Tag Microsoft

GitHub Addresses Critical Vulnerability in Enterprise Server That Permits Unauthorized Access

GitHub Security Updates Address Critical Vulnerabilities in Enterprise Server GitHub has announced crucial security updates for its Enterprise Server (GHES), responding to multiple vulnerabilities, including a severe flaw that could lead to unauthorized access. The updates aim to enhance user protection, particularly against a vulnerability identified as CVE-2024-9487, which has…

Read MoreGitHub Addresses Critical Vulnerability in Enterprise Server That Permits Unauthorized Access

Critical Vulnerability in Kubernetes Image Builder Poses Root Access Risk to Nodes

A significant security vulnerability has emerged within the Kubernetes Image Builder, posing a risk of unauthorized root access under specific conditions. The flaw, identified as CVE-2024-9486 and rated with a critical CVSS score of 9.8, has been resolved in the latest release, version 0.1.38. The vulnerability was reported by security…

Read MoreCritical Vulnerability in Kubernetes Image Builder Poses Root Access Risk to Nodes

Chinese Hackers Utilize Recent SolarWinds 0-Day in Targeted Attacks

Microsoft has recently identified a series of attacks on SolarWinds’ Serv-U managed file transfer service, which were executed using a now-resolved remote code execution (RCE) vulnerability attributed to a Chinese threat group known as “DEV-0322.” This announcement follows SolarWinds’ emergency patches aimed at countering an exploit that could have allowed…

Read MoreChinese Hackers Utilize Recent SolarWinds 0-Day in Targeted Attacks

US and Global Partners Blame China for Major Microsoft Exchange Cyberattack

The U.S. government, along with critical allies such as the European Union, the United Kingdom, and NATO, has officially linked a substantial cyberattack on Microsoft Exchange email servers to state-sponsored hacking groups associated with China’s Ministry of State Security (MSS). The attack exploited zero-day vulnerabilities in Microsoft Exchange, which were…

Read MoreUS and Global Partners Blame China for Major Microsoft Exchange Cyberattack

Gmail Security Alert: Google Urges Users to Stop Using Passwords

Significant changes are coming to Gmail’s security protocols. dpa/picture alliance via Getty Images Updated on November 3 with additional reports regarding compromised Gmail passwords and updated recommendations for users regarding password management. While numerous claims of widespread Gmail password leaks have circulated recently, Google has reassured users that no immediate…

Read MoreGmail Security Alert: Google Urges Users to Stop Using Passwords

Security Vulnerability in Styra’s OPA Exposes NTLM Hashes to Remote Threats

Security Flaw in Styra’s Open Policy Agent Exposes NTLM Hashes Recently, a significant security vulnerability in Styra’s Open Policy Agent (OPA) has come to light, one that could have potentially exposed New Technology LAN Manager (NTLM) hashes if exploited. Following a responsible disclosure, this flaw has been addressed in a…

Read MoreSecurity Vulnerability in Styra’s OPA Exposes NTLM Hashes to Remote Threats

CISA Alerts on Ongoing Exploitation of Microsoft SharePoint Vulnerability (CVE-2024-38094)

A critical vulnerability affecting Microsoft SharePoint, identified as CVE-2024-38094, has been recently incorporated into the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog. This adds urgency as CISA has flagged the issue, citing active exploitation in the wild. This high-severity vulnerability, which carries a CVSS score…

Read MoreCISA Alerts on Ongoing Exploitation of Microsoft SharePoint Vulnerability (CVE-2024-38094)

Weekly Cybersecurity Update: EY Data Leak, Bind 9 Issues, Chrome Vulnerability, and Aardvark Agent Insights

This week’s cybersecurity highlights draw attention to rising threats stemming from misconfigurations, software vulnerabilities, and sophisticated malware. The incidents outlined below require the immediate focus of IT teams and business executives. ISC has addressed CVE-2025-5470 in BIND 9, a denial-of-service vulnerability impacting versions 9.16.0 to 9.18.26. The vulnerability enables server…

Read MoreWeekly Cybersecurity Update: EY Data Leak, Bind 9 Issues, Chrome Vulnerability, and Aardvark Agent Insights