Tag Microsoft

Microsoft Tackles Significant Power Platform Vulnerability Following Delays and Feedback

Microsoft Addresses Security Flaw in Power Platform Amid Criticism for Delayed Response On Friday, Microsoft announced it has remedied a significant security vulnerability affecting its Power Platform, although it faced backlash for not acting more swiftly. This flaw posed a risk of unauthorized access to Custom Code functions utilized in…

Read MoreMicrosoft Tackles Significant Power Platform Vulnerability Following Delays and Feedback

CISA Includes Microsoft .NET Vulnerability in KEV Catalog Due to Ongoing Exploits

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently included a newly patched vulnerability affecting Microsoft’s .NET and Visual Studio products in its Known Exploited Vulnerabilities (KEV) catalog. This decision comes in response to evidence indicating that the flaw is actively being exploited in the wild. This vulnerability, tracked…

Read MoreCISA Includes Microsoft .NET Vulnerability in KEV Catalog Due to Ongoing Exploits

16 New CODESYS SDK Vulnerabilities Put OT Environments at Risk of Remote Attacks

A recent disclosure has revealed a series of 16 high-severity security vulnerabilities in the CODESYS V3 software development kit (SDK). This suite of flaws could potentially lead to remote code execution and denial-of-service conditions, thereby posing significant risks to operational technology (OT) sectors. The vulnerabilities, tracked from CVE-2022-47378 to CVE-2022-47393…

Read More16 New CODESYS SDK Vulnerabilities Put OT Environments at Risk of Remote Attacks

Microsoft Uncovers Increased Russian Cyber Attacks Before Mid-Term Elections

Microsoft Discovers New Russian Hacking Attempts Ahead of U.S. Midterm Elections In a recent revelation, Microsoft announced the discovery of new hacking efforts attributed to the Russian hacking group APT28, also known as Strontium or Fancy Bear. These attempts, aimed at conservative think tanks and the U.S. Senate, surfaced amid…

Read MoreMicrosoft Uncovers Increased Russian Cyber Attacks Before Mid-Term Elections

Microsoft Takes Legal Action Against U.S. Government Over Unconstitutional Secret Data Requests

In a significant legal move, Microsoft has initiated a lawsuit against the Department of Justice (DoJ) to contest a gag order that prohibits technology companies from notifying their customers when their cloud-based data is accessed by government authorities. This lawsuit arises from concerns regarding the implications of the Electronic Communications…

Read MoreMicrosoft Takes Legal Action Against U.S. Government Over Unconstitutional Secret Data Requests

Mandiant Unveils Rainbow Table Capable of Breaking Weak Admin Passwords in Just 12 Hours

Microsoft’s NTLMv1 protocol, introduced in the 1980s alongside OS/2, has long been known for its vulnerabilities. Significant research, notably by cryptanalyst Bruce Schneier and Mudge in 1999, highlighted critical weaknesses in NTLMv1’s security architecture. This became alarmingly clear during the 2012 Defcon 20 conference, where researchers unveiled a toolkit that…

Read MoreMandiant Unveils Rainbow Table Capable of Breaking Weak Admin Passwords in Just 12 Hours

Kaiser Permanente Settles Data Breach for $46 Million—Here’s How to Submit Your Claim

Kaiser Permanente to Disburse Payments Following Data Sharing Settlement Kaiser Permanente, a prominent player in the U.S. healthcare landscape, is preparing to issue payments to customers affected by an incident involving the unauthorized sharing of personal data and health information with third-party companies. This move comes in the wake of…

Read MoreKaiser Permanente Settles Data Breach for $46 Million—Here’s How to Submit Your Claim