Remove mitigations-available-latest-office-zero-day
article thumbnail

Apple & Microsoft Patch Tuesday, July 2023 Edition

Krebs on Security

Meanwhile, Apple customers have their own zero-day woes again this month: On Monday, Apple issued (and then quickly pulled) an emergency update to fix a zero-day vulnerability that is being exploited on MacOS and iOS devices. The two other zero-day threats this month for Windows are both privilege escalation flaws.

Software 205
article thumbnail

Microsoft Targets Critical Outlook Zero-Day Flaw

eSecurity Planet

Microsoft’s Patch Tuesday for March 2023 includes patches for more than 70 vulnerabilities, including zero-day flaws in Outlook and in Windows SmartScreen. Critical Outlook Zero-Day The Outlook zero-day, CVE-2023-23397 , with a critical CVSS score of 9.8, Office documents? all of them?)

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

IT threat evolution Q2 2022

SecureList

In recent months, they have also become more interested in businesses located in other East Asian countries and their China-based offices. You can find more details, including appropriate mitigation steps, in our blog post. Provide your SOC team with access to the latest threat intelligence. Follina vulnerability in MSDT.

Mobile 79
article thumbnail

Hackers exploit unpatched vulnerabilities, zero day to attack governments and contractors

SC Magazine

While the cybersecurity community pumps out a seemingly unending list of newly discovered software and hardware vulnerabilities each day, many organizations are far more likely to be compromised in part or in whole by older flaws that have yet to be patched. and Europe. and Europe.

article thumbnail

Protecting Against Ransomware 3.0 and Building Resilience

Duo's Security Blog

Twenty-nine per cent of incidents reported to the Office of the Australian Information Commissioner (OAIC) were attributed to ransomware between July and December of 2022, making it the most reported type of security breach of the year. billion annually from these incidents. The Rise of Ransomware 3.0 in Australia What is Ransomware 3.0?

article thumbnail

Easily Exploitable Linux Flaw Exposes All Distributions: Qualys

eSecurity Planet

An easily exploited flaw in a program found in every major Linux distribution is the latest serious security issue that has arisen in the open-source space in recent weeks. Until patches are broadly available, SysAdmins can remove the SUID bit from pkexec – using: # chmod 0755 /usr/bin/pkexec — to temporarily mitigate the problem.”.