Security News

Microsoft fixes Windows Server VMs broken by October updates
2023-11-15 20:51

Microsoft fixed a known issue causing blue screens and boot failures in Windows Server 2022 virtual machines deployed on VMware ESXi hosts. The company confirmed the issue days later, saying it only affects guest VMs on VMware ESXi hosts with an AMD Epyc physical processor, the "Expose IOMMU to guest OS" VMware option toggled on, and Virtualization Based Security and System Guard Secure Launch enabled in Windows Server 2022.

New Reptar CPU flaw impacts Intel desktop and server systems
2023-11-14 23:15

Intel has fixed a high-severity CPU vulnerability in its modern desktop, server, mobile, and embedded CPUs, including the latest Alder Lake, Raptor Lake, and Sapphire Rapids microarchitectures. "Under certain microarchitectural conditions, Intel has identified cases where execution of an instruction encoded with a redundant REX prefix may result in unpredictable system behavior resulting in a system crash/hang, or, in some limited scenarios, may allow escalation of privilege from CPL3 to CPL0," Intel said.

LockBit ransomware exploits Citrix Bleed in attacks, 10K servers exposed
2023-11-14 20:03

The Lockbit ransomware attacks use publicly available exploits for the Citrix Bleed vulnerability to breach the systems of large organizations, steal data, and encrypt files. Although Citrix made fixes available for CVE-2023-4966 more than a month ago, thousands of internet-exposed endpoints are still running vulnerable appliances, many in the U.S. High-profile Lockbit attacks.

Intel emits patch to squash chip bug that lets any guest VM crash host servers
2023-11-14 18:00

Intel on Tuesday issued an out-of-band security update to address a privilege escalation vulnerability in recent server and personal computer chips. The flaw, designated INTEL-SA-00950 and given a CVSS 3.0 score of 8.8 out of 10, affects Intel Sapphire Rapids, Alder Lake, and Raptor Lake chip families.

Passive SSH server private key compromise is real ... for some vulnerable gear
2023-11-14 02:38

OpenSSL, LibreSSL, OpenSSH users, don't worry – you can sit this one out An academic study has shown how it's possible for someone to snoop on certain devices' SSH connections and, with a bit of...

Microsoft extends Windows Server 2012 ESUs to October 2026
2023-11-10 16:50

Microsoft provides three more years of Windows Server 2012 Extended Security Updates (ESUs) until October 2026, allowing administrators more time to upgrade or migrate to Azure. [...]

Alert: 'Effluence' Backdoor Persists Despite Patching Atlassian Confluence Servers
2023-11-10 08:58

Cybersecurity researchers have discovered a stealthy backdoor named Effluence that's deployed following the successful exploitation of a recently disclosed security flaw in Atlassian Confluence Data Center and Server. "The malware acts as a persistent backdoor and is not remediated by applying patches to Confluence," Aon's Stroz Friedberg Incident Response Services said in an analysis published earlier this week.

Microsoft shares temp fix for broken Windows Server 2022 VMs
2023-11-09 18:07

Microsoft publicly acknowledged a known issue causing Windows Server 2022 virtual machine blue screens and boot failures on VMware ESXi hosts. "Affected VMs will receive an error with a blue screen and Stop code : PNP DETECTED FATAL ERROR," Microsoft said in an update to the Windows release health dashboard.

3,000 Apache ActiveMQ servers vulnerable to RCE attacks exposed online
2023-11-01 18:05

Over three thousand internet-exposed Apache ActiveMQ servers are vulnerable to a recently disclosed critical remote code execution vulnerability. Apache ActiveMQ is a scalable open-source message broker that fosters communication between clients and servers, supporting Java and various cross-language clients and many protocols, including AMQP, MQTT, OpenWire, and STOMP. Thanks to the project's support for a diverse set of secure authentication and authorization mechanisms, it is widely used in enterprise environments where systems communicate without direct connectivity.

Microsoft tests Windows 11 encrypted DNS server auto-discovery
2023-10-25 20:45

Microsoft is testing support for the Discovery of Network-designated Resolvers internet standard, which enables automated client-side discovery of encrypted DNS servers on local area networks. Without DNR support, users must manually enter the info of encrypted DNS servers on their local area network within the network settings.