article thumbnail

Patch Tuesday, November 2020 Edition

Krebs on Security

” A chief concern among all these updates this month is CVE-2020-17087 , which is an “important” bug in the Windows kernel that is already seeing active exploitation. “With no details provided by Microsoft, we can only assume this is the bypass of CVE-2020-16875 he had previously mentioned,” Childs said.

Software 279
article thumbnail

Microsoft Patch Tuesday, May 2020 Edition

Krebs on Security

“What is interesting and often overlooked is seven of the ten [fixes] at higher risk of exploit are only rated as Important,” Schell said. These include a pair of “Important” flaws in Win32k ( CVE-2020-1054 , CVE-2020-1143 ) and one in the Windows Graphics Component ( CVE-2020-1135 ).

Backups 276
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

CISA: Cisco ASA/FTD bug CVE-2020-3259 exploited in ransomware attacks

Security Affairs

CISA warns that the Akira Ransomware gang is exploiting the Cisco ASA/FTD vulnerability CVE-2020-3259 (CVSS score: 7.5) Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco ASA and FTD bug, tracked as CVE-2020-3259 (CVSS score: 7.5), to its Known Exploited Vulnerabilities catalog. in attacks in the wild.

article thumbnail

More on the Security of the 2020 US Election

Schneier on Security

Last week I signed on to two joint letters about the security of the 2020 election. To our collective knowledge, no credible evidence has been put forth that supports a conclusion that the 2020 election outcome in any state has been altered through technical compromise. The New York Times wrote about the letter.

article thumbnail

Risk managers: Here are the must-have skills for 2020

Tech Republic Security

The risk management field is growing more challenging as threats evolve. How will these changing threats affect your organization in 2020?

Risk 141
article thumbnail

The NIST Artificial Intelligence Risk Management Framework

SecureWorld News

National Institute of Standards and Technology (NIST) has published the Artificial Intelligence Risk Management Framework (AI RMF). NIST has been working on this framework for some time, as directed by the National Artificial Intelligence Initiative Act of 2020. Govern – Cultivating a risk management culture 2. Very likely.

article thumbnail

Patch Tuesday, Good Riddance 2020 Edition

Krebs on Security

Microsoft today issued its final batch of security updates for Windows PCs in 2020, ending the year with a relatively light patch load. Additionally, Microsoft released an advisory on how to minimize the risk from a DNS spoofing weakness in Windows Server 2008 through 2019.

DNS 278