Security News

Critical vulnerabilities in Cisco Security Manager fixed, researcher discloses PoCs
2020-11-17 11:49

Cisco has patched two vulnerabilities in its Cisco Security Manager solution, both of which could allow unauthenticated, remote attackers to gain access to sensitive information on an affected system. Those are part of a batch of twelve vulnerabilities flagged in July 2020 by Florian Hauser, a security researcher and red teamer at Code White.

Researcher Discloses Critical RCE Flaws In Cisco Security Manager
2020-11-17 08:09

Cisco has published multiple security advisories concerning critical flaws in Cisco Security Manager a week after the networking equipment maker quietly released patches with version 4.22 of the platform. The flaws were responsibly reported to Cisco's Product Security Incident Response Team three months ago, on July 13.

STEM and cybersecurity training are critical for the future
2020-11-13 17:19

Training people to fill cybersecurity jobs is important, but teaching everyone safe practices is also essential. Karen Roby: While it may seem I think obvious to why a real focus on STEM should be involved when it comes to cybersecurity, it also seems some government agencies are resistant, hesitant, to adopt new cybersecurity methods.

Bugs in Critical Infrastructure Gear Allow Sophisticated Cyberattacks
2020-11-12 16:52

Two security vulnerabilities in Schneider Electric's programmable logic controllers could allow attackers to compromise a PLC and move on to more sophisticated critical infrastructure attacks. There are two types of application protection available: Read protection protects the controller's application from being read by any unauthorized personnel at the engineering workstation; and the write protection protects the controller's application from unauthorized changes.

SAP Patches Several Critical Vulnerabilities With November 2020 Security Updates
2020-11-12 04:35

SAP's security updates for November 2020 patch several critical vulnerabilities affecting the company's Solution Manager, Data Services, ABAP, S4/HANA, and NetWeaver products. One of the hot news patches resolves a total of four vulnerabilities related to missing authentication checks in SolMan, which provides a central management interface for SAP and non-SAP systems.

Datadog’s new capabilities for monitoring DNS provide visibility into the health of business-critical apps
2020-11-12 01:00

Datadog announced new capabilities for monitoring DNS. These new features allow engineers to troubleshoot DNS issues that affect the performance and availability of web applications and backend microservices. Datadog's DNS monitoring capabilities now allow customers to monitor key performance metrics about both internal and external DNS resolution to maintain efficient service networking and availability.

Samsung fixes critical Android flaws with November 2020 updates
2020-11-11 05:56

This week Samsung has started rolling out Android's November security updates to mobile devices to patch critical security vulnerabilities in the operating system and enhance overall features on the devices. This comes after Android had published their November 2020 security updates bulletin, which includes patches for critical vulnerabilities impacting the latest devices.

Microsoft Releases Windows Security Updates For Critical Flaws
2020-11-11 02:29

Microsoft formally released fixes for 112 newly discovered security vulnerabilities as part of its November 2020 Patch Tuesday, including an actively exploited zero-day flaw disclosed by Google's security team last week. Outside of the zero-day, the update fixes a number of remote code execution vulnerabilities impacting Exchange Server, Network File System, and Microsoft Teams, as well as a security bypass flaw in Windows Hyper-V virtualization software.

Microsoft Patch Tuesday Update Fixes 17 Critical Bugs
2020-11-10 21:12

Microsoft's November Patch Tuesday roundup of security fixes tackled an unusually large crop of remote code execution bugs. Twelve of Microsoft's 17 critical patches were tied to RCE bugs.

Colossal Intel Update Anchored by Critical Privilege-Escalation Bugs
2020-11-10 20:59

A massive Intel security update this month addresses flaws across a myriad of products - most notably, critical bugs that can be exploited by unauthenticated cybercriminals in order to gain escalated privileges. These critical flaws exist in products related to Wireless Bluetooth - including various Intel Wi-Fi modules and wireless network adapters - as well as in its remote out-of-band management tool, Active Management Technology.