Security News

Microsoft July 2024 Patch Tuesday fixes 142 flaws, 4 zero-days
2024-07-09 17:52

Today is Microsoft's July 2024 Patch Tuesday, which includes security updates for 142 flaws, including two actively exploited and two publicly disclosed zero-days. [...]

Microsoft China staff can't log on with an Android, so Redmond buys them iThings
2024-07-09 06:32

Theregister.com needs to review the security of your connection before proceeding. Theregister.com to respond.....

Microsoft’s cybersecurity dilemma: An open letter to Satya Nadella
2024-07-09 04:30

Microsoft is suffering cybersecurity failures due to systemic problems with strategic leadership. The world is witnessing an alarming trend of cybersecurity issues with Microsoft products and services.

Microsoft: Windows 11 22H2 reaches end of service in October
2024-07-08 18:57

Microsoft reminded customers today that multiple editions of Windows 11, version 22H2, will reach the end of servicing in three months, on October 8, 2024. Windows 11 22H2 started rolling out in September to Release Preview Insiders for enterprise testing and was released as an enablement package on October 31.

Microsoft forgets about SwiftKey's support site
2024-07-08 14:12

Another Microsoft certificate has expired, leaving SwiftKey users that are seeking support faced with an alarming certificate error. One such user contacted The Register after heading into the app's settings to find the support page.

Microsoft Uncovers Critical Flaws in Rockwell Automation PanelView Plus
2024-07-04 09:10

Microsoft has identified two critical vulnerabilities in Rockwell Automation's PanelView Plus, enabling remote, unauthenticated attackers to execute arbitrary code and cause a denial-of-service (DoS). Researcher Yuval Gordon explained that the remote code execution flaw exploits custom classes to upload malicious DLLs, while the DoS vulnerability sends unmanageable crafted buffers, crashing the system.The vulnerabilities, CVE-2023-2071 and CVE-2023-29464, with CVSS scores of 9.8 and 8.2, respectively, involve improper input validation. CVE-2023-2071 affects FactoryTalk View Machine Edition versions 13.0, 12.0, and earlier, allowing remote code execution. CVE-2023-29464 impacts FactoryTalk Linx versions 6.30, 6.20, and earlier, enabling data reading from memory and DoS through oversized packets.

Microsoft MSHTML Flaw Exploited to Deliver MerkSpy Spyware Tool
2024-07-03 09:53

Unknown threat actors have been observed exploiting a now-patched security flaw in Microsoft MSHTML to deliver a surveillance tool called MerkSpy as part of a campaign primarily targeting users in...

Microsoft tells yet more customers their emails have been stolen
2024-07-01 03:35

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Microsoft resumes rollout of Windows 11 KB5039302 update for most users
2024-06-29 18:01

Microsoft has resumed the rollout of the June Windows 11 KB5039302 update, now blocking the update only for those using virtualization software. On Wednesday, Microsoft pulled the KB5039302 update after Windows 11 users found that their devices went into a reboot loop after it was installed.

Microsoft hits snooze again on security certificate renewal
2024-06-28 13:26

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.