Mitigation for ProxyNotShell Exchange Vulnerabilities Easily Bypassed

A mitigation proposed by Microsoft and others for the new Exchange Server zero-day vulnerabilities named ProxyNotShell can be easily bypassed, researchers warn.
The security holes, officially tracked as CVE-2022-41040 and CVE-2022-41082, can allow an a… Continue reading Mitigation for ProxyNotShell Exchange Vulnerabilities Easily Bypassed

Microsoft Links Exploitation of Exchange Zero-Days to State-Sponsored Hacker Group

Microsoft has been investigating the attacks exploiting the new Exchange Server zero-day vulnerabilities and believes that a single state-sponsored threat group has been using them in highly targeted attacks.
read more Continue reading Microsoft Links Exploitation of Exchange Zero-Days to State-Sponsored Hacker Group

Details Disclosed After Schneider Electric Patches Critical Flaw Allowing PLC Hacking

Schneider Electric in recent months released patches for its EcoStruxure platform and some Modicon programmable logic controllers (PLCs) to address a critical vulnerability that was disclosed more than a year ago.
read more Continue reading Details Disclosed After Schneider Electric Patches Critical Flaw Allowing PLC Hacking

Hackers Possibly From China Using New Method to Deploy Persistent ESXi Backdoors

Hackers possibly from China have been using a new technique to install persistent backdoors in VMware ESXi hypervisors, giving them significant capabilities while making detection more difficult.
read more Continue reading Hackers Possibly From China Using New Method to Deploy Persistent ESXi Backdoors

GuidePoint Security Launches ICS/OT Security Services

Virginia-based cybersecurity consulting services company GuidePoint Security has announced the launch of new offerings focusing on industrial control systems (ICS) and other operational technology (OT).
read more Continue reading GuidePoint Security Launches ICS/OT Security Services