Security
Headlines
HeadlinesLatestCVEs

Tag

#microsoft

Microsoft Azure Vulnerability Exposes PostgreSQL Databases to Other Customers

Microsoft on Thursday disclosed that it addressed a pair of issues with the Azure Database for PostgreSQL Flexible Server that could result in unauthorized cross-account database access in a region. "By exploiting an elevated permissions bug in the Flexible Server authentication process for a replication user, a malicious user could leverage an improperly anchored regular expression to bypass

The Hacker News
#sql#vulnerability#windows#microsoft#perl#auth#postgres#The Hacker News
Microsoft Patches Pair of Dangerous Vulnerabilities in Azure PostgreSQL

Flaws gave attackers a way to access other cloud accounts and databases, security vendor says.

Microsoft: Russia Using Cyberattacks in Coordination With Military Invasion of Ukraine

Six Russian state-backed threat actors have lunched 237 cyberattacks on Ukraine's infrastructure, new research from MIcrosoft shows.

Threat Source newsletter (April 28, 2022) — The 2022 Cybersecurity Mock Draft

By Jon Munshaw.  Welcome to this week’s edition of the Threat Source newsletter that’s going to be a little different, but bear with me.  In honor of the NFL Draft starting this evening — an event that Cisco is helping to secure — I thought it’d be appropriate to look at building a... [[ This is only the beginning! Please visit the blog for the complete entry ]]

CVE-2022-1501: Chromium: CVE-2022-1501 Inappropriate implementation in iframe

**What is the version information for this release?** Microsoft Edge Version Date Released Based on Chromium Version 101.0.1210.32 4/28/2022 101.0.4951.41

CVE-2022-1500: Chromium: CVE-2022-1500 Insufficient data validation in Dev Tools

**What is the version information for this release?** Microsoft Edge Version Date Released Based on Chromium Version 101.0.1210.32 4/28/2022 101.0.4951.41

CVE-2022-1499: Chromium: CVE-2022-1499 Inappropriate implementation in WebAuthentication

**What is the version information for this release?** Microsoft Edge Version Date Released Based on Chromium Version 101.0.1210.32 4/28/2022 101.0.4951.41

CVE-2022-1498: Chromium: CVE-2022-1498 Inappropriate implementation in HTML Parser

**What is the version information for this release?** Microsoft Edge Version Date Released Based on Chromium Version 101.0.1210.32 4/28/2022 101.0.4951.41

CVE-2022-1497: Chromium: CVE-2022-1497 Inappropriate implementation in Input

**What is the version information for this release?** Microsoft Edge Version Date Released Based on Chromium Version 101.0.1210.32 4/28/2022 101.0.4951.41

CVE-2022-1495: Chromium: CVE-2022-1495 Incorrect security UI in Downloads

**What is the version information for this release?** Microsoft Edge Version Date Released Based on Chromium Version 101.0.1210.32 4/28/2022 101.0.4951.41