The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Microsoft Word documents exploiting known remote code execution flaws are being used as phishing lures to drop malware calledLokiBoton compromised systems."Lok…
The July 2023 Patch Tuesday update bundle patched at least six different actively-exploited vulnerabilities across…Microsoft July Patch Tuesday Fixed Six Zero-…
Microsoft on Tuesday released updates to address a totalof 130 new security flawsspanning its software, including six zero-day flaws that it said have been act…
Microsoft on Tuesday released updates to address a totalof 132 new security flawsspanning its software, including six zero-day flaws that it said have been act…
Two "dangerous" security vulnerabilities have been disclosed in Microsoft Azure Bastion and Azure Container Registry that could have been exploited to carry ou…
Microsoft has shared details of a now-patched flaw in Apple macOS that could be abused by threat actors with root access to bypass security enforcements and pe…
The infamous Lazarus Group actor has been targeting vulnerable versions of Microsoft Internet Information Services (IIS) servers as an initial breach route to …
Iranian nation-state groups have now joined financially motivated actors in actively exploiting a critical flaw in PaperCut print management software, Microsof…
Three new security flaws have been disclosed in Microsoft Azure API Management service that could be abused by malicious actors to gain access to sensitive inf…
Microsoft has confirmed that theactive exploitation of PaperCut serversis linked to attacks that are designed to deliver Cl0p and LockBit ransomware families.T…
It's the second Tuesday of the month, and Microsoft has released another set of security updates to fixa total of 97 flawsimpacting its software, one of which …
Microsoft has patched a misconfiguration issue impacting the Azure Active Directory (AAD) identity and access management service that exposed several "high-imp…
Details have emerged about a now-patched vulnerability in Azure Service Fabric Explorer (SFX) that could lead to unauthenticated remote code execution.Tracked …
Microsoft on Friday shared guidance to help customers discover indicators of compromise (IoCs) associated with a recently patched Outlook vulnerability.Tracked…
Microsoft's Patch Tuesday update for March 2023 is rolling out with remediations for a set of80 security flaws, two of which have come under active exploitatio…
Microsoft on Tuesday releasedsecurity updatesto address 75 flaws spanning its product portfolio, three of which have come under active exploitation in the wild…
A new critical remote code execution (RCE) flaw discovered impacting multiple services related to Microsoft Azure could be exploited by a malicious actor to co…
A new critical remote code execution (RCE) flaw discovered impacting multiple services related to Microsoft Azure could be exploited by a malicious actor to co…
Four different Microsoft Azure services have been found vulnerable to server-side request forgery (SSRF) attacks that could be exploited to gain unauthorized a…
Microsoft has disclosed details of a now-patched security flaw in Apple macOS that could be exploited by an attacker to get around security protections imposed…
Microsoft has revised the severity of a security vulnerability it originallypatched in September 2022, upgrading it to "Critical" after it emerged that it coul…
Tech giant Microsoft released its last set of monthly security updates for 2022 withfixes for 49 vulnerabilitiesacross its software products.Of the 49 bugs, si…
The Redmond giant has rolled out its monthly scheduled updates for users, addressing multiple vulnerabilities.…Microsoft July Patch Tuesday Arrives With 84 Bug…
Microsoft says the Sysrv botnet is now exploiting vulnerabilities in the Spring Framework and WordPress to ensnare and deploy cryptomining malware on vulnerabl…