Tag Threat Actor

November 19, 2022

Hello all, A few of the notable call-out’s from this week’s report (found below this introduction) are: I just read an interesting article that said Turkeys are notoriously difficult to hunt. They are well camouflaged and are “the smartest and…

November 12, 2022

A few of the notable call-out’s from this week’s report are: Research shows that criminals avoid homes that have CCTV and/or yappy dogs. Make sure that your network is being watched and has some yappy dogs running around in them.…

October 15, 2022

Microsoft October 2022 Patch Tuesday fixes two zero-days, 1 used in attacks, 84 flaws, 13 of which are critical The October 2022 Exchange SUs do not contain fixes for the zero-day vulnerabilities reported on September 29, 2022 Windows 11 KB5018427…

October 8, 2022

Fortinet warns admins to patch critical auth bypass bug immediately Updated information: Customer Guidance for Reported Zero-day Vulnerabilities in Microsoft Exchange Server Steam Gaming Phish Showcases Browser-in-Browser Threat ‘IT security issue’ impacts multiple hospitals across several states Microsoft investigates Windows…

September 30, 2022

Two Zero-Day Microsoft Exchange vulnerabilities without a patch are being exploited – mitigation steps published Microsoft Customer Guidance for Reported Zero-day Vulnerabilities in Microsoft Exchange Server Critical Remote Hack Flaws Found in Dataprobe’s Power Distribution Units WhatsApp 0-Day Bug Let…

September 9, 2022

QNAP patches zero-day used in new Deadbolt ransomware attacks Interpol and local Police dismantled an Asian Sextortion ring Zyxel has released patches for NAS products affected by a format string vulnerability HP fixes severe Privilege Escalation bug in pre-installed HP…

September 2, 2022

64% of Businesses Suspect They’ve Been Targeted or Impacted by Nation-State Attacks US House appropriators want to fund more than $15 billion for cybersecurity Microsoft adds virtual core licensing to Windows Server – major cloud hosts excluded New licensing benefits…

August 26, 2022

Microsoft shares workarounds for broken audio on Windows 10 after KB5015878 Cookie theft threat: When multi-factor authentication (MFA) is not enough CISA is warning of high-severity PAN-OS DDoS flaw used in attacks LastPass source code, blueprints stolen by intruder –…

August 19, 2022

Microsoft’s Secure Boot fix sends some PCs into BitLocker Recovery New macOS 12.5.1 and iOS 15.6.1 updates patch “actively exploited” vulnerabilities Microsoft will turn off TLS 1.0 and 1.1 in Internet Explorer and EdgeHTML on September 13 Exploit out for…

August 12, 2022

August 2022 Patch Tuesday | Microsoft Releases 121 Vulnerabilities with 17 Critical Microsoft August Patch Tuesday fixes critical Secure Boot GRUB vulnerability Microsoft blocks UEFI bootloaders enabling Windows Secure Boot bypass Microsoft warns about Windows update fails, UEFI update might…

August 5, 2022

VMware urges admins to patch critical auth bypass bug immediately Cisco fixes critical remote code execution bug in VPN routers Millions of Arris routers are vulnerable to path traversal attacks Critical RCE Bug Could Let Hackers Remotely Take Over DrayTek…

July 29, 20222

Qakbot Resurfaces With New Playbook Beware New Windows Vulnerability With Remote Search Window Access Critical Filewave MDM Vulnerabilities Allow Attackers Full Mobile Device Control Critical security vulnerability in Grails could lead to remote code execution Update Google Chrome now! New…