❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

SAP Patches Critical Extended Passport Processing Vulnerability

8 September 2026 at 10:55

Affecting the SAP kernel code, the flaw allows unauthenticated, remote attackers to run arbitrary commands, recover secrets, and modify data.

The post SAP Patches Critical Extended Passport Processing Vulnerability appeared first on SecurityWeek.

How to find out what’s using your RAM

7 September 2026 at 03:44
WINDOWS 11 By Mary Branscombe Task Manager isn’t the only option for tracking down memory usage. Other tools give you more details. The next time your PC feels slow, you could just assume it’s due to too many open tabs in your browser and look at Task Manager to see if you’re right. But that […]

Fixing the IP address of a networked printer

By: Ben Myers
24 August 2026 at 03:42
BEN’S WORKSHOP By Ben Myers The power goes out where you live. When it comes back on, you can no longer use your printer. Then what? In the area where I live, we lose electrical power frequently. Many people cannot afford, do not have room for, or will not put up with a large uninterruptable […]

Separating that network

3 August 2026 at 03:42
ON SECURITY By Susan Bradley OpenAI’s recent attack on another company’s cloud instances reminds me that sometimes we forget the basics. As we understand the situation at the moment, OpenAI’s test platform was meant to be isolated and not connected to the Internet. But because it needed to download certain items, it was given read-only […]

Latest Updates to Wiretap Litigation

By: Dissent
1 August 2026 at 09:42
Jill Canfield and Tyler R. Bridegan of Womble Bond Dickinson write: The California Invasion of Privacy Act (CIPA), a 1967 penal code law originally designed to protect the privacy rights of California residents, has become the basis for a recent surge in demands and lawsuits. Plaintiffs’ attorneys are suing companies across the country for using...

Microsoft discloses β€˜the mother of all’ vulnerability loads, tripling June’s previous record

14 July 2026 at 16:05

Microsoft’s monthly Patch TuesdayΒ security program reached an unrivaled pinnacle this month, as the vendor addressed 622 vulnerabilities across its suite of business products and systems.Β 

β€œThe bug apocalypse has finally descended upon us,” Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, wrote in a blog post Tuesday.

β€œThe mother of all releases. To call this record-breaking is an understatement,” he added. β€œThe CVE count year-to-date exceeds all other years’ totals.”

The startling increase in vulnerabilities reflects a compounding effect taking root across software as artificial intelligence plays a growing role in discovering and developing patches for defects lurking in error-riddled applications.Β 

Microsoft’s June Patch Tuesday update broke the previous all-time record with 206 vulnerabilities.

The company last week warned forewarned customers and defenders that a flood of defects would be uncovered as it applies its multi-model agentic scanning harness (MDASH) to discover and address vulnerabilities at greater speed and scale.

The monthly exponential rise in Microsoft vulnerabilities already puts the vendor on pace to break a full-year record, ending 2026 with the largest annual collection of defects, beating the previous record of 1,245 CVEs in 2020, Satnam Narang, senior staff research engineer at Tenable, said in an email.Β 

β€œIt’s probable that we will not only exceed 2,000 CVEs in a calendar year, but potentially over 3,000 CVEs this year or more,” he added.

β€œThe volume is striking, but it reflects how good these tools have become at finding bugs, not how many of those bugs actually pose a risk to organizations,” Narang said.

Microsoft disclosed two actively exploited zero-day vulnerabilities β€” CVE-2026-56155 and CVE-2026-56164, privilege escalation defects in Active Directory Federation Services and Microsoft SharePoint Server, respectively.Β 

The monthly batch of patches included 416 defects in Windows, 82 in Office and 46 in Microsoft Edge. More than 1 in 10 vulnerabilities the vendor disclosed β€” 63 total β€” were rated as critical.

β€œThe products covered this month are also astonishing,” Childs said. β€œJust about everything you’ve ever heard of is getting patched.”

The full list of vulnerabilities addressed this month is available in Microsoft’s Security Response Center.

SAP also addressed a fresh assortment of vulnerabilities Tuesday, including critical defects CVE-2026-44747 in SAP NetWeaver Application Server and CVE-2026-27690 in SAP Approuter.

The post Microsoft discloses β€˜the mother of all’ vulnerability loads, tripling June’s previous record appeared first on CyberScoop.

Nmap Cheatsheet

By: BHIS
6 August 2025 at 11:00

Nmap is a powerful open-source tool commonly used by system/network administrators and security professionals to perform network discovery, security auditing, and basic vulnerability assessment.

The post Nmap Cheatsheet appeared first on Black Hills Information Security, Inc..

Vulnerability Scanning with NmapΒ 

By: BHIS
16 July 2025 at 10:00

Nmap, also known as Network Mapper, is a commonly used network scanning tool. As penetration testers, Nmap is a tool we use daily that is indispensable for verifying configurations and identifying potential vulnerabilities.

The post Vulnerability Scanning with NmapΒ  appeared first on Black Hills Information Security, Inc..

Messing With Web Attackers With SpiderTrap (Cyber Deception)

By: BHIS
30 March 2020 at 08:11

Hello and welcome! My name is John Strand. In this video, we’re going to be talking about using SpiderTrap to entrap and ensnare any web application pentesters or hackers that […]

The post Messing With Web Attackers With SpiderTrap (Cyber Deception) appeared first on Black Hills Information Security, Inc..

Tap Into Your Valuable DNS Data

By: BHIS
3 June 2019 at 11:21

Joff Thyer // The Domain Name System (DNS) is the single most important protocol on the Internet. The distributed architecture of DNS name servers and resolvers has resulted in a […]

The post Tap Into Your Valuable DNS Data appeared first on Black Hills Information Security, Inc..

WEBCAST: Blue Team-Apalooza

By: BHIS
15 November 2018 at 11:57

Kent Ickler & Jordan Drysdale // Preface We had a sysadmin and security professional β€œAA” meeting on November 8, 2018. We met and discussed things that seem to be painfully […]

The post WEBCAST: Blue Team-Apalooza appeared first on Black Hills Information Security, Inc..

WEBCAST: There and Back Again – A Pathfinder’s Tale

By: BHIS
19 December 2017 at 11:22

Matthew Toussain// Portswigger’s Burpsuite has become the tool of choice for web application penetration testers. OWASP’s Zed Attack Proxy (ZAP) not only fights in the same weight class but also […]

The post WEBCAST: There and Back Again – A Pathfinder’s Tale appeared first on Black Hills Information Security, Inc..

AppleTV & nmap -sV

By: BHIS
11 October 2016 at 10:21

BBKing // So I’m working the other day, and my wife asks me why the TV is on. I don’t know. I didn’t turn it on. But it’s near my […]

The post AppleTV & nmap -sV appeared first on Black Hills Information Security, Inc..

Are you Snoopable?!

By: BHIS
8 June 2016 at 11:05

Rick Wisser // All right, you’ve taken all the precautions related to your network. You have lockout controls in place, you use awesome password policies (20 characters with uppercase, lowercase, […]

The post Are you Snoopable?! appeared first on Black Hills Information Security, Inc..

❌
❌