Security Bulletin
12 Nov 2024
Biztonsági szemle
2 Zero-Day Bugs in Microsoft's Nov. Update Under Active Exploit
The November 2024 Patch Tuesday update contains a substantially high percentage of remote code execution (RCE) vulnerabilities (including a critical issue in Windows Kerberos), and two other zero-day bugs that have been previously disclosed and could...
12 Nov 2024
Biztonsági szemle
Amazon Employee Data Compromised in MOVEit Breach
The data leak was not actually due to a breach in Amazon's systems but rather that of a third-party vendor; the supply chain incident affected several other clients as well.
12 Nov 2024
Biztonsági szemle
Millions of records from MOVEit hack released on dark web
Reportedly 2.8 million Amazon records alone were exposed.
12 Nov 2024
Biztonsági szemle
New Essay Competition Explores AI's Role in Cybersecurity
The essays are to focus on the impact that artificial intelligence will have on European policy.
12 Nov 2024
Biztonsági szemle
CrowdStrike Spends to Boost Identity Threat Detection
Adaptive Shield is the third security posture management provider the company has acquired in the last 14 months as identity-based attacks continue to rise.
12 Nov 2024
Biztonsági szemle
'GoIssue' Cybercrime Tool Targets GitHub Developers En Masse
Marketed on a cybercriminal forum, the $700 tool harvests email addresses from public GitHub profiles, priming cyberattackers for further credential theft, malware delivery, OAuth subversion, supply chain attacks, and other corporate breaches.
12 Nov 2024
Biztonsági szemle
Citrix Issues Patches for Zero-Day Recording Manager Bugs
There is some disagreement over whether the remote code execution (RCE) security flaws allow for unauthenticated exploitation or not. Citrix says no, but researchers say the company is downplaying a "good old unauthenticated RCE."
12 Nov 2024
Biztonsági szemle
Citrix 'Recording Manager' Zero-Day Bug Allows Unauthenticated RCE
The security vulnerability is due to an exposed Microsoft Message Queuing (MSMQ) instance and the use of the insecure BinaryFormatter.
12 Nov 2024
Biztonsági szemle
The Power of the Purse: How to Ensure Security by Design
CISA should make its recommended goals mandatory and perform audits to ensure compliance.
12 Nov 2024
Biztonsági szemle
The rise of phishing-resistant MFA and what it means for a passwordless future
Slowly but surely, phishing-resistant forms of multi-factor authentication are catching on. Here's how to join the movement, and how it can lead to a fully passwordless environment.
12 Nov 2024
Biztonsági szemle
Single points of failure breed systemic risk to national security
The industry needs to adopt a collaborative approach to undercover single points of failure before our adversaries exploit them.
12 Nov 2024
Biztonsági szemle
Toward greater transparency: Publishing machine-readable CSAF files
Welcome to the third installment in our series on transparency at the Microsoft Security Response Center (MSRC). In this ongoing discussion, we talk about our commitment to providing comprehensive vulnerability information to our customers. At MSRC...
Pagination
- Previous page ‹‹
- Page 385
- Next page ››