Patch Tuesday – March 2022

Microsoft released 71 fixes this month, 3 of which are rated Critical and 68 Important. While three are publicly known at the time they were released, none are believed to be in active use by hackers. Windows and Windows Server Microsoft released an update for CVE-2022-21990, which is a Remote Desktop Client (RDP) remote code […] Continue reading Patch Tuesday – March 2022

Patch Tuesday January 2022 – Wormable Bug in Windows and a Critical Bug in Exchange Server Get Fixes

Microsoft patches a wormable bug in http.sys in Windows and Windows Server. There are also fixes for three remote code execution vulnerabilities in Exchange Server. And Adobe releases fixes for 26 flaws in Acrobat and Reader. So, let’s get started! Windows and Windows Server This month there are fixes for six zero-days in Windows and […] Continue reading Patch Tuesday January 2022 – Wormable Bug in Windows and a Critical Bug in Exchange Server Get Fixes

‘Wormable’ Flaw Leads January 2022 Patch Tuesday

Microsoft today released updates to plug nearly 120 security holes in Windows and supported software. Six of the vulnerabilities were publicly detailed already, potentially giving attackers a head start in figuring out how to exploit them in unpatched systems. More concerning, Microsoft warns that one of the flaws fixed this month is “wormable,” meaning no human interaction would be required for an attack to spread from one vulnerable Windows box to another. Continue reading ‘Wormable’ Flaw Leads January 2022 Patch Tuesday

This Week in IT: Can Intel 12th Gen Mobile CPUs Compete with Apple’s M1 Chip?

  In this edition of This Week in IT, at CES AMD releases its Ryzen 6000 series CPUs with Microsoft’s Pluton security chip and Intel announces its 12th generation hybrid architecture CPUs for mobile devices, but can they compete with the Apple M1 chip? Microsoft releases a hangover cure for Exchange Server administrators to solve […] Continue reading This Week in IT: Can Intel 12th Gen Mobile CPUs Compete with Apple’s M1 Chip?

Microsoft Delivers Emergency Fix For Exchange Y2K22 Bug

Microsoft has released an official fix for the “Y2K22” bug that was previously preventing on-premise Exchange servers from sending emails. This issue started at midnight on January 1st, 2022, and it was causing emails to get stuck in transport queues due to a date check failure in the FIP-FS anti-malware scanning engine. The Microsoft Exchange Y2K22 […] Continue reading Microsoft Delivers Emergency Fix For Exchange Y2K22 Bug

Patch Tuesday November 2021 – Microsoft Patches Windows RDP Zero-Day and Exchange RCE

Patch Tuesday in November 2021 sees Microsoft release patches to address 55 CVEs, including fixes for 6 zero-day bugs. There are updates for products including Windows, Windows Server, Office, Exchange Server, Active Directory, Microsoft Dynamics, Hyper-V, and Azure Real Time Operating System (RTOS), which is ThreadX RTOS, an embedded real-time operating system that Microsoft purchased […] Continue reading Patch Tuesday November 2021 – Microsoft Patches Windows RDP Zero-Day and Exchange RCE

Patch Tuesday October 2021 – Microsoft Fixes Windows Kernel Zero-Day and Critical Bug in Exchange Server

This month’s Patch Tuesday for includes a cumulative update (CU) for Windows 11, which was made generally available October 4th. In total Microsoft released patches addressing 71 CVEs in Windows, Edge, Exchange Server, .NET Core, SharePoint Server, and many other products. Two of the CVEs patched this month are rated Critical, and 68 Important. And […] Continue reading Patch Tuesday October 2021 – Microsoft Fixes Windows Kernel Zero-Day and Critical Bug in Exchange Server

How to Mitigate Microsoft Exchange Autodiscover Protocol Flaw That Leaks User Credentials

In this article, I explain how the recently discovered flaw in the Exchange Server Autodiscover protocol can leak user credentials. And how to mitigate the issue in your environment. Microsoft Exchange Server Autodiscover protocol leaks thousands of user credentials Researchers at security company Guardicore have released details of a security issue in the Autodiscover protocol […] Continue reading How to Mitigate Microsoft Exchange Autodiscover Protocol Flaw That Leaks User Credentials

Unpatched Microsoft Exchange servers hit with ProxyShell attack

By Waqas
Researchers have identified 140+ webshells launched against 1,900 unpatched Microsoft Exchange servers.
This is a post from HackRead.com Read the original post: Unpatched Microsoft Exchange servers hit with ProxyShell attack
Continue reading Unpatched Microsoft Exchange servers hit with ProxyShell attack