Security News

Patch procrastination leaves 50,000 Fortinet firewalls vulnerable to zero-day
2025-01-21 18:45

Seven days after disclosure and little action taken, data shows Fortinet customers need to get with the program and apply the latest updates as nearly 50,000 management interfaces are still...

7-Zip fixes bug that bypasses Windows MoTW security warnings, patch now
2025-01-21 16:05

​A high-severity vulnerability in the 7-Zip file archiver allows attackers to bypass the Mark of the Web (MotW) Windows security feature and execute code on users' computers when extracting...

New UEFI Secure Boot flaw exposes systems to bootkits, patch now
2025-01-16 15:05

A new UEFI Secure Boot bypass vulnerability tracked as CVE-2024-7344 that affects a Microsoft-signed application could be exploited to deploy bootkits even if Secure Boot protection is active. [...]

Windows Patch Tuesday hits snag with Citrix software, workarounds published
2025-01-15 17:15

Microsoft starts 2025 as it hopefully doesn't mean to go on Devices that have Citrix's Session Recording software installed are having problems completing this month's Microsoft Patch Tuesday...

Patch Tuesday: January 2025 Security Update Patches Exploited Elevation of Privilege Attacks
2025-01-15 16:03

Microsoft’s monthly patches cover Hyper-V NT Kernel Integration VSPs, Git in Visual Studio, and more.

Rsync vulnerabilities allow remote code execution on servers, patch quickly!
2025-01-15 14:24

Six vulnerabilities have been fixed in the newest versions of Rsync (v3.4.0), two of which could be exploited by a malicious client to achieve arbitrary code execution on a machine with a running...

Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws
2025-01-14 19:01

Today is Microsoft's January 2025 Patch Tuesday, which includes security updates for 159 flaws, including eight zero-day vulnerabilities, with three actively exploited in attacks. [...]

CISA orders agencies to patch BeyondTrust bug exploited in attacks
2025-01-13 20:58

​CISA tagged a vulnerability in BeyondTrust's Privileged Remote Access (PRA) and Remote Support (RS) as actively exploited in attacks, ordering agencies to secure their systems within three weeks. [...]

Week in review: Exploited Ivanti Connect Secure zero-day, Patch Tuesday forecast
2025-01-12 09:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Ivanti Connect Secure zero-day exploited by attackers (CVE-2025-0282) Ivanti has fixed two...

January 2025 Patch Tuesday forecast: Changes coming in cybersecurity guidance
2025-01-10 07:38

Welcome to 2025 and a new year of patch excitement! In my December article, I talked about Microsoft’s Secure Future Initiative (SFI) and how it manifested in many of the Microsoft products...