Microsoft Outlook December updates trigger ICS security alerts

February 5, 2024 at 05:07PM Microsoft is investigating an issue where Outlook triggers security alerts when opening .ICS calendar files post-December 2023 Patch Tuesday Office updates. Users are affected by warning dialog boxes, and the company is working on a fix for this bug and related security warning due to CVE-2023-35636. A temporary registry key … Read more

Researchers Uncover How Outlook Vulnerability Could Leak Your NTLM Passwords

January 29, 2024 at 09:17AM A Microsoft Outlook security flaw, CVE-2023-35636, could expose NTLM v2 hashed passwords through a specially crafted file, recently patched by Microsoft. Attackers could exploit it via email or web, convincing users to open the file or click a link. Varonis researcher Dolev Taler reported the bug, highlighting potential leakage vulnerabilities. … Read more

Windows 10 KB5034203 preview update adds EU DMA compliance

January 23, 2024 at 02:14PM Microsoft released the January 2024 preview update for Windows 10, version 22H2, adding Digital Markets Act (DMA) compliance for European users, allowing uninstallation of all apps by March 6. KB5034203 is an optional update for testing fixes and improvements. The update also addresses specific issues and can be manually installed … Read more

High-Severity Vulnerability Patched in Splunk Enterprise

January 23, 2024 at 09:12AM Splunk announced patches for multiple vulnerabilities, including a high-severity bug (CVE-2024-23678) affecting Splunk Enterprise on Windows, allowing unsafe deserialization leading to potential denial of service, application logic abuse, or code execution. Other medium-severity vulnerabilities and flaws in third-party packages were also resolved in versions 9.0.8 and 9.1.3. Splunk recommends upgrading … Read more

Exploit for under-siege SharePoint vuln reportedly in hands of ransomware crew

January 12, 2024 at 02:49PM Security experts have warned about a ransomware group exploiting a critical Microsoft SharePoint vulnerability, CVE-2023-29357, which can lead to remote code execution. This vulnerability was added to the US’s must-patch list, giving agencies three weeks to patch it. The exploit chain has been a concern, and patching is crucial to … Read more

Act Now: CISA Flags Active Exploitation of Microsoft SharePoint Vulnerability

January 12, 2024 at 02:03AM The U.S. CISA added a critical security vulnerability in Microsoft SharePoint Server to its catalog, noting evidence of active exploitation and the availability of patches from Microsoft. Security researcher Nguyễn Tiến Giang demonstrated an exploit at a hacking contest, with federal agencies advised to apply the patches by January 31, … Read more

Microsoft’s January 2024 Windows Update Patches 48 New Vulnerabilities

January 10, 2024 at 01:06AM In January 2024, Microsoft addressed 48 security flaws in its software, with 2 rated Critical and 46 Important. No evidence indicates active attacks, marking the second consecutive Patch Tuesday with no zero-days. This includes fixes for vulnerabilities in the Chromium-based Edge browser. Other vendors have also released security updates to … Read more

New year, new bugs in Windows, Adobe, Android, more to be fixed

January 9, 2024 at 05:35PM Microsoft’s recent Patch Tuesday brought 49 Windows security updates and four high-severity Chrome flaws for Edge. Although there’s no active exploitation, two critical CVEs are listed as “exploitation more likely.” Adobe and SAP also released patches for their products, while Google’s Android Security Bulletin addressed 59 CVEs. No prior exploits … Read more

Windows 10 KB5034122 update released with fix for shut down bug

January 9, 2024 at 02:55PM Microsoft released KB5034122 cumulative update for Windows 10 21H2 and 22H2, containing January 2024 security updates. It’s mandatory, with limited fixes due to the holiday season. After manual installation or ‘Check for Updates,’ it’ll automatically start but can be scheduled for restart. New update for Win 10, addressing issues and … Read more

Microsoft January 2024 Patch Tuesday fixes 49 flaws, 12 RCE bugs

January 9, 2024 at 02:11PM Microsoft’s January 2024 Patch Tuesday addresses 49 flaws and 12 remote code execution vulnerabilities. Notably, a Windows Kerberos Security Feature Bypass and a Hyper-V RCE were classified as critical. Microsoft also addressed an Office Remote Code Execution Vulnerability and other flaws. Other vendors released updates, including .NET, Azure, Microsoft Edge, … Read more