Security News

Drupal Updates Patch Another Vulnerability Related to Archive Files
2021-01-21 16:13

Security updates released this week by the developers of the Drupal content management system patch a vulnerability identified in a third-party library. Core patches were made available for Drupal 9.1, 9.0, 8.9, and 7, to resolve a security flaw affecting PEAR Archive Tar, and which also impacts Drupal.

Microsoft warns of incoming Windows Zerologon patch enforcement
2021-01-15 09:51

Microsoft today warned admins that updates addressing the Windows Zerologon vulnerability will transition into the enforcement phase starting next month. "DC enforcement mode requires that all Windows and non-Windows devices use secure RPC with Netlogon secure channel unless customers have explicitly allowed the account to be vulnerable by adding an exception for the non-compliant device."

Microsoft Patch Tuesday, January 2021 Edition
2021-01-13 01:32

Microsoft today released updates to plug more than 80 security holes in its Windows operating systems and other software, including one that is actively being exploited and another which was disclosed prior to today. Microsoft recently stopped providing a great deal of detail in their vulnerability advisories, so it's not entirely clear how this is being exploited.

Critical Microsoft Defender Bug Actively Exploited; Patch Tuesday Offers 83 Fixes
2021-01-12 21:45

Microsoft addressed 10 critical bugs, one under active exploit and another publicly known, in its January Patch Tuesday roundup of fixes. The most serious bug is a flaw in Microsoft's Defender anti-malware software that allows remote attackers to infect targeted systems with executable code.

January 2021 Patch Tuesday: Microsoft plugs Defender zero-day RCE
2021-01-12 21:24

Microsoft has plugged 83 CVEs, including a Microsoft Defender zero-day. One of the latter - a zero-day RCE affecting Microsoft Defender antivirus - is being exploited in the wild, but Microsoft didn't reveal more about these attacks.

Microsoft Patch Tuesday: 83 Vulnerabilities, 10 Critical, 1 Actively Exploited
2021-01-12 18:59

Microsoft on Tuesday released the first batch of security patches for 2021 with fixes for 83 documented security vulnerabilities, including a "Critical" bug in the Defender security product that's being actively exploited. Security experts are urging security response personnel to pay special attention to CVE-2021-1647, which describes a remote code execution flaw in Microsoft Defender, the company's flagship anti-malware product.

Microsoft January 2021 Patch Tuesday fixes 83 flaws, 1 zero-day
2021-01-12 13:27

Today is Microsoft's January 2021 Patch Tuesday, and it is the first Microsoft security update release in 2021, so please be very nice to your Windows administrators today. With the January 2021 Patch Tuesday security updates release, Microsoft has released fixes for 83 vulnerabilities, with ten classified as Critical and 73 as Important.

Week in review: Fileless malware, key risk areas in 2021, Patch Tuesday forecast
2021-01-10 09:00

January 2021 Patch Tuesday forecast: New focus on security and software development2020 is in the rearview mirror and most of us can't get away fast enough. Review: Code42 Incydr - SaaS data risk detection and responseIncydr is Code42's new SaaS data risk detection and response solution, which enables security teams to mitigate file exposure and exfiltration risk without disrupting legitimate collaboration.

January 2021 Patch Tuesday forecast: New focus on security and software development
2021-01-08 08:21

Many predictions said we were due for another major cyberattack leading into 2021, but no one foresaw this type of attack and the impact it had, leading to a new focus on security and software development. The compromise of SolarWinds brings into question the security practices of all software developers, including topics such as patching of development machines, outsourcing of code development, control and understanding of code functionality through mergers and employee turnover, code reviews and other techniques to identify security issues and many others.

Zyxel hardcoded admin password found – patch now!
2021-01-06 17:27

Zyxel products are Linux-based, and Linux usernames and passwords are typically split between two files for security reasons. The early passwords of several Unix pioneers were cracked for fun in 2019 based on ancient password files embedded in the BSD-3 source code.