-
Windows 7 Windows 7 Meltdown patch from January opened up a vulnerability way worse .
Total Meltdown? Is my system vulnerable? Only Windows 7 x64 systems patched with the 2018-01 or 2018-02 patches are vulnerable. If your system isn't patched since December 2017 or if it's patched with the 2018-03 2018-03-29 patches or later it will be secure. Reference and further...- kemical
- Thread
- 2018 updates exploitation in-process memory kernel memory meltdown memory access memory mapping patch performance process management read/write security unprivileged access update user awareness vulnerabilities vulnerability windows 7 windows security
- Replies: 1
- Forum: Windows Upgrade and Installation
-
Meltdown and Spectre: CPU vulnerabilities patched
New vulnerabilities have recently been discovered with modern cpu's: It would seem Intel are more prone to attack than AMD: Meltdown and Spectre Microsoft have released patches which will be available via Windows update. If like me yours hasn't arrived then download the standalone...- kemical
- Thread
- amd cloud solutions cpu data theft desktop exploitation hardware intel laptop meltdown patch privacy security spectre update vulnerabilities windows 10 windows 7 windows 8.1
- Replies: 39
- Forum: Windows Security
-
TA17-163A: CrashOverride Malware
Original release date: June 12, 2017 | Last revised: July 27, 2017 Systems Affected Industrial Control Systems Overview The National Cybersecurity and Communications Integration Center (NCCIC) is aware of public reports from ESET and Dragos outlining a new, highly capable Industrial...- News
- Thread
- attack authentication crashoverride cybersecurity detection exploitation ics industrial control systems infrastructure malware mitigation monitoring nccic remote access response risk assessment threats ttps vulnerability
- Replies: 0
- Forum: Security Alerts
-
TA17-132A: Indicators Associated With WannaCry Ransomware
Original release date: May 12, 2017 | Last revised: May 19, 2017 Systems Affected Microsoft Windows operating systems Overview According to numerous open-source reports, a widespread ransomware campaign is affecting various organizations with reports of tens of thousands of infections in...- News
- Thread
- backup bitcoin cybersecurity dhs exploitation extended security updates fbi iocs malicious software malware microsoft ms17-010 network security phishing prevention ransomware threat response vulnerability wannacry windows
- Replies: 0
- Forum: Security Alerts
-
4025685 - Guidance related to June 2017 security update release - Version: 1.0
Revision Note: V1.0 (June 13, 2017): Advisory published Summary: Microsoft is announcing the availability of additional guidance for critical security updates, that are at heightened risk of exploitation due to past and threatened nation-state attacks and disclosures. Some of the releases are...- News
- Thread
- advisory critical exploitation guidance information disclosure june microsoft nation older platforms patch management public availability risk security update version 1.0 vulnerability
- Replies: 0
- Forum: Security Alerts
-
ssd-drives vulnerable to attacks …
just wanting to run this past you guys … this post is straight from our good friends at bleepingcomputer.com … and the issue is in regards to the inherent vulnerabilities with current ssd-drives. i don't have much to say, since i do not own an ssd-drive …...- pnamajck
- Thread
- approach bleepingcomputer cybersecurity data corruption exploitation file advisory hardware information security pdf personal environment privacy research security ssd storage devices technical technical aspects user data virus scan vulnerabilities
- Replies: 4
- Forum: Windows Security
-
MS17-021 - Important: Security Update for Windows DirectShow (4010318) - Version: 1.0
Severity Rating: Important Revision Note: V1.0 (March 14, 2017): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow an Information Disclosure if Windows DirectShow opens specially crafted media content that is hosted on...- News
- Thread
- 4010318 attack bulletin directshow exploitation information disclosure malicious website march media content microsoft patch revision note security security bulletin system compromise update version 1.0 vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS16-153 - Important: Security Update for Common Log File System Driver (3207328) -...
Severity Rating: Important Revision Note: V1.0 (December 13, 2016): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow Information Disclosure when the Windows Common Log File System (CLFS) driver improperly handles...- News
- Thread
- clfs common log file system december 2016 exploitation information disclosure local attack microsoft ms16-153 security update vulnerability
- Replies: 0
- Forum: Security Alerts
-
MS16-148 - Critical: Security Update for Microsoft Office (3204068) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (December 13, 2016): Bulletin published Summary: This security update resolves vulnerabilities in Microsoft Office. The most severe of the vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file...- News
- Thread
- arbitrary code critical cybersecurity december 2016 exploitation extended security updates information security malware prevention microsoft office ms16-148 patch remote code execution revision note software update system admin technical bulletin user impact user rights vulnerability
- Replies: 0
- Forum: Security Alerts
-
MS16-121 - Important: Security Update for Microsoft Office (3194063) - Version: 1.0
Severity Rating: Important Revision Note: V1.0 (October 11, 2016): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Office. An Office RTF remote code execution vulnerability exists in Microsoft Office software when the Office software fails to properly...- News
- Thread
- arbitrary code bulletin cybersecurity exploitation microsoft microsoft office ms16-121 october patch remote code execution revision note rtf security software update threat mitigation update user context vulnerability
- Replies: 0
- Forum: Security Alerts
-
MS16-123 - Important: Security Update for Windows Kernel-Mode Drivers (3192892) - Version: 1.0
Severity Rating: Important Revision Note: V1.0 (October 11, 2016): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Windows. The more severe of the vulnerabilities could allow elevation of privilege if an attacker logs on to an affected system and runs a...- News
- Thread
- application attacker bulletin control drivers exploitation important kernel-mode microsoft ms16-123 october patch privilege revision security system technical update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS16-107 - Critical: Security Update for Microsoft Office (3185852) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (September 13, 2016): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Office. The most severe of the vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file...- News
- Thread
- arbitrary code critical cybersecurity exploitation extended security updates malware microsoft office ms16-107 office files patch remote code execution revision note security september software security update user account control user rights vulnerabilities
- Replies: 0
- Forum: Security Alerts
-
MS16-102 - Critical: Security Update for Microsoft Windows PDF Library (3182248) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (August 9, 2016): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user views specially crafted PDF content online or opens a specially crafted...- News
- Thread
- 2016 admin rights critical cybersecurity data security exploit exploitation extended security updates microsoft ms16-102 patch pdf remote code execution security bulletin software update technical note user account control user rights vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS16-070 - Critical: Security Update for Microsoft Office (3163610) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (June 14, 2016): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file. An attacker who...- News
- Thread
- arbitrary code attacker bulletin critical execution exploitation files june microsoft ms16-070 office patch remote code execution revision security software update user rights vulnerability
- Replies: 0
- Forum: Security Alerts
-
TA16-132A: Exploitation of SAP Business Applications
Original release date: May 11, 2016 Systems Affected Outdated or misconfigured SAP systems Overview At least 36 organizations worldwide are affected by an SAP vulnerability Link Removed. Security researchers from Onapsis discovered indicators of exploitation against these organizations’ SAP...- News
- Thread
- business applications cloud security crm erp exploitation governance invoker servlet mitigation onapsis patch management plm regulatory compliance remote access risk management sap scm security threat intelligence vulnerability
- Replies: 0
- Forum: Security Alerts
-
MS16-058 - Important: Security Update for Windows IIS (3141083) - Version: 1.0
Severity Rating: Important Revision Note: V1.0 (May 10, 2016): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker with access to the local system executes a malicious application. An...- News
- Thread
- 2016 admin rights bulletin exploitation iis malicious software microsoft ms16-058 patch remote code execution revision note security security bulletin update user account user rights vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
TA16-105A: Apple Ends Support for QuickTime for Windows; New Vulnerabilities Announced
Original release date: April 14, 2016 Systems Affected Microsoft Windows with Apple QuickTime installed Overview According to Trend Micro, Apple will no longer be providing security updates for QuickTime for Windows, leaving this software vulnerable to exploitation. [1] Description All...- News
- Thread
- advisories apple cybersecurity data loss exploitation integrity privacy quicktime remote access security software support trend micro uninstall vulnerabilities windows zero day initiative
- Replies: 0
- Forum: Security Alerts
-
MS16-001 - Critical: Cumulative Security Update for Internet Explorer (3124903) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (January 12, 2016): Bulletin published. Summary: This security update resolves vulnerabilities in Internet Explorer. The more severe of the vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet...- News
- Thread
- 2016 admin rights critical cumulative update data security exploitation extended security updates internet explorer malware ms16-001 patch remote code execution revision note security bulletin system control technet user account user rights vulnerability web security
- Replies: 0
- Forum: Security Alerts
-
MS15-124 - Critical: Cumulative Security Update for Internet Explorer (3116180) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (December 8, 2015): Bulletin published. Summary: This security update resolves vulnerabilities in Internet Explorer. The most severe of the vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet...- News
- Thread
- 2015 admin rights attacker bulletin critical cumulative exploitation internet explorer ms15-124 patch remote code execution security technet update user account user rights vulnerabilities webpage
- Replies: 0
- Forum: Security Alerts
-
TA15-314A: Web Shells – Threat Awareness and Guidance
Original release date: November 10, 2015 Systems Affected Web servers that allow web shells Overview This alert describes the frequent use of web shells as an exploitation vector. Web shells can be used to obtain unauthorized access and can lead to wider network compromise. This alert...- News
- Thread
- asp command and control cybersecurity data exfiltration detection exploitation incident response malware mitigation network compromise perl php python remote access security best practices software security threats update vulnerabilities web shells
- Replies: 0
- Forum: Security Alerts