day in Windows CSRSS (CVE-2022-22047)
2022-07-12 19:44

The July 2022 Patch Tuesday is upon us and has brought fixes for 84 CVEs in various Microsoft products, including an actively exploited zero-day: CVE-2022-22047, an elevation of privilege bug in Windows' Client/Server Runtime Subsystem. "An attacker who successfully exploited this vulnerability could gain SYSTEM privileges," Microsoft noted, but the attacker must first gain access to the system, usually by exploiting a separate code execution bug.

Critical infrastructure IIoT/OT security projects suffer high rates of failure
2022-07-12 19:13

Critical infrastructure IIoT/OT security projects suffer high rates of failure. Barracuda Networks surveyed 800 senior IT managers, senior IT security managers and project managers as part of its "The State of Industrial Security in 2022" report, and found that a whopping 93% have suffered from failed security projects.

Windows 11 KB5015814 update adds Search Highlights feature, 27 fixes
2022-07-12 18:54

Microsoft has released the Windows 11 KB5015814 cumulative update with security updates, improvements, and the new Search Highlights feature. KB5015814 is a mandatory cumulative update containing the July 2022 Patch Tuesday security updates for vulnerabilities discovered in previous months.

Windows 11 KB5015814 update adds Search Highlights feature, 27 changes
2022-07-12 18:54

Microsoft has released the Windows 11 KB5015814 cumulative update with security updates, improvements, and the new Search Highlights feature. KB5015814 is a mandatory cumulative update containing the July 2022 Patch Tuesday security updates for vulnerabilities discovered in previous months.

Microsoft warns Windows Server 20H2 reaches EOS next month
2022-07-12 18:53

Microsoft reminded customers today that Windows Server, version 20H2 will be reaching its End of Service next month, on August 9. This comes after a May 2022 reminder that Windows Server 20H2 will reach the mainstream support end date for Standard Core and Datacenter Core users.