โŒ

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

The hits for September just keep on coming

23 September 2026 at 04:00
Although the fix for the File History bug has been fixed in a preview update for Windows 11, there is no such advanced fix for those of you on Windows 10. Your choice is to uninstall the September updates if you happened to inadvertently install them, or to just wait out the month with a [โ€ฆ]

Should we patch faster?

14 September 2026 at 03:45
ISSUE 23.37 โ€ข 2026-09-14 PATCH WATCH By Susan Bradley Is AI pushing us to patch faster? Recently, I sat down with Richard Campbell of the RunAsRadio podcast to talk about patching, security, and whether we should patch faster just because of AI. I made the point that vulnerability counts do not equate to exploitation. The [โ€ฆ]

Silent Patches Donโ€™t Stop Attackers โ€“ They Blind Defenders

25 August 2026 at 06:00

Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk.

The post Silent Patches Donโ€™t Stop Attackers โ€“ They Blind Defenders appeared first on SecurityWeek.

Microsoft Patches Exploited Entra ID Vulnerability

21 August 2026 at 04:12

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

The post Microsoft Patches Exploited Entra ID Vulnerability appeared first on SecurityWeek.

Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it

21 August 2026 at 12:29
CISA has ordered US federal agencies to patch two exploited flaws in TrueConf, a Russian-built video conferencing platform, after compromised servers were caught handing malware to unsuspecting meeting participants. The US cybersecurity agency on Thursday added CVE-2026-72529 and CVE-2026-72530 to its Known Exploited Vulnerabilities catalog, saying both have been used in real-world attacks. What CISA doesn't say is who is being attacked, or where. The only publicly documented attacks exploiting these two bugs so far come from Kaspersky, which linked them to Head Mare, a pro-Ukrainian hacktivist group that has repeatedly gone after Russian organizations. Its latest campaign targeted Russian companies across industries including transport, energy, electronics, IT, and software development. CISA doesn't say whether it added the flaws to KEV because of those attacks or because it has evidence of exploitation elsewhere, potentially including against organizations in the US. That question is particularly interesting given what TrueConf is and who uses it. TrueConf is a Moscow-based maker of video conferencing software that offers an on-premises alternative to cloud services such as Zoom and Microsoft Teams. Organizations can run TrueConf Server on their own infrastructure, including in private networks, giving them control over where their calls and associated data go. While the company's roots and much of its customer base are Russian, TrueConf has users worldwide. It says it has users in its portfolio that include Switzerlandโ€™s Department of Justice and Home Affairs, Istanbul Airport, and a news org, which The Reg has contacted to confirm. Most of the customer success stories are dated before 2022. Used together, the two bugs flagged by CISA can give an attacker control of the underlying server. According to Kaspersky, an unauthenticated attacker with network access to TCP port 4307, which TrueConf documentation says is open by default, can exploit the first flaw to run a malicious script. The second flaw lets the attacker break out of the isolated environment where the script runs and execute arbitrary code on the underlying server. Kaspersky says Head Mare used that access to plant a web shell, move through victims' infrastructure, and gain privileged access to the TrueConf database. From there, the attackers replaced the legitimate TrueConf Windows client installer on compromised servers with a trojanized version carrying the PhantomCore backdoor. Kaspersky warns that this creates a risk beyond organizations actually running vulnerable TrueConf servers. Employees joining conferences hosted by suppliers or other third parties could potentially download a compromised client from someone else's hacked infrastructure. The researcher says the flaws affect TrueConf Server releases going back to 2022. TrueConf shipped fixes in versions 5.3.9, 5.4.9 and 5.5.5 on June 18, warning customers that skipping the update could leave their conferencing systems exposed to attacks over the public internet. That doesn't mean every TrueConf box is sitting on the internet waiting to be popped. Exploitation requires network access to the vulnerable service, so a server confined to an internal network would not be directly reachable from outside unless an attacker had another route in. Federal agencies have until September 10 to patch the flaws. Other TrueConf admins can take their time, as long as they're comfortable with a conferencing server potentially moonlighting as a malware distribution point. ยฎ

Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update

27 July 2026 at 09:45
Not content with broken Windows updates, Microsoft has disclosed two problems with Defender for Endpoint on Linux โ€“ one that could disable the security service after a reboot, and another that prevents updates on FIPS-enabled Red Hat Enterprise Linux 8 and 9. The more serious problem affected versions 101.26042.0000 through 101.26042.0009 across all supported Linux operating systems. After an upgrade or reinstall followed by a reboot, "the Defender service might be disabled on some devices," according to Microsoft. "If you use Defender for Servers (Plan 1 or 2) with Defender for Cloud and have the MDE [Microsoft Defender Endpoint] integration enabled, automatic updates for the MDE.Linux extension are enabled by default, which means your machines could have received an affected version automatically," it explained. "If an affected version was installed, the issue might impact active protection on rebooted devices until remediation steps are taken." Microsoft did not specify what caused Defender to become disabled, but anything that could knock out endpoint protection will give administrators sweaty palms. A separate problem affected RHEL 8 and 9 systems running in FIPS mode: the 101.26042.x update could fail to install, leaving devices on their previous version. FIPS refers to US Federal Information Processing Standards, which in this context impose requirements on the cryptography used by government and other regulated systems. Although Microsoft's alert did not mention an available update, its release notes direct users affected by the disabled-service bug to build 101.26042.0011. The separate FIPS installation problem is fixed in version 101.26052.0011 and later. Microsoft Defender for Endpoint on Linux protects server workloads on-premises and in the cloud. According to Microsoft, "it helps you prevent, detect, investigate, and respond to advanced threats with unified visibility through the Microsoft Defender portal." Other endpoint security platforms are available, but where an organization has gone all-in with Microsoft, the unified management offered by Defender for Endpoint on Linux can be difficult to resist. Microsoft has an unfortunate habit of shipping broken updates for its flagship operating system, Windows. An update that breaks software specifically designed to protect a device takes things to another level, particularly given the relentless rise in attacks and the need to both fend them off and monitor activity. Hence the appeal of unified visibility through the Microsoft Defender portal. However, an update that could leave Defender disabled after a reboot โ€“ while also refusing to install on some security-hardened systems โ€“ is less than ideal. ยฎ

Year-long Russian attacks infect users as soon as they look at an email

23 July 2026 at 12:47
Kremlin cyber goons have been breaking into government and commercial networks for at least a year by exploiting a Zimbra bug with a novel twist on Russiaโ€™s usual phishing expeditions: this attack occurs as soon as the victim looks at an email, with no need to even click on a link or open a file. These attacks have been ongoing since July 2025, according to a whopping 27 US, UK, and other international government agencies, which attribute the intrusions to a group they track as Laundry Bear, aka Void Blizzard. โ€œLaundry Bearโ€™s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data,โ€ according to the joint security alert. The Russiansโ€™ latest campaign targets CVE-2025-66376, a cross-site scripting (XSS) vulnerability in the Zimbra web-based email and collaboration suite that was patched in November 2025 โ€“ but Moscow's attackers began exploiting it long before then. This type of vulnerability allows attackers to inject malicious JavaScript into web pages viewed by the victim. In this case, the phishing bears abused the security hole in the Zimbra Collaboration Suite by sending malware-laden HTML email messages to target Western organizations. Targeted orgs include those in the defense industrial base, federal and local governments, education, energy, law enforcement, media, non-governmental organizations, and technology sectors. Some of the email addresses used in this campaign include ivanka.zurabishvili@proton[.]me, zmul1@buildandconsulting[.]com, garrysmithme@pinmx[.]net, and hostingclient@pinmx[.]net, weโ€™re told. The attack doesnโ€™t require any user interaction other than viewing the malicious email, and once that happens, the attackers get to work exfiltrating a ton of data. This includes the victimsโ€™ last 90 days of email communications, email addresses and passwords, the organizationsโ€™ email directories such as global address lists, two-factor authentication tokens, and newly created application passcodes. Then the attackers use these stolen credentials to maintain access to the victimsโ€™ email, modifying account preferences and collecting authentication information. Laundry Bear stores the stolen goods on an unattributable virtual private server (VPS) running its custom โ€œFlowerbedโ€ collection framework. Flowerbed is a Python project that uses Docker for containerization. โ€œThe simplistic Flowerbed codebase has indications that artificial intelligence (AI) played a role in its development,โ€ the government agencies noted. The 31-page security alert includes an extensive indicators of compromise (IOC) section, which organizations should review to identify individuals compromised by the campaign. Also, the agencies recommend minimizing employeesโ€™ use of the ZCS webmail client until their organizations update to a patched version that is not vulnerable to CVE-2025-66376. ยฎ

โŒ
โŒ