Tag Microsoft

Microsoft Releases Fixes for 73 Vulnerabilities, Including Two Windows Zero-Day Exploits

In its February 2024 Patch Tuesday updates, Microsoft has issued fixes for 73 security vulnerabilities across its software ecosystem, including two zero-day flaws currently under active exploitation. Among these vulnerabilities, five have been categorized as Critical and 65 as Important, while three have a Moderate severity rating. This release also…

Read MoreMicrosoft Releases Fixes for 73 Vulnerabilities, Including Two Windows Zero-Day Exploits

Severe Exchange Server Vulnerability (CVE-2024-21410) Currently Under Active Attack

On Wednesday, Microsoft disclosed that a severe security vulnerability, identified as CVE-2024-21410, within its Exchange Server software has been actively exploited in the wild. This revelation came shortly after the tech giant released fixes during its monthly Patch Tuesday updates. With a CVSS score of 9.8, the flaw represents a…

Read MoreSevere Exchange Server Vulnerability (CVE-2024-21410) Currently Under Active Attack

FBI, CISA, and NSA Hold Russia Responsible for SolarWinds Cyber Attack

On Tuesday, officials from the U.S. government formally accused the Russian government of orchestrating the significant SolarWinds supply chain compromise unveiled last month. This allegation came as part of a broader assessment conducted by multiple agencies, including the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency…

Read MoreFBI, CISA, and NSA Hold Russia Responsible for SolarWinds Cyber Attack

Hackers Breach Microsoft Support Agent to Access Outlook Email Accounts

A recent data breach has compromised accounts within Microsoft’s Outlook email service, raising significant concerns for users. The incident was confirmed by Microsoft and reported by The Hacker News. Hackers gained unauthorized access to a customer support portal, allowing them to view certain account-related information for a subset of Outlook…

Read MoreHackers Breach Microsoft Support Agent to Access Outlook Email Accounts

Kaiser Permanente Agrees to Pay Up to $47.5M in Web Tracker Settlement

Data Privacy, Data Security, Fraud Management & Cybercrime Class Action Lawsuit Claims Web Trackers Misused Patient Data Marianne Kolbasuk McGee (HealthInfoSec) • December 2, 2025 Kaiser Permanente has agreed to pay up to $47.5 million to resolve class action litigation related to its website tracking activities. Kaiser Permanente has reached…

Read MoreKaiser Permanente Agrees to Pay Up to $47.5M in Web Tracker Settlement

Lazarus Group Exploits Windows Kernel Vulnerability as Zero-Day in Recent Attacks

Recent cybersecurity intelligence has revealed that the infamous Lazarus Group has exploited a newly patched privilege escalation vulnerability in the Windows Kernel as a zero-day attack. This exploit allows the adversaries to gain kernel-level access, enabling them to disable crucial security software on affected systems. The vulnerability, identified as CVE-2024-21338…

Read MoreLazarus Group Exploits Windows Kernel Vulnerability as Zero-Day in Recent Attacks

How the SolarWinds Hackers Managed to Remain Under the Radar for So Long

On Wednesday, Microsoft provided additional insights into the methodologies employed by the attackers behind the SolarWinds breach, one of the most intricate cybersecurity incidents in recent history. This deeper understanding is crucial as cybersecurity firms endeavor to gain a more definitive grasp of the attack’s sophisticated nature. Describing the attackers…

Read MoreHow the SolarWinds Hackers Managed to Remain Under the Radar for So Long