Security
Headlines
HeadlinesLatestCVEs

Tag

#microsoft

Ransomware market evolution results in fewer variants, but rise in off-the-shelf cybercrime kits continues

RaaS model continues to be adopted by criminals looking to maximize their ROI, new study indicates

PortSwigger
#vulnerability#microsoft#pdf#auth
APT Hackers Targeting Industrial Control Systems with ShadowPad Backdoor

Entities located in Afghanistan, Malaysia, and Pakistan are in the crosshairs of an attack campaign that targets unpatched Microsoft Exchange Servers as an initial access vector to deploy the ShadowPad malware. Russian cybersecurity firm Kaspersky, which first detected the activity in mid-October 2021, attributed it to a previously unknown Chinese-speaking threat actor. Targets include

Service Fabric Privilege Escalation from Containerized Workloads on Linux

Under Coordinated Vulnerability Disclosure (CVD), cloud-security vendor Palo Alto Networks informed Microsoft of an issue affecting Service Fabric (SF) Linux clusters (CVE-2022-30137). The vulnerability enables a bad actor, with access to a compromised container, to escalate privileges and gain control of the resource’s host SF node and the entire cluster.

Service Fabric Privilege Escalation from Containerized Workloads on Linux

Under Coordinated Vulnerability Disclosure (CVD), cloud-security vendor Palo Alto Networks informed Microsoft of an issue affecting Service Fabric (SF) Linux clusters (CVE-2022-30137). The vulnerability enables a bad actor, with access to a compromised container, to escalate privileges and gain control of the resource’s host SF node and the entire cluster.

You only have nine months to ditch Exchange Server 2013

Microsoft posted a reminder that Exchange Server 2013 is destined to reach end of support very, very soon. The post You only have nine months to ditch Exchange Server 2013 appeared first on Malwarebytes Labs.

Mailhog 1.0.1 Cross Site Scripting

Mailhog version 1.0.1 suffers from a persistent cross site scripting vulnerability.

Thrive Acquires DSM

DSM is now the third acquisition by Thrive in Florida in the past six months.

How to Use Microsoft Defender on All Your Devices

If you use a mix of Apple, Android, and Windows gadgets, you're in luck: The security tool is now available to any Microsoft 365 subscriber.

The Post-Roe Privacy Nightmare Has Arrived

Plus: Microsoft details Russia’s Ukraine hacking campaign, Meta’s election integrity efforts dwindle, and more.