Security News

Microsoft and Google to invest billions to bolster US cybersecurity
2021-08-26 15:27

Executives and leaders from big tech, education, the finance sector, and infrastructure have committed to bolstering US interests' security during yesterday's White House cybersecurity summit. The Biden administration has added natural gas pipelines to the Industrial Control Systems Cybersecurity Initiative, aiming to strengthen critical infrastructure cybersecurity.

Microsoft accidentally lowers OneDrive for Business storage limits
2021-08-26 13:05

Microsoft is investigating an ongoing issue impacting OneDrive for Business customers and causing their storage space to shrink down to the default setting or switching them to read-only mode, forcing some to delete files to free up space to work on their projects. OneDrive for Business is a cloud storage and file sharing service for enterprise customers that allows users to access, share, and collaborate on personal and shared work files across Microsoft 365.

Microsoft Breaks Silence on Barrage of ProxyShell Attacks
2021-08-26 12:39

Microsoft has broken its silence on the recent barrage of attacks on several ProxyShell vulnerabilities in that were highlighted by a researcher at Black Hat earlier this month. "Please update now!"Customers that have installed the May 2021 security updates or the July 2021 security updates on their Exchange servers are protected from these vulnerabilities, as are Exchange Online customers so long as they ensure that all hybrid Exchange servers are updated, the company wrote.

Microsoft: ProxyShell bugs “might be exploited,” patch servers now!
2021-08-25 20:19

Microsoft has finally published guidance today for the actively exploited ProxyShell vulnerabilities impacting multiple on-premises Microsoft Exchange versions. Although Microsoft fully patched the ProxyShell bugs by May 2021, they didn't assign CVE IDs for the vulnerabilities until July, preventing some orgs with unpatched servers from discovering that they had vulnerable systems on their networks.

Microsoft will add secure preview for Office 365 quarantined emails
2021-08-25 19:15

Microsoft is updating Defender for Office 365 to protect customers from embedded email threats while previewing quarantined emails. Microsoft Defender for Office 365 provides Office 365 enterprise email accounts with protection from multiple threats, including business email compromise and credential phishing, as well as automated attack remediation.

Why you need to make Microsoft 365 a 24/7 security priority
2021-08-25 07:00

Despite the wide range of applications and features in the Microsoft 365 platform, the primary communication and collaboration tool for most users - and the core of Microsoft 365's functionality - continues to be email. The Microsoft 365 cloud environment itself benefits from an extensive monitoring and security infrastructure.

Microsoft Power Apps misconfiguration exposes data from 38 million records
2021-08-24 13:52

A lack of proper security configuration with Microsoft's Power Apps has led to the exposure of data from some 38 million records, according to security firm UpGuard. Among the organizations whose data was exposed were government agencies in Indiana, Maryland and New York City, as well as private companies such as American Airlines, J.B. Hunt and even Microsoft itself.

38 Million Records Exposed from Microsoft Power Apps of Dozens of Organisations
2021-08-24 02:58

More than 38 million records from 47 different entities that rely on Microsoft's Power Apps portals platform were inadvertently left exposed online, bringing into sharp focus a "New vector of data exposure." Power Apps is a Microsoft-powered development platform for building low-code custom business apps that work across mobile and the web using prebuilt templates, in addition to offering APIs to enable access to data by other applications, including options to retrieve and store information.

38 Million Records Exposed from Microsoft Power Apps of Dozens of Organisations
2021-08-24 02:58

More than 38 million records from 47 different entities that rely on Microsoft's Power Apps portals platform were inadvertently left exposed online, bringing into sharp focus a "New vector of data exposure."Power Apps is a Microsoft-powered development platform for building low-code custom business apps that work across mobile and the web using prebuilt templates, in addition to offering APIs to enable access to data by other applications, including options to retrieve and store information.

Microsoft Spills 38 Million Sensitive Data Records Via Careless Power App Configs
2021-08-23 23:18

For months, Microsoft's Power Apps portals exposed personal data tied to 38 million records ranging from COVID-19 vaccination status, social security numbers and email addresses. Microsoft describes its Power Apps as a "Suite of apps, services, and connectors, as well as a data platform, that provides a rapid development environment to build custom apps for your business needs." The tool is used by developers to build applications that share data locally or with the cloud.