Security News

Week in review: Sumo Logic breach, 7 free cyber threat maps, Patch Tuesday forecast
2023-11-12 09:00

Aqua Trivy open-source security scanner now finds Kubernetes security risksThe Aqua Trivy open-source scanner now supports vulnerability scanning for Kubernetes components and Kubernetes Bill of Materials generation. Sumo Logic discloses potential breach via compromised AWS credentialCloud-native big data and security analytics firm Sumo Logic is investigating a potential security incident within their platform, the company revealed on Tuesday.

November 2023 Patch Tuesday forecast: Year 21 begins
2023-11-10 06:00

The October forecast for large numbers of CVEs addressed in Windows 10 and 11 and the recent record on the number fixed in Windows Server 2012 was spot on! Microsoft addressed 75 CVEs in Windows 11, 80 in Windows 10, and 61 in Server 2012 R2. While Server 2012 and Server 2012 R2 may be in good shape for the short term, please don't count on it for long, and don't forget they are moving into Extended Security Updates this month. Software updates across the board had been haphazard and happenstance until that second Tuesday in October 2003.

From chaos to cadence: Celebrating two decades of Microsoft's Patch Tuesday
2023-10-11 13:01

Childs described the early years of Patch Tuesday at Microsoft being kind of a party, complete with catered breakfast and music. "Certainly a lot of large financial institutions and I imagine a lot of other organizations were part of really bringing pressure to bear to Microsoft to release it as an instance, a single time so we can plan for it, take a more measured approach and reduce a lot of the chaos that was prior to Patch Tuesday being a thing," he tells The Register.

Microsoft October 2023 Patch Tuesday fixes 3 zero-days, 104 flaws
2023-10-10 17:49

Today is Microsoft's October 2023 Patch Tuesday, with security updates for 104 flaws, including three actively exploited zero-day vulnerabilities. While forty-five remote code execution bugs were fixed, Microsoft only rated twelve vulnerabilities as 'Critical,' all of which are RCE flaws.

Week in review: Patch Tuesday forecast, 9 free ransomware guides, Cybertech Europe 2023
2023-10-08 08:30

Cybertech Europe 2023 video walkthroughIn this Help Net Security video, we take you inside Cybertech Europe 2023 at La Nuvola Convention Center in Rome. Tackling cyber risks head-on using security questionnairesIn this Help Net Security interview, Gaspard de Lacroix-Vaubois, CEO at Skypher, talks about the implementation of security questionnaires and how they facilitate assessments and accountability across all participants in the technology supply chain, fostering trust and safeguarding sensitive data.

October 2023 Patch Tuesday forecast: Operating system updates and zero-days aplenty
2023-10-06 04:42

The November Patch Tuesday cumulative update will include the Moment 4 features and updates. This patch Tuesday will include the last updates for Windows 11 21H2 and Microsoft Server 2012/2012 R2. The later go into Extended Security Support starting with a November release, and Microsoft also announced the keys used to enable these updates will be managed as part of Azure Arc.

Microsoft September 2023 Patch Tuesday fixes 2 zero-days, 59 flaws
2023-09-12 18:11

Today is Microsoft's September 2023 Patch Tuesday, with security updates for 59 flaws, including two actively exploited zero-day vulnerabilities. Microsoft also shared fixes for two flaws in non-Microsoft products, Electron and Autodesk, and four Microsoft Edge vulnerabilities on September 7th. To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5030219 cumulative update and Windows 10 KB5030211 updates released.

Week in review: 6 free resources for getting started in cybersecurity, Patch Tuesday forecast
2023-09-10 08:00

LibreOffice: Stability, security, and continued developmentLibreOffice, the most widely used open-source office productivity suite, has plenty to recommend it: it's feature-rich, user-friendly, well-documented, reliable, has an active community of developers working on improving it, and it's free. North Korean hackers target security researchers with zero-day exploitNorth Korean threat actors are once again attempting to compromise security researchers' machines by employing a zero-day exploit.

September 2023 Patch Tuesday forecast: Important Federal government news
2023-09-08 05:08

The last security updates will be issued next month on the October Patch Tuesday. September 2023 Patch Tuesday forecast Microsoft will probably up their game on CVEs addressed this month, but don't expect the breadth of updates we saw last month.

Microsoft Patch Tuesday: 74 CVEs plus 2 “Exploit Detected” advisories
2023-08-09 20:34

The August 2023 Microsoft security updates are out, with 74 CVE-numbered bugs fixed. Intriguingly, if not confusingly, Microsoft's offical bug listing page is topped by two special items dubbed Exploitation Detected.