Security News

Researchers warn of increased malware delivery via fake browser updates
2023-10-17 10:18

ClearFake, a recently documented threat leveraging compromised WordPress sites to push malicious fake browser updates, is likely operated by the threat group behind the SocGholish "Malware delivery via fake browser updates" campaigns, Sekoia researchers have concluded. Subsequently downloaded payloads create an iframe element to host the fake update interface, download that interface, and the fake update content and HTML page.

Microsoft fixes Windows 10 security update installation issue
2023-10-16 11:53

Microsoft has resolved a known issue that caused Windows 10 security updates released during this month's Patch Tuesday to fail with 0x8007000d errors. For systems impacted by this issue, specifically Windows 10 21H2 and Windows 10 22H2, the KB5031356 security update would fail despite displaying initial progress during deployment.

Steam enforces SMS verification to curb malware-ridden updates
2023-10-15 15:12

This is to deal with a recent outbreak of malicious updates pushing malware from compromised publisher accounts. Starting in late August and into September 2023, there has been an elevated number of reports about compromised Steamworks accounts and the attackers uploading malicious builds that infect players with malware.

Microsoft: October Windows 10 security updates fail to install
2023-10-13 19:56

Microsoft says Windows 10 security updates released during this month's Patch Tuesday may fail to install with 0x8007000d errors, although initially displaying progress. On systems affected by this known issue running client platforms, the KB5031356 security update will fail to complete installation.

Windows 10 KB5031356 update released with 25 improvements
2023-10-10 19:02

Microsoft has released the KB5031356 cumulative update for Windows 10 21H2 and Windows 10 22H2, with twenty-five fixes for various issues. KB5031356 is a mandatory Windows 10 cumulative update containing the October 2023 Patch Tuesday security updates.

Windows 11 KB5031354 cumulative update released with new features
2023-10-10 18:05

Microsoft has released the Windows 11 22H2 KB5031354 cumulative update to fix security vulnerabilities. KB5031354 is a mandatory Windows 11 cumulative update containing the October 2023 Patch Tuesday security updates.

October 2023 Patch Tuesday forecast: Operating system updates and zero-days aplenty
2023-10-06 04:42

The November Patch Tuesday cumulative update will include the Moment 4 features and updates. This patch Tuesday will include the last updates for Windows 11 21H2 and Microsoft Server 2012/2012 R2. The later go into Extended Security Support starting with a November release, and Microsoft also announced the keys used to enable these updates will be managed as part of Azure Arc.

Another security update, Apple? You're really keeping up with your tech rivals
2023-10-05 18:16

Apple has demonstrated that it can more than hold its own among the tech giants, at least in terms of finding itself on the wrong end of zero-day vulnerabilities. iOS and iPadOS have again come under attack, and Apple has rushed out a fix to ward off miscreants.

Apple emergency update fixes new zero-day used to hack iPhones
2023-10-04 18:19

Apple released emergency security updates to patch a new zero-day security flaw exploited in attacks targeting iPhone and iPad users. The zero-day is caused by a weakness discovered in the XNU kernel that enables local attackers to escalate privileges on unpatched iPhones and iPads.

Android October security update fixes zero-days exploited in attacks
2023-10-03 18:12

Google has released the October 2023 security updates for Android, addressing 54 unique vulnerabilities, including two known to be actively exploited. CVE-2023-4211 is an actively exploited flaw impacting multiple versions of Arm Mali GPU drivers used in a broad range of Android device models.