Security News

New 0-Day Attack Targeting Windows Users With Microsoft Office Documents
2021-09-07 21:55

Microsoft on Tuesday warned of an actively exploited zero-day flaw impacting Internet Explorer that's being used to hijack vulnerable Windows systems by leveraging weaponized Office documents. "Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents," the company said.

Microsoft shares temp fix for ongoing Office 365 zero-day attacks
2021-09-07 19:36

Microsoft today shared mitigation for a remote code execution vulnerability in Windows that is being exploited in targeted attacks against Office 365 and Office 2019 on Windows 10. Microsoft is aware of targeted attacks that try to exploit the vulnerability by sending specially-crafted Microsoft Office documents to potential victims, the company says in an advisory today.

Office 365 to let admins block Active Content on Trusted Docs
2021-09-05 14:00

Microsoft plans to allow Office 365 admins ensure that end-users can't ignore organization-wide policies set up to block active content on Trusted Documents. Redmond says trusted docs are files with active content functions that don't require user interaction) that open without warnings after the content has been enabled.

Microsoft will add secure preview for Office 365 quarantined emails
2021-08-25 19:15

Microsoft is updating Defender for Office 365 to protect customers from embedded email threats while previewing quarantined emails. Microsoft Defender for Office 365 provides Office 365 enterprise email accounts with protection from multiple threats, including business email compromise and credential phishing, as well as automated attack remediation.

A full return to the office is more likely once the pandemic ends
2021-08-20 04:00

While many U.S. professionals are embracing hybrid work arrangements, a research from Robert Half shows a majority of companies anticipate a full return to the office once the pandemic ends. According to a survey of more than 2,800 senior managers in the U.S., 71% of respondents said they will require their teams to be on-site full time once COVID-19-related restrictions completely lift.

Pakistan's tax office services go dark after migration project goes awry
2021-08-17 03:00

Local reports suggest Microsoft Hyper-V crack was the cause, as rumours swirl of data leak Pakistan's Federal Board of Revenue – the nation's tax office – has experienced a lengthy outage after a...

Microsoft: Evasive Office 365 phishing campaign active since July 2020
2021-08-12 18:14

Microsoft says that a year-long and highly evasive spear-phishing campaign has targeted Office 365 customers in multiple waves of attacks starting with July 2020. The ongoing phishing campaign lures targets into handing over their Office 365 credentials using invoice-themed XLS.HTML attachments and various information about the potential victims, such as email addresses and company logos.

Week in review: Clever Office 365 phishing, 2021 CWE Top 25, Patch Tuesday forecast
2021-08-08 08:00

Patch bypass flaw in Pulse Secure VPNs can lead to total compromiseThe patch for a vulnerability in Pulse Connect Secure VPN devices that attackers have been exploiting in the wild can be bypassed, security researcher Rich Warren has found. Vulnerable TCP/IP stack is used by almost 200 device vendorsResearchers have discovered 14 new vulnerabilities affecting the proprietary NicheStack TCP/IP stack, used in OT devices such as the extremely popular Siemens S7 PLCs. A look at the 2021 CWE Top 25 most dangerous software weaknessesThe 2021 Common Weakness Enumeration Top 25 Most Dangerous Software Weaknesses is a demonstrative list of the most common issues experienced over the previous two calendar years.

Got a cheap Cisco router in your home office? If it's one of these, there's an exposed RCE hole you need to plug
2021-08-05 13:28

Cisco has published patches for critical vulns affecting the web management interface for some of its Small Business Dual WAN Gigabit routers - including a 9.8-rated nasty. The two vulnerabilities affect the RV340, RV345, RV340W, and RV345P products, which are aimed at SMEs and home office setups.

A clever phishing campaign is targeting Office 365 users
2021-08-04 12:12

Microsoft is warning about an ongoing, "Sneakier than usual" phishing campaign aimed at Office 365 users. An active phishing campaign is using a crafty combination of legitimate-looking original sender email addresses, spoofed display sender addresses that contain the target usernames and domains, and display names that mimic legitimate services to try and slip through email filters.