October Windows Server updates cause Hyper-V VM boot issues

October 17, 2023 at 08:37AM Hyper-V hosts running Windows Server 2019 and Windows Server 2022 are experiencing issues with virtual machines (VMs) failing to boot after installing certain Patch Tuesday updates. Uninstalling the problematic updates resolves the issue, and Microsoft has yet to acknowledge it. In the past, the company released emergency updates to fix … Read more

NSA Publishes ICS/OT Intrusion Detection Signatures and Analytics

October 17, 2023 at 07:12AM The National Security Agency has released a repository called Elitewolf on GitHub, which contains intrusion detection signatures and analytics for hunting malicious activity in industrial control systems and operational technology environments. The release is in response to increased cyber activity targeting critical infrastructure and aims to help organizations implement continuous … Read more

US Gov Expects Widespread Exploitation of Atlassian Confluence Vulnerability

October 17, 2023 at 07:12AM The US cybersecurity agency CISA, together with the FBI and MS-ISAC, has issued a warning about a zero-day vulnerability in Atlassian Confluence Data Center and Server. Tracked as CVE-2023-22515, the flaw has been exploited by a nation-state threat actor since September 14. It allows unauthorized access, creation of administrative accounts, … Read more

Cisco Devices Hacked via IOS XE Zero-Day Vulnerability

October 17, 2023 at 07:12AM Cisco has issued a warning about a zero-day vulnerability, CVE-2023-20198, affecting its IOS XE software. The vulnerability allows remote attackers to gain privileged access and take control of devices, potentially modifying network routing rules and exfiltrating data. Cisco has observed active exploitation of the vulnerability and is working on a … Read more

WordPress Websites Hacked via Royal Elementor Plugin Zero-Day

October 17, 2023 at 05:54AM Researchers have discovered a critical vulnerability in the Royal Elementor Addons and Templates WordPress plugin that has been exploited for over a month. The bug allows attackers to upload arbitrary files to vulnerable sites, leading to remote code execution. The vulnerability has been targeted in over 46,000 attacks, with most … Read more

British boffins say aircraft could fly on trash, cutting pollution debt by 80%

October 17, 2023 at 03:35AM Researchers from the National Centre for Atmospheric Science and the University of Manchester have found that sustainable aviation fuels (SAFs) have the potential to reduce emissions by up to 80%. Blends of traditional jet fuel and SAF were tested, showing a significant reduction in emissions. SAFs can be made from … Read more

CERT-UA Reports: 11 Ukrainian Telecom Providers Hit by Cyberattacks

October 17, 2023 at 02:09AM Between May and September 2023, at least 11 telecommunication service providers in Ukraine were targeted by threat actors. The attacks, carried out under the name UAC-0165, caused service interruptions for customers. The attackers used reconnaissance and exploitation techniques from previously compromised servers, employing specialized programs for credential theft and remote … Read more

Warning: Unpatched Cisco Zero-Day Vulnerability Actively Targeted in the Wild

October 17, 2023 at 01:03AM Cisco has issued a warning about a critical security flaw in its IOS XE software that is being actively exploited. The vulnerability, assigned as CVE-2023-20198, allows remote attackers to create an account with high-level access and gain control of affected systems. The flaw only affects enterprise networking gear with the … Read more

Will you meet the directive?

October 16, 2023 at 11:11PM Upcoming changes to cyber security regulations in the US and Europe require organizations to focus on compliance. The SEC mandate in the US will enforce reporting of cyber incidents and the production of a Cyber Report by December 18. The DoD directive specifies that anyone working within the DoD must … Read more

Email Security Best Practices for Phishing Prevention

October 16, 2023 at 10:52PM Phishing attacks have been on the rise, with a 29% increase in detections reported by Trend Micro for 2022. These attacks are becoming more sophisticated, including tactics like spear phishing, whaling, and QR code phishing. Organizations need to implement a layered approach to email security, including capabilities like email gateway … Read more