Recent Security News

  • What to expect when the UK-US Data Bridge comes into force this week

    October 11, 2023 at 05:19AM The UK Extension to the EU-US Data Privacy Framework, also known as the Data Bridge, will allow for the transfer of personal data from the UK to the US starting on October 12. This is necessary due to the UK no longer being a member of the EU. However, the…

    Read More

  • Microsoft Releases October 2023 Patches for 103 Flaws, Including 2 Active Exploits

    October 11, 2023 at 03:12AM Microsoft has released its October 2023 Patch Tuesday updates, addressing 103 flaws, two of which are actively being exploited. Among the vulnerabilities are information disclosure in Microsoft WordPad and privilege escalation in Skype for Business. Microsoft also fixed flaws in Microsoft Message Queuing and Layer 2 Tunneling Protocol. Additionally, Microsoft…

    Read More

  • Microsoft Warns of Nation-State Hackers Exploiting Critical Atlassian Confluence Vulnerability

    October 11, 2023 at 12:30AM Microsoft has identified a critical flaw in Atlassian Confluence Data Center and Server that is being exploited by a nation-state actor called Storm-0062. The vulnerability, known as CVE-2023-22515, allows attackers to create unauthorized administrator accounts. Atlassian has been made aware of the issue and advises users to upgrade to the…

    Read More

  • A Frontline Report of Chinese Threat Actor Tactics and Techniques

    October 11, 2023 at 12:09AM Microsoft analysts and researchers analyze trillions of signals daily to uncover emerging threats and provide timely security insights. They focus on nation-state groups to understand their activities within geopolitical trends. With the shift to remote work due to COVID-19, cybercriminals are exploiting system vulnerabilities and misconfigurations to access sensitive resources…

    Read More

  • It’s 2023 and Microsoft WordPad can be exploited to hijack vulnerable systems

    October 10, 2023 at 07:58PM Microsoft has released over 100 security updates, including fixes for two bugs that are already being actively exploited. One of the vulnerabilities, known as Rapid Reset, is an HTTP/2 weakness that has been used since August to launch distributed denial of service (DDoS) attacks. Microsoft WordPad also has an information…

    Read More