Tag: update
-
Xerox Versalink Printer Vulnerabilities Enable Lateral Movement
Xerox released security updates to resolve pass-back attack vulnerabilities in Versalink multifunction printers. The post Xerox Versalink Printer Vulnerabilities Enable Lateral Movement appeared first on SecurityWeek. First seen on securityweek.com Jump to article: www.securityweek.com/xerox-versalink-printer-vulnerabilities-enable-lateral-movement/
-
Microsoft rolls out BIOS update that fixes ASUS blue screen issues
More ASUS customers can now install Windows 11 24H2 after applying a BIOS update that resolves blue screen of death (BSOD) issues acknowledged in October. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-rolls-out-bios-update-that-fixes-asus-blue-screen-issues/
-
Linux Kernel 6.14 rc3 Released With The Fixes for Critical Issues
Linus Torvalds has announced the release of Linux Kernel 6.14-rc3, marking a critical milestone in stabilizing the upcoming 6.14 kernel version. This release candidate addresses architectural vulnerabilities and introduces the lightweight >>Faux Bus
-
Winzip: Sicherheitslücke ermöglicht Unterschieben von Schadcode
Eine Schwachstelle in Winzip ermöglicht Angreifern, mit manipulierten Archiven beliebigen Code einzuschleusen. Ein Update korrigiert das. First seen on heise.de Jump to article: www.heise.de/news/Winzip-Sicherheitsluecke-ermoeglicht-Unterschieben-von-Schadcode-10284660.html
-
KB5051987: Windows-11-Update macht den Explorer kaputt
Das Update KB5051987 für Windows 11 24H2 bereitet Anwendern Kopfzerbrechen. Bei einigen spinnt der Explorer, andere können das Update gar nicht installieren. First seen on golem.de Jump to article: www.golem.de/news/kb5051987-windows-11-update-macht-den-explorer-kaputt-2502-193396.html
-
How to evaluate and mitigate risks to the global supply chain
Tags: access, business, ceo, ciso, communications, compliance, control, cyberattack, cybersecurity, data, framework, governance, government, intelligence, international, ISO-27001, kaspersky, microsoft, mitigation, monitoring, office, resilience, risk, risk-assessment, risk-management, russia, service, soc, software, supply-chain, technology, threat, tool, update, vulnerabilityMaintain a diversified supply chain: Organizations that source from international technology suppliers need to ensure they are not overly reliant on a single vendor, single region or even a single technology. Maintaining a diversified supply chain can mitigate costly disruptions from a cyberattack or vulnerability involving a key supplier, or from disruptions tied to regulatory…
-
Angriffe auf Sicherheitslücken in iOS, iPadOS, Mitel SIP-Phones und PAN-OS
IT-Forscher haben Angriffe auf Sicherheitslücken in iPadOS, Mitel SIP-Phones und PAN-OS beobachtet. Updates dichten die Sicherheitslecks ab. First seen on heise.de Jump to article: www.heise.de/news/Angreifer-attackieren-Sicherheitsluecken-in-iOS-Mitel-SIP-Phones-und-PAN-OS-10284172.html
-
Google Chrome Introduces AI to Block Malicious Websites and Downloads
Google has taken a significant step in enhancing internet safety by integrating artificial intelligence (AI) into its >>Safe Browsing
-
Software Bill of Material umsetzen: Die besten SBOM-Tools
Tags: api, business, compliance, container, cyberattack, data, docker, gartner, github, gitlab, healthcare, linux, monitoring, open-source, risk, saas, sbom, service, software, tool, update, vulnerabilityNur wenn Sie wissen, was drinsteckt, können Sie sich sicher sein, dass alles mit rechten Dingen zugeht. Das gilt für Fast Food wie für Software. Um Software abzusichern, muss man wissen, was in ihrem Code steckt. Aus diesem Grund ist eine Software Bill of Material, SBOM oder Software-Stückliste heute unerlässlich. Der SolarWinds-Angriff sowie die Log4j-Schwachstelle…
-
Sicherheitslücke: Attacken auf PostgreSQL-Clients möglich
Ein Patch schließt eine Schadcode-Lücke, die unter bestimmten Voraussetzungen für Clients mit Zugriff auf Postgre-SQL-Datenbanken gefährlich werden kann. First seen on heise.de Jump to article: www.heise.de/news/Sicherheitsluecke-Angreifer-koennen-PostgreSQL-Datenbanken-attackieren-10282360.html
-
Malware auf Steam: Neues Spiel schleust Schadsoftware per Update ein so sollen Betroffene jetzt handeln
First seen on t3n.de Jump to article: t3n.de/news/malware-auf-steam-schadsoftware-per-update-1672891/
-
MSP Update: Turn/River Capital Takes SolarWinds Private in $4.4B Deal
First seen on scworld.com Jump to article: www.scworld.com/news/msp-update-turn-river-capital-takes-solarwinds-private-in-4-4b-deal
-
Security Update: Check Point and Wiz Partner for Better Cloud Security
First seen on scworld.com Jump to article: www.scworld.com/news/security-update-check-point-and-wiz-partner-for-better-cloud-security
-
SonicWall firewalls now under attack: Patch ASAP or risk intrusion via your SSL VPN
Roses are red, violets are blue, CVE-2024-53704 is sweet for a ransomware crew First seen on theregister.com Jump to article: www.theregister.com/2025/02/14/sonicwall_firewalls_under_attack_patch/
-
MSSP Market Update: Cisco Responds to Salt Typhoon Claims
First seen on scworld.com Jump to article: www.scworld.com/news/mssp-market-update-cisco-responds-to-salt-typhoon-claims
-
Microsoft Security Update Notification in February of High-Risk Vulnerabilities in Multiple Products
Overview On February 12, NSFOCUS CERT detected that Microsoft released a security update patch for February, which fixed 63 security issues involving widely used products such as Windows, Microsoft Office, Azure, Apps, and Microsoft Visual Studio, including high-risk vulnerabilities such as privilege escalation and remote code execution. Among the vulnerabilities fixed in Microsoft’s monthly update…The…
-
Progress Telerik und Loadmaster: Updates dichten Sicherheitslecks ab
In Loadmaster und Telerik von Progress hat der Hersteller hochriskante Schwachstellen entdeckt. Updates bessern sie aus. First seen on heise.de Jump to article: www.heise.de/news/Progress-Telerik-und-Loadmaster-stopfen-hochriskante-Sicherheitsluecken-10282137.html
-
Progress Telerik und Loadmaster stopfen hochriskante Sicherheitslücken
In Loadmaster und Telerik von Progress hat der Hersteller hochriskante Schwachstellen entdeckt. Updates bessern sie aus. First seen on heise.de Jump to article: www.heise.de/news/Progress-Telerik-und-Loadmaster-stopfen-hochriskante-Sicherheitsluecken-10282137.html
-
Lexmark warnt vor Sicherheitslücken in Drucker-Software und -Firmware
Lexmark hat Sicherheitslücken in Drucker-Firmware und Begleitsoftware gefunden. Updates stehen bereit, um sie zu schließen. First seen on heise.de Jump to article: www.heise.de/news/Lexmark-warnt-vor-Sicherheitsluecken-in-Drucker-Software-und-Firmware-10282090.html
-
AMD Ryzen Flaw Enables Code Execution Through DLL Hijacking
A security vulnerability hasbeen identified inthe AMD Ryzen Master Utility, a performance-tuningtool for AMDRyzen processors. This flaw, discovered by a security researcher, allows for privilege escalation and arbitrary code execution via DLL hijacking. AMD has confirmed the issue and issued a patch to mitigate the risk. The Vulnerability The AMDRyzen Master Utility provides users with a streamlined interface for overclocking, monitoring system performance,…
-
WinZip Vulnerability Allows Remote Attackers to Execute Arbitrary Code
A newly discovered vulnerability in WinZip, a popular file compression and archiving utility, has raised alarms among cybersecurity experts. Identified as CVE-2025-1240, this critical flaw allows remote attackers to execute arbitrary code on a victim’s system under specific conditions. Users are strongly advised to update their software to mitigate the risk. Key Details of the…
-
Burp Suite Professional / Community 2025.2 Released With New Built-in AI Integration
PortSwigger has announced the release of Burp Suite Professional and Community Edition 2025.2, introducing significant updates that include AI integration into the Montoya API, enhancing the capabilities for building smarter, AI-powered extensions. Bug Fixes and Browser Updates: A notable bug fix corrects the display of source IP addresses for DNS requests over IPv6 in the…
-
MSSP Market Update: Thrive Acquires Secured Network Services
First seen on scworld.com Jump to article: www.scworld.com/news/mssp-market-update-thrive-acquires-secured-network-services
-
Ivanti Issues Updates to Fix Critical Vulnerabilities
First seen on scworld.com Jump to article: www.scworld.com/brief/ivanti-issues-updates-to-fix-critical-vulnerabilities
-
MSSP Market Update: ArmorPoint Teams With SentinelOne for AI SOC Automation
First seen on scworld.com Jump to article: www.scworld.com/news/mssp-market-update-armorpoint-teams-with-sentinelone-for-ai-soc-automation
-
February Patch Tuesday: MSFT Fixes Pair of Zero-Days
First seen on scworld.com Jump to article: www.scworld.com/brief/february-patch-tuesday-msft-fixes-pair-of-zero-days
-
February brings 56 Patch Tuesday fixes from Microsoft
First seen on scworld.com Jump to article: www.scworld.com/news/february-brings-56-patch-tuesday-fixes-from-microsoft
-
Cryptohack Roundup: Sentencing in a $37M Theft Case
Also: Complaint Against Trump, Melania Memecoins. This week’s stories include sentencing in a $37 million theft, $9 million zkLend theft, Tornado Cash developer’s pretrial detention release, guilty plea in SEC hack, an update on a crypto-using murderer, case against Trump memecoin, and a prisoner exchange involving a Russian Bitcoin fraud suspect. First seen on govinfosecurity.com…
-
Technical Analysis of Xloader Versions 6 and 7 – Part 2
Tags: cloud, communications, control, data, encryption, malware, network, reverse-engineering, threat, updateThis is Part 2 of our two-part technical analysis on Xloader versions 6 and 7. For details on how Xloader conceals its critical code and data, go to Part 1.IntroductionIn Part 2 of this blog series, we examine how Xloader obfuscates the command-and-control (C2) code and data to complicate analysis. We will also delve into…

