-
AA20-258A: Chinese Ministry of State Security-Affiliated Cyber Threat Actor Activity
Original release date: September 14, 2020 Summary The Cybersecurity and Infrastructure Security Agency (CISA) has consistently observed Chinese Ministry of State Security (MSS)-affiliated cyber threat actors using publicly available information sources and common, well-known tactics...- News
- Thread
- apt chinese threats cisa cobalt strike command and control cybersecurity data breach exploit incident response mimikatz mitre att&ck mss network security open source patch management ransomware spear phishing technical details threat actors vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
AA19-339A: Dridex Malware
Original release date: December 5, 2019 Summary This Alert is the result of recent collaboration between the Department of the Treasury Financial Sector Cyber Information Group (CIG) and the Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN) to identify and share...- News
- Thread
- bots cisa cybersecurity data breach dridex exploit financial fincen indicators of compromise intrusion detection intrusion prevention malspam malware mitigation phishing privacy ransomware security best practices trojan vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
Wormable Vulnerability (RDP service) in Out of Support Operating Systems
Pretty significant vulnerability that Microsoft is patching even for out of support versions of Windows. For the out of support the update is available only through the Windows Update Catalog. Microsoft Update Catalog TechNet Blog about the vulnerability and direct links to the patch download...- Neemobeer
- Thread
- catalog cve-2019-0708 exploit microsoft network outdated patch rdp remote desktop risk security software support system technet update vulnerability windows windows update
- Replies: 0
- Forum: Windows Security
-
Prevent a worm by updating Remote Desktop Services (CVE-2019-0708)
Today Microsoft released fixes for a critical Remote Code Execution vulnerability, CVE-2019-0708, in Remote Desktop Services – formerly known as Terminal Services – that affects some older versions of Windows. The Remote Desktop Protocol (RDP) itself is not vulnerable. This vulnerability is...- News
- Thread
- authentication cve-2019-0708 emergency patch exploit extended security updates legacy systems malware microsoft security network level authentication out-of-support patch management remote code execution remote desktop vulnerabilities wannacry windows 2003 windows 2008 windows 7 windows server windows xp
- Replies: 0
- Forum: Security Alerts
-
AA19-122A: New Exploits for Unsecure SAP Systems
Original release date: May 02, 2019 Summary The Cybersecurity and Infrastructure Security Agency (CISA) is issuing this activity alert in response to recently disclosed exploits that target unsecure configurations of SAP components. [1] Technical Details A presentation at the April 2019...- News
- Thread
- access control acls cisa configuration cybersecurity exploit internet exposure message server mitigation network security presentation remote code execution research routing sap security best practices security software snc system commands vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
Call for Papers | Microsoft BlueHat Shanghai 2019
The Microsoft Security Response Center (MSRC) recently announced our first BlueHat security conference in Shanghai which will take place on May 29-30, 2019. After 15 years of BlueHat events in Redmond, Washington and Israel, we are thrilled to expand to a new location. We work with many talented...- News
- Thread
- bluehat call for papers community conference cybersecurity engineering exploit firmware interpretation iot machine learning malware microsoft research security shanghai submission supply chain threats virtualization
- Replies: 0
- Forum: Security Alerts
-
Intel Foreshadow vulnerability
Intel has revealed another major security vulnerability in its CPUs, similar to the Meltdown/Spectre vulnerabilities revealed earlier this year. It is understood that at this time there are no current exploits and further information can be found on the released Link Removed . AMD chips are...- kemical
- Thread
- amd cache cache timing cpu cybersecurity exploit hardware information disclosure intel l1tf meltdown mitigation processor security side-channel spectre speculative execution technology vulnerability
- Replies: 1
- Forum: Windows Hardware
-
TA18-145A: Cyber Actors Target Home and Office Routers and Networked Devices Worldwide
Original release date: May 25, 2018 Systems Affected Small office/home office (SOHO) routers Networked devices Network-attached storage (NAS) devices Overview Cybersecurity researchers have identified that foreign cyber actors have compromised hundreds of thousands of home and office...- News
- Thread
- blackenergy cyber actors cybersecurity data loss dhs exploit fbi firmware intelligence malware network devices network security network traffic reboot router soho threats vpnfilter
- Replies: 0
- Forum: Security Alerts
-
Windows EMET making a come back.
Looks like EMET is coming back as a built-in feature in the fall creators update. I've personally always used it as a free added security measure. Like other security software it's not bullet proof and there have been bypasses, but it does a good job of protecting against common avenues used...- Neemobeer
- Thread
- bypass emet exploit fall creators update features malware protection security update windows 10
- Replies: 4
- Forum: Windows Security
-
Protecting customers and evaluating risk
Today, Microsoft triaged a large release of exploits made publicly available by Shadow Brokers. Understandingly, customers have expressed concerns around the risk this disclosure potentially creates. Our engineers have investigated the disclosed exploits, and most of the exploits are already...- News
- Thread
- collaboration customer safety cve-2017-0146 cve-2017-0147 engineering exchange 2010 exploit microsoft patch protection research response center risk assessment security security research threat mitigation update vulnerabilities windows 7
- Replies: 0
- Forum: Security Alerts
-
Strengthening the Microsoft Edge Sandbox
In a recent post, we outlined the layered strategy that the Microsoft Edge security team employs to protect you from vulnerabilities that could be used to compromise your device or personal data. In particular, we showed how Microsoft Edge is leveraging technologies like Code Integrity Guard...- News
- Thread
- appcontainer attack brokers browser capabilities creatersupdate defense edge exploit flash player microsoft mitigation privilege protected mode rce sandbox security surface vulnerabilities web
- Replies: 0
- Forum: Live RSS Feeds
-
MS17-016 - Important: Security Update for Windows IIS (4013074) - Version: 1.0
Severity Rating: Important Revision Note: V1.0 (March 14, 2017): Click here to enter text. Summary: This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker with access to the local system executes a malicious...- News
- Thread
- admin rights exploit iis local system malicious software march microsoft ms17-016 remote code execution security security patch update user account user rights version 1.0 vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS17-010 - Critical: Security Update for Microsoft Windows SMB Server (4013389) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (March 14, 2017): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Windows. The most severe of the vulnerabilities could allow remote code execution if an attacker sends specially crafted messages to a Windows...- News
- Thread
- critical cybersecurity exploit extended security updates march microsoft ms17-010 network security patch remote code execution revision note server smb server technet threats update version 1.0 vulnerabilities windows windows update
- Replies: 0
- Forum: Security Alerts
-
MS17-007 - Critical: Cumulative Security Update for Microsoft Edge (4013071) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (March 14, 2017): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Edge. The most severe of the vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Microsoft Edge...- News
- Thread
- critical cumulative data security exploit extended security updates march microsoft edge ms17-007 remote code execution revision note system control update bulletin user rights vulnerabilities webpage
- Replies: 0
- Forum: Security Alerts
-
Mitigating arbitrary native code execution in Microsoft Edge
Some of the most important security features in modern web browsers are those that you never actually see as you browse the web. These security features work behind the scenes to protect you from browser-based vulnerabilities that could be abused by hackers to compromise your device or personal...- News
- Thread
- arbitrary code browser code integrity control flow guard creators update cybersecurity execution exploit exploit prevention jit compilation memory safety microsoft edge mitigation native code security smartscreen user mode vulnerabilities windows 10 windows defender
- Replies: 0
- Forum: Live RSS Feeds
-
MS16-144 - Critical: Cumulative Security Update for Internet Explorer (3204059) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (December 13, 2016): Bulletin published. Summary: This security update resolves vulnerabilities in Internet Explorer. The most severe of the vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet...- News
- Thread
- account management admin rights attack bulletin control critical cumulative data protection december 2016 exploit internet explorer ms16-144 remote code execution revision note security update user rights vulnerabilities webpage
- Replies: 0
- Forum: Security Alerts
-
firefox/tor zero-day exploit …
for everyone using firefox (or tor) … update your browser immediately … there are some critical updates you don't want to miss. the updates are engineered to circumvent a zero-day exploit. according to the article(s) posted below … evidently, pc 'n mac 'n linux...- pnamajck
- Thread
- exploit firefox tor zero-day
- Replies: 1
- Forum: Windows Security
-
Defending against ransomware with Windows 10 Anniversary Update
Ransomware is one of the latest malware threats that is attracting an increasing number of cyber-criminals who are looking to profit from it. In fact, in the last 12 months, the number of ransomware variants have more than doubled. Its premise is deceptively simple: infect users’ devices, and...- News
- Thread
- advanced threat protection anniversary backup browser hardening cloud security consumer protection cybersecurity email security endpoint security enterprise security exploit machine learning malware post-breach defense pro ransomware security settings threat detection windows 10 windows defender
- Replies: 0
- Forum: Live RSS Feeds
-
MS16-138 - Important: Security Update for Microsoft Virtual Hard Disk Driver (3199647) -...
Severity Rating: Important Revision Note: V1.0 (November 8, 2016): Bulletin published. Summary: The Windows Virtual Hard Disk Driver improperly handles user access to certain files. An attacker can manipulate files in locations not intended to be available to the user by exploiting this...- News
- Thread
- access control bulletin driver issues exploit file management important manipulation microsoft ms16-138 patch revision note risk assessment security technical details update virtual drive vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS16-118 - Critical: Cumulative Security Update for Internet Explorer (3192887) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (October 11, 2016): Bulletin published. Summary: This security update resolves vulnerabilities in Internet Explorer. The most severe of the vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet...- News
- Thread
- admin rights attacker bulletin critical update cumulative update data security exploit internet explorer ms16-118 october patch remote code execution revision note security system control update user account user rights vulnerabilities webpage threats
- Replies: 0
- Forum: Security Alerts