Zero-Day Flaw Allowed Attackers to Achieve RCE on Firewalls

British security firm Sophos determined that malicious actors had abused a zero-day vulnerability to achieve remote code execution (RCE) on some of its firewall products. According to Sophos, the attack chain began when digital attackers exploited a ze… Continue reading Zero-Day Flaw Allowed Attackers to Achieve RCE on Firewalls

Windows has a zero-day that won’t be patched for weeks

Cybercriminals are exploiting two unpatched zero-day flaws affecting all supported versions of Windows, Microsoft has warned. Continue reading Windows has a zero-day that won’t be patched for weeks

Microsoft Patches 26 Critical Bugs in Big March Update

March security updates include 115 CVEs patching everything from Windows, Office and Microsoft’s new Chromium-based Edge web browser. Continue reading Microsoft Patches 26 Critical Bugs in Big March Update

US charges four Chinese military members with Equifax hack

The indictment suggests the hack was part of a series of major data thefts organized by Chinese military and intelligence agencies. Continue reading US charges four Chinese military members with Equifax hack

Critical Citrix RCE Flaw Still Threatens 1,000s of Corporate LANs

RCE and myriad other types of attacks could take aim at the 19 percent of vulnerable companies that haven’t yet patched CVE-2019-19781. Continue reading Critical Citrix RCE Flaw Still Threatens 1,000s of Corporate LANs