July 19, 2025

Hello all, What started out as a somewhat quiet week, with only one nasty item early on from Google Chrome, escalated slowly with the last few days bringing reveals of multiple critical and high-severity vulnerabilities in products by Cisco, CrushFTP, HPE, Microsoft, Sophos, Symantec and more. To offset some of the…

July 12, 2025

Hello all, Wow, another Patch Tuesday for the records! Microsoft offered up fixes for 137 flaws, with at least one zero-day in the mix. Adobe patched 58 vulnerabilities across multiple products, Ivanti plugged more holes, Fortinet patched just about everything they make. Splunk released fixes, and the list goes on. Basically,…

July 5, 2025

Hello all, The United States of America turned 249 on Friday. Hopefully, all of our US based readers still have all of their digits and have recovered most of their hearing from the celebratory fireworks, both public and private. Speaking of fireworks, this coming week is Patch Tuesday, expect an incoming…

June 28, 2025

Hello all, As we close out the first half of the year, there were a number of new vulnerability and defects revealed that need attention. We must stay diligent to remediate, patch, and mitigate these issues as they arise. On the malevolent human front, defying industry expectations and warnings, there has…

June 21, 2025

Hello all, Iranian cyber-criminals are among the world’s best and most effective. And with the middle eastern war now involving the United States, expect that many of these well-trained spies and thieves will become agents of chaos and destruction targeting American companies and infrastructure. Having your data encrypted unless you pay…

June 14, 2025

Hello all, As expected, Microsoft and a cadre of other vendors unleashed updates this past week. I shouldn’t be surprised that the quantity appears to be increasing, but I am. With the concerted push for the past few years on zero-trust, and memory safe software, shouldn’t the defects be decreasing? Microsoft,…

June 7, 2025

Hello all, With the Patch Tuesday onslaught coming next week, I was happy to see that this was another somewhat quiet week as far as vulnerabilities and zero-day reveals are concerned. Last month I was quite wrong in my prediction of fewer vulnerabilities coming out, so this month, I’ll just wait…

May 31, 2025

Hello all, It seemed to me that this week was mercifully quiet on the global scale, with fewer massive holes and defects being revealed. That’s not so say that dirtbags took the week off, oh no, they already have plenty of the aforementioned flaws available to enable their nefarious activity. They…

May 24, 2025

Hello all, It was a busy news week with a nice smattering of good news of indictments and takedowns of threat actors and their infrastructure. Pwn2Own Berlin concluded with 29 zero-days being utilized. Some have already been patched, others are now under a 90-day clock for vendors to patch before the…

May 17, 2025

Hello all, Along with the usual Microsoft Patch Tuesday scramble, this week brought an explosion of updates and vulnerability reveals from a lot of other vendors and products, ranging from ASUS to VMware – almost to Z. Headline NEWS: In Ransomware, Malware, and Vulnerabilities News: In Other News Events of Note…

May 10, 2025

Hello all, After a slow start to the week, we closed it out with a few very serious vulnerabilities made public by Cisco, SonicWall, and Ubiquiti. This coming week is Patch Tuesday and if historic numbers are a valid guide, I expect about 40 items to be patched by Microsoft, and…

May 3, 2025

Hello all, Last week was “World Password Week”. However, this year many tech giants chose, to replace “password” with “passkey”. In fact, on what was World Password Day, Microsoft announced that all new Microsoft accounts will now be passwordless, use passkeys by default, and existing accounts will be transitioned as quickly…