article thumbnail

Microsoft Patch Tuesday, April 2020 Edition

Krebs on Security

Near the top of the heap is CVE-2020-1020 , a remotely exploitable bug in the Adobe Font Manager library that was first detailed in late March when Microsoft said it had seen the flaw being used in active attacks. Also, keep an eye on the AskWoody blog from Woody Leonhard , who keeps a close eye on buggy Microsoft updates each month.

Backups 254
article thumbnail

Microsoft Patch Tuesday, May 2020 Edition

Krebs on Security

” For example, Satnam Narang from Tenable notes that two remote code execution flaws in Microsoft Color Management ( CVE-2020-1117 ) and Windows Media Foundation ( CVE-2020-1126 ) could be exploited by tricking a user into opening a malicious email attachment or visiting a website that contains code designed to exploit the vulnerabilities.

Backups 276
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Hackers are scanning the internet for vulnerable Salt installs, Ghost blogging platform hacked

Security Affairs

Hackers are conducting a mass-scanning the Internet for vulnerable Salt installs that could allow them to hack the organizations, the last victim is the Ghost blogging platform. The two flaws, tracked as CVE-2020-11651 and CVE-2020-11652, are a directory traversal issue and an authentication bypass vulnerability respectively.

Internet 112
article thumbnail

Chinese linked to two attacks on internet-facing SolarWinds server

SC Magazine

The Chinese espionage group Spiral may be to blame for two intrusions in 2020 to a SolarWinds Orion server that were linked to each other but not to the infamous SolarWinds attack attributed to Russia. ( “Peter @ Solarwinds office” by ecooper99 is licensed under CC BY 2.0 ). The second attack happened in late 2020.

Internet 106
article thumbnail

One billion dollars lost by over-60s through online fraud in 2020, says FBI

Hot for Security

According to a newly-published report by the FBI’s Internet Crime Complaint Center (IC3), the elderly are more at risk from falling victim to online fraud and internet scammers than ever before. Read more in my article on the Hot for Security blog.

Internet 145
article thumbnail

FBI: Victims Lost $4.2 Billion to Cybercriminals in 2020

Heimadal Security

The Federal Bureau of Investigation’s Internet Crime Complaint Center (IC3) has published its annual report for 2020, revealing that a total loss of $4.2 Billion to Cybercriminals in 2020 appeared first on Heimdal Security Blog. Billion to Cybercriminals in 2020 appeared first on Heimdal Security Blog.

article thumbnail

Microsoft fixes CVE-2020-0796, the SMBv3 wormable bug recently leaked

Security Affairs

Microsoft released security updates to fix a recently disclosed CVE-2020-0796 vulnerability in SMBv3 protocol that could be abused by wormable malware. Microsoft has released security updates to address the CVE-2020-0796 vulnerability in SMBv3 protocol that could be exploited by vxers to implement “ wormable ” malware.