Security News

Patch Tuesday fixes 4 critical RCE bugs, and a bunch of Office holes
2023-06-14 18:32

In case you were wondering, there were 26 Remote Code Execution patches, including four dubbed "Critical", although three of those seem to related bugs that were found and fixed together in a single Windows component. RCE patches generally cause the most concern, because they deal with bugs that can, in theory at least, be exploited by attackers who don't yet have a foothold on your network, which means they represent possible ways of criminals breaking-and-entering in the first place.

These Microsoft Office security signatures are 'practically worthless'
2023-06-13 10:26

Office Open XML Signatures, an Ecma/ISO standard used in Microsoft Office applications and open source OnlyOffice, have several security flaws and can be easily spoofed. Microsoft refers to the format simply as Open XML. The boffins say they found discrepancies in the structure of office documents and the way signatures get verified.

UK criminal records office confirms cyber incident behind portal issues
2023-04-06 19:38

The UK's Criminal Records Office has finally confirmed, after weeks of delaying issuing a statement, that online portal issues experienced since January 17 resulted from what it described as a "Cyber security incident." ACRO is the country's national law enforcement organization responsible for managing criminal record information, providing criminal records on request, and sharing those records with foreign nations.

Criminal records office yanks web portal offline amid 'cyber security incident'
2023-04-06 08:30

ACRO, the UK's criminal records office, is combing over a "Cyber security incident" that forced it to pull its customer portal offline. In an email to users this week - seen by El Reg - ACRO confirmed it has "Recently been made aware of a cyber security incident affecting the website between 17th January 2023 and 21 March 2023.".

Capita cyberattack disrupted access to its Microsoft Office 365 apps
2023-04-03 13:20

British outsourcing services provider Capita announced today that a cyberattack on Friday prevented access to its internal Microsoft Office 365 applications. The cyber incident prompted the Capita on March 31 to announce an IT issue that impacted its internal systems.

Massive adversary-in-the-middle phishing campaign bypasses MFA and mimics Microsoft Office
2023-03-23 19:18

New research from Microsoft's Threat Intelligence team exposed the activities of a threat actor named DEV-1101, which started advertising for an open-source phishing kit to deploy an adversary-in-the-middle campaign. According to Microsoft, the threat actor described the kit as a phishing application with "Reverse-proxy capabilities, automated setup, detection evasion through an antibot database, management of phishing activity through Telegram bots, and a wide range of ready-made phishing pages mimicking services such as Microsoft Office or Outlook."

Australian woman arrested for email bombing a government office
2023-03-02 18:03

The Australian Federal Police arrested a woman in Werrington, Sydney, for allegedly email bombing the office of a Federal Member of Parliament. Email bombing is an online attack where attackers bombard an email address with thousands of emails to overwhelm a recipient's inbox or mail server.

Microsoft: Scan for outdated Office versions respects your privacy
2023-02-02 20:05

Microsoft says the KB5021751 update is respecting users' privacy while identifying the number of customers running Office versions that are outdated or approaching their end of support. It will only be installed on systems where one of the following Microsoft Office versions is also present: Office 2013, Office 2010, or Office 2007.

Microsoft pushes KB5021751 to check for outdated Office installs
2023-01-19 21:52

We and our store and/or access information on a device, such as cookies and process personal data, such as unique identifiers and standard information sent by a device for personalised ads and content, ad and content measurement, and audience insights, as well as to develop and improve products. With your permission we and our partners may use precise geolocation data and identification through device scanning.

10 data security enhancements to consider as your employees return to the office
2023-01-16 04:30

"The increase in data breach incidents across North America is troubling and must be prioritized as employees continue to return in-person to their corporate offices," said Kuljit Chahal, Practice Lead, Data Security at Adastra North America. Awareness of data security best practices among employees is essential-according to the 2022 Verizon Data Breach Investigations Report, 82% of data breaches are caused by human error and companies of all sizes are at risk.