Security News

Microsoft 365 outage triggered by Meraki firewall false positive
2022-08-10 14:34

An ongoing outage affects multiple Microsoft 365 services, blocking users from connecting to Exchange Online, Microsoft Teams, Outlook desktop clients, and OneDrive for Business. While Microsoft says that this incident has only affected customers in the EMEA region, users have been reporting server connection issues and sign-in failures worldwide.

Microsoft Patches ‘Dogwalk’ Zero-Day and 17 Critical Flaws
2022-08-10 12:48

Microsoft is urging users to patch a zero-day vulnerability dubbed Dogwalk that is actively being exploited in the wild. The actively exploited Dogwalk bug was first reported to Microsoft in January 2020 by researcher Imre Rad. However, it wasn't until a separate researchers began tracking the exploitation of a flaw dubbed Follina that the Dogwalk bug was rediscovered.

Patch Tuesday: Yet another Microsoft RCE bug under active exploit
2022-08-09 21:51

Of the 121 Microsoft bugs, 17 are considered critical. First, CVE-2022-34713, a remote code execution vulnerability in Microsoft Windows Support Diagnostic Tool that's under active attack.

Microsoft: Exchange ‘Extended Protection’ needed to fully patch new bugs
2022-08-09 21:14

Microsoft says that some of the Exchange Server flaws addressed as part of the August 2022 Patch Tuesday also require admins to manually enable Extended Protection on affected servers to fully block attacks. Remote attackers can exploit these Exchange bugs to escalate privileges in low-complexity attacks after tricking targets into visiting a malicious server using phishing emails or chat messages.

Microsoft fixes exploited zero-day in Windows Support Diagnostic Tool (CVE-2022-34713)
2022-08-09 20:30

The August 2022 Patch Tuesday has arrived, with fixes for an unexpectedly high number of vulnerabilities in various Microsoft products, including two zero-days: one actively exploited and one not yet. CVE-2022-34713 is a vulnerability in Microsoft Windows Support Diagnostic Tool that allows for remote code execution.

Microsoft patches Windows DogWalk zero-day exploited in attacks
2022-08-09 18:22

Microsoft has released security updates to address a high severity Windows zero-day vulnerability with publicly available exploit code and abused in attacks. DogWalk was publicly disclosed by security researcher Imre Rad more than two years ago, in January 2020, after Microsoft replied to his report saying it won't provide a fix because this isn't a security issue.

Microsoft August 2022 Patch Tuesday fixes exploited zero-day, 121 flaws
2022-08-09 17:34

Today is Microsoft's August 2022 Patch Tuesday, and with it comes fixes for the actively exploited 'DogWalk' zero-day vulnerability and a total of 121 flaws. [...]

Microsoft's fix for 'data damage' risk hits PC performance
2022-08-09 13:30

Microsoft has warned that Windows devices with the newest supported processors might be susceptible to data damage, noting the initial fix might have slowed operations down for some. It's a bit awkward since Microsoft insisted that its infamous hardware compatibility list for Windows 11 was about CPU security and experience, but here we are.

Microsoft tightens Edge security for less visited websites
2022-08-08 17:15

Microsoft wants to make it safer for Edge users to browse and visit unfamiliar websites by automatically applying stronger security settings. "With enhanced security mode, Microsoft Edge helps reduce the risk of an attack by automatically applying more conservative security settings on unfamiliar sites and adapts over time as you continue to browse."

Snapchat, Amex sites abused in Microsoft 365 phishing attacks
2022-08-07 14:12

Attackers abused open redirects on the websites of Snapchat and American Express in a series of phishing attacks to steal Microsoft 365 credentials. Open redirects are web app weaknesses that allow threat actors to use the domains of trusted organizations and websites as temporary landing pages to simplify phishing attacks.