Security News

Microsoft September 2021 Patch Tuesday fixes 2 zero-days, 60 flaws
2021-09-14 17:56

Today is Microsoft's September 2021 Patch Tuesday, and with it comes fixes for two zero-day vulnerabilities and a total of 60 flaws. Microsoft has fixed 60 vulnerabilities with today's update, with three classified as Critical, one as Moderate, and 56 as Important.

Apple releases emergency patch to protect all devices against Pegasus spyware
2021-09-14 12:56

Designed to combat zero-day flaws exploited in Apple's operating systems, the patch applies to the iPhone, iPad, Apple Watch and Mac. Apple has pushed out an update for most of its major products to protect them from a strain of spyware that has already targeted a number of people.

Week in review: How CISSP can change a career, rural hospitals cybersecurity, Patch Tuesday forecast
2021-09-12 08:00

Healthcare cybersecurity under attack: How the pandemic affected rural hospitalsIn this interview with Help Net Security, Baha Zeidan, CEO at Azalea Health, talks about how rural hospitals have been affected by the pandemic and what steps they should take to boost their cybersecurity posture. 3 ways to protect yourself from cyberattacks in the midst of an IT security skill shortageEnterprises face a catch-22 situation: Security is more vital than ever, but cybersecurity positions are nearly impossible to fill.

September 2021 Patch Tuesday forecast: It’s new operating system season
2021-09-10 05:48

Apple also has the beta available for the next version of macOS. But let's start by focusing on a new Office vulnerability before next week's Patch Tuesday. September 2021 Patch Tuesday forecast I expect a limited number of CVEs addressed this month across all the operating systems as Microsoft comes back from final summer vacation.

Patch now? Why enterprise exploits are still partying like it's 1999
2021-09-08 09:13

Eoin Keary, CEO and founder of Edgescan, told The Register that the oldest common vulnerability discovered in its latest quarterly vulnerability scans report dated back to 1999. Before we look at the why, let's explore some of the what: the old vulnerabilities that are still being used in very real world enterprise attacks to this day.

Miscreants fling booby-trapped Office files at victims, no patch yet, says Microsoft
2021-09-07 22:20

In an advisory issued on Tuesday, Microsoft said some of its users were targeted by poisoned Office documents that exploit an unpatched flaw to hijack their Windows machines. Miscreants are seemingly placing a malicious ActiveX control in an Office document and convincing victims to open or view it, potentially achieving remote code execution.

Critical Auth Bypass Bug Affect NETGEAR Smart Switches — Patch and PoC Released
2021-09-06 03:33

Networking, storage and security solutions provider Netgear on Friday issued patches to address three security vulnerabilities affecting its smart switches that could be abused by an adversary to gain full control of a vulnerable device. The flaws, which were discovered and reported to Netgear by Google security engineer Gynvael Coldwind, impact the following models -.

Cisco Issues Patch for Critical Enterprise NFVIS Flaw — PoC Exploit Available
2021-09-04 00:07

Cisco has patched a critical security vulnerability impacting its Enterprise Network Function Virtualization Infrastructure Software that could be exploited by an attacker to take control of an affected system. The network equipment maker said it's aware of a publicly available proof-of-concept exploit code targeting the vulnerability, but added it's not detected any successful weaponization attempts in the wild.

US govt warns orgs to patch massively exploited Confluence bug
2021-09-03 15:23

US Cyber Command has issued a rare alert today urging US organizations to patch a massively exploited Atlassian Confluence critical vulnerability immediately.The USCYBERCOM unit also stressed the importance of patching vulnerable Confluence servers as soon as possible: "Please patch immediately if you haven't already- this cannot wait until after the weekend."

F5 Releases Critical Security Patch for BIG-IP and BIG-IQ Devices
2021-08-27 00:48

Enterprise security and network appliance vendor F5 has released patches for more than two dozen security vulnerabilities affecting multiple versions of BIG-IP and BIG-IQ devices that could potentially allow an attacker to perform a wide range of malicious actions, including accessing arbitrary files, escalating privileges, and executing JavaScript code. Chief among them is CVE-2021-23031, a vulnerability affecting BIG-IP Advanced Web Application Firewall and BIG-IP Application Security Manager that allows an authenticated user to perform a privilege escalation.