Microsoft patches zero-days used by state-sponsored and ransomware threat actors (CVE-2023-23397, CVE-2023-24880)

Microsoft patches zero-days used by state-sponsored and ransomware threat actors (CVE-2023-23397, CVE-2023-24880)

It’s March 2023 Patch Tuesday, and Microsoft has delivered fixes for 76 CVE-numbered vulnerabilities, including two actively exploited in the wild (CVE-2023-23397, CVE-2023-24880) by different threat actors. About CVE-2023-23397 “CVE-2023-23397 is a critical EoP vulnerability in Microsoft Outlook that is...
Cyber Security Today, August 21, 2023 – The latest ransomware news, and security patches issued by Cisco, Juniper and Jenkins

Cyber Security Today, August 21, 2023 – The latest ransomware news, and security patches issued by Cisco, Juniper and Jenkins

The latest ransomware news, and security patches issued by Cisco, Juniper and Jenkins. Welcome to Cyber Security Today. It’s Monday, August 21st, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.   The Black...
OpenSSL patches are out – CRITICAL bug downgraded to HIGH, but patch anyway! – Naked Security

OpenSSL patches are out – CRITICAL bug downgraded to HIGH, but patch anyway! – Naked Security

We’ll begin with the vital stuff: the extensively awaited OpenSSL bugfixes introduced final week are out. OpenSSL 1.1.1 goes to model 1.1.1s, and patches one listed security-related bug, but this bug doesn’t have a safety score or an official CVE...
Zoom for Mac patches sneaky “spy-on-me” bug – update now! – Naked Security

Zoom for Mac patches sneaky “spy-on-me” bug – update now! – Naked Security

Popular and ubiquitous (software program isn’t at all times each of these issues!) cloud assembly firm Zoom not too long ago introduced an oops-that-wasn’t-supposed-to-happen bug within the Mac model of its software program. The safety bulletin is, forgivably, written within...
Business email platform Zimbra patches memcached injection flaw that imperils user credentials

Business email platform Zimbra patches memcached injection flaw that imperils user credentials

Adam Bannister 16 June 2022 at 11:04 UTC Updated: 16 June 2022 at 15:09 UTC Attackers may additionally doubtlessly achieve entry to varied inside providers, researcher warnsA memcached injection vulnerability in enterprise webmail platform Zimbra may enable attackers to steal...