Security News

At Least 10 Threat Actors Targeting Recent Microsoft Exchange Vulnerabilities
2021-03-11 14:04

At least 10 threat actors are currently involved in the targeting of Microsoft Exchange servers that are affected by recently disclosed zero-day vulnerabilities, according to cybersecurity firm ESET. On March 2, Microsoft announced patches for four bugs that were part of a pre-authentication remote code execution attack chain already being exploited in the wild. Now, ESET reveals that at least 10 threat actors are actively engaged in such attacks, including Tick, LuckyMouse, Calypso, Websiic, Winnti Group, Tonto Team, ShadowPad, Mikroceen, and DLTMiner.

Adobe fixes critical Creative Cloud, Adobe Connect vulnerabilities
2021-03-09 16:27

Adobe has released security updates that fix vulnerabilities in Adobe Creative Cloud Desktop, Framemaker, and Connect. In total, the company fixed eight vulnerabilities today, with the majority of them rated as Critical as they allow arbitrary code execution.

Siemens Releases Several Advisories for Vulnerabilities in Third-Party Components
2021-03-09 14:44

Siemens on Tuesday published 12 new security advisories to inform customers about nearly two dozen vulnerabilities affecting its products. Half of the new advisories cover vulnerabilities in third-party components.

On Not Fixing Old Vulnerabilities
2021-03-09 12:16

How is this even possible? …26% of companies Positive Technologies tested were vulnerable to WannaCry, which was a threat years ago, and some even vulnerable to Heartbleed. “The most frequent...

Microsoft Shares Additional Mitigations for Exchange Server Vulnerabilities Under Attack
2021-03-06 15:30

Microsoft on Friday released alternative mitigation measures for organizations who have not been able to immediately apply emergency out-of-band patches released earlier this week that address vulnerabilities being exploited to siphon e-mail data from corporate Microsoft Exchange servers. "These mitigations are not a remediation if your Exchange servers have already been compromised, nor are they full protection against attack," Microsoft warned in a blog post.

Microsoft: Exchange updates can install without fixing vulnerabilities
2021-03-05 15:12

Due to the critical nature of recently issued Microsoft Exchange security updates, admins need to know that the updates may have installation issues on servers where User Account Control is enabled. Microsoft has added these warnings to all Exchange security updates released throughout the last few years.

Cybercriminals innovate to find vulnerabilities that can be monetized
2021-03-04 05:00

Overall unique threats in the wild increased two folds from 389 in 2019 to 600 unique threats in 2020. The financial sector is the most proactive and concerned with cyber threats, running 39% of the total assessments performed, and the technology sector is the second most security conscious.

GRUB2 boot loader reveals multiple high severity vulnerabilities
2021-03-03 19:37

GRUB, a popular boot loader used by Unix-based operating systems has fixed multiple high severity vulnerabilities. In 2020, BleepingComputer had reported on the BootHole vulnerability in GRUB2 that could have let attackers compromise an operating system's booting process even if the Secure Boot verification mechanism was active.

Now-fixed Linux kernel vulnerabilities enabled local privilege escalation (CVE-2021-26708)
2021-03-03 14:00

Security researcher Alexander Popov has discovered and fixed five similar issues in the virtual socket implementation of the Linux kernel. The vulnerabilities could be exploited for local privilege escalation, as confirmed in experiments on Fedora 33 Server.

GPS Vulnerabilities
2021-02-22 12:17

Really good op-ed in the New York Times about how vulnerable the GPS system is to interference, spoofing, and jamming - and potential alternatives. The 2018 National Defense Authorization Act included funding for the Departments of Defense, Homeland Security and Transportation to jointly conduct demonstrations of various alternatives to GPS, which were concluded last March.