Security News

Patch Tuesday: Microsoft Warns of Under-Attack Windows Kernel Flaw
2021-02-09 20:56

The Microsoft patch drop adds to the workloads for weary defenders struggling to keep pace with the volume and pace of security updates from major vendors. Earlier Tuesday, Adobe shipped fixes for multiple dangerous security holes, including a bug in the Adobe Reader that is being exploited in "Limited targeted attacks" against Windows OS users.

February 2021 Patch Tuesday: Microsoft and Adobe fix exploited zero-days
2021-02-09 20:09

Microsoft has plugged 56 security holes, including one actively exploited privilege escalation flaw. Adobe has released security updates for Acrobat and Reader, Dreamweaver, Photoshop, Illustrator, Animate, and the Magento CMS. Out of all of those, the Acrobat and Reader updates should be tested and deployed as soon as possible, as they fix a bucketload of critical and important issues in widely used solutions, including one bug that is being exploited in "Limited" attacks on Reader for Windows.

Microsoft urges customers to patch critical Windows TCP/IP bugs
2021-02-09 18:52

Microsoft has urged customers today to install security updates for three Windows TCP/IP vulnerabilities rated as critical and high severity as soon as possible. The three TCP/IP security vulnerabilities impact computers running Windows client and server versions starting with Windows 7 and higher.

Microsoft February 2021 Patch Tuesday fixes 56 flaws, 1 zero-day
2021-02-09 18:25

Today is Microsoft's February 2021 Patch Tuesday, so please be buy your Windows administrators some snacks to keep their energy up throughout the day. With today's update, Microsoft has fixed for 56 vulnerabilities, with eleven classified as Critical, two as Moderate, and 43 as Important.

Researcher hacks Microsoft, Apple, more in novel supply chain attack
2021-02-09 18:04

A researcher managed to breach over 35 major companies' internal systems, including Microsoft, Apple, PayPal, Shopify, Netflix, Yelp, Tesla, and Uber, in a novel software supply chain attack. Unlike traditional typosquatting attacks that rely on social engineering tactics or the victim misspelling a package name, this particular supply chain attack is more sophisticated as it needed no action by the victim, who automatically received the malicious packages.

Microsoft: Recent Windows 10 gaming issues caused by Discord bug
2021-02-09 13:37

Microsoft has acknowledged a known issue that was causing Direct3D 12 games to fail to launch or crash with an error on some Windows 10 devices. "Microsoft and Discord have found incompatibility issues with some games using Direct3D 12 when the in-game overlay feature of Discord is enabled," Microsoft said.

Microsoft to alert enterprise security teams when nation-state attackers target their employees
2021-02-09 11:45

Microsoft will introduce this month a new security alert that will notify enterprise security teams when an employee is being targeted by suspected nation-state attackers. " attacks represent some of the most advanced and persistent threat activity Microsoft tracks.

Microsoft: Keep your guard up even after Emotet’s disruption
2021-02-08 18:53

Microsoft warns customers not to let their guard down even after hundreds of Emotet botnet servers were taken down in late January 2021. Telemetry data collected by Microsoft since Emotet's infrastructure was disrupted shows that the botnet has seen a drastic drop in activity, but Redmond still warns customers not to take down their defenses.

Microsoft to alert Office 365 users of nation-state hacking activity
2021-02-08 13:52

Microsoft will soon notify Office 365 of suspected nation-state hacking activity detected within their tenants according to a new listing on the company's Microsoft 365 roadmap. Microsoft Defender for Office 365 provides Office 365 enterprise accounts with email protection against several types of threats including credential phishing and business email compromise, as well as automated attack remediation.

Google Chrome, Microsoft IE Zero-Days in Crosshairs
2021-02-05 20:00

Google late Thursday night shipped an emergency patch to close a Chrome browser vulnerability that was being used in mysterious zero-day attacks. The Google Chrome patch, which is being pushed via the browser's automatic self-patching, covers a critical vulnerability in V8, Google's JavaScript and WebAssembly engine.