Security News

Windows 10 KB5040427 update released with Copilot changes, 12 other fixes
2024-07-09 18:11

Microsoft has released the KB5040427 cumulative update for Windows 10 21H2 and Windows 10 22H2 with 13 changes, including Microsoft Copilot now behaving like an app, providing more flexibility on...

Microsoft July 2024 Patch Tuesday fixes 142 flaws, 4 zero-days
2024-07-09 17:52

Today is Microsoft's July 2024 Patch Tuesday, which includes security updates for 142 flaws, including two actively exploited and two publicly disclosed zero-days. [...]

Windows 11 KB5040442 update released with 31 fixes, changes
2024-07-09 17:37

Microsoft is rolling out the KB5040442 cumulative update for Windows 11 23H2, which includes up to thirty-one improvements and changes. The changes include a new feature that adds back the "Show...

Windows 11 KB5040435 update released with 31 fixes, changes
2024-07-09 17:37

Microsoft is rolling out the KB5040442 cumulative update for Windows 11 23H3, which includes up to thirty-one improvements and changes. You can go to Start > Settings > Windows Update and click 'Check for Updates' to download the update.

Hackers target WordPress calendar plugin used by 150,000 sites
2024-07-09 17:21

Hackers are trying to exploit a vulnerability in the Modern Events Calendar WordPress plugin that is present on more than 150,000 websites to upload arbitrary files to a vulnerable site and...

City of Philadelphia says over 35,000 hit in May 2023 breach
2024-07-09 16:55

The City of Philadelphia revealed that a May 2024 disclosed in October impacted more than 35,000 individuals' personal and protected health information. Demographic information, such as name, address, date of birth, social security number, and other contact information; medical information, such as diagnosis and other treatment-related information; and limited financial information, such as claims information.

Reverse-Engineering Ticketmaster’s Barcode System
2024-07-09 16:27

About Bruce Schneier I am a public-interest technologist, working at the intersection of security, technology, and people. I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

How to Run a Cybersecurity Risk Assessment in 5 Steps
2024-07-09 16:00

Though cybersecurity is on every executive's checklist today, most struggle with growing compliance burdens, keeping the costs moderate and bringing team alignment. Read this guide, written by Avya Chaudhary for TechRepublic Premium, to learn how to perform a cybersecurity assessment within a five-point framework.

Social Engineering Awareness Policy
2024-07-09 16:00

The purpose of this customizable Social Engineering Awareness Policy, written by Maria Carrisa Sanchez for TechRepublic Premium, is to provide guidelines for preventing, recognizing and addressing social engineering attacks. Regular update of passwords: The company believes passwords serve as the fundamental line of security against unwanted access.

Chinese APT40 hackers hijack SOHO routers to launch attacks
2024-07-09 15:11

A joint advisory from international cybersecurity agencies and law enforcement warns of the tactics used by the Chinese state-sponsored APT 40 hacking group and their hijacking of SOHO routers to launch cyberespionage attacks. Previously, APT40 was linked to a wave of attacks targeting over 250,000 Microsoft Exchange servers using the ProxyLogon vulnerabilities and campaigns involving exploiting flaws in widely used software, such as WinRAR. APT40 activity overview.