Security
Headlines
HeadlinesLatestCVEs

Tag

#microsoft

CVE-2021-37981: Chromium: CVE-2021-37981 Heap buffer overflow in Skia

*What is the version information for this release?* Microsoft Edge Version Date Released Based on Chromium Version 95.0.1020.30 10/21/2021 95.0.4638.54

Microsoft Security Response Center
#Microsoft Edge (Chromium-based)#Security Vulnerability#microsoft
CVE-2021-42307: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

*What is the version information for this release?* Microsoft Edge Version Date Released Based on Chromium Version 95.0.1020.30 10/21/2021 95.0.4638.54

Security News: Microsoft Patch Tuesday October 2021, Autodiscover, MysterySnail, Exchange, DNS, Apache, HAProxy, VMware vCenter, Moodle

Hello everyone! This episode will be about relatively recent critical vulnerabilities. Let’s start with Microsoft Patch Tuesday for October 2021. Specifically, with the vulnerability that I expected there, but it didn’t get there. Autodiscover leak discovered by Guardicore Labs “Autodiscover, a protocol used by Microsoft Exchange for automatic configuration of clients such as Microsoft Outlook, […]

Microsoft-Signed Rootkit Targets Gaming Environments in China

FiveSys is the second publicly known rootkit since June that attackers have managed to sneak past Microsoft's driver certification process.

Microsoft, Intel, and Goldman Sachs to Lead New TCG Work Group to Tackle Supply Chain Security Challenges

Led by representatives from the three companies, the work group will create guidance that defines, implements, and upholds security standards for the entire supply chain.

MITRE Engenuity Announces ATT&CK® Evaluations Call for Participation for Managed Services

Offering to provide transparency into the capabilities of managed security service providers and and managed detection and response competencies.

CISA Awards $2 Million to Bring Cybersecurity Training to Rural Communities and Diverse Populations

Award recipients NPower and CyberWarrior recognized for development of cyber workforce training programs.

Execs From Now-Defunct GigaTrust Arrested in $50M Fraud Scheme

Email endpoint security-as-a-service company founder and two others indicted in an elaborate financial fraud scheme.

Google: Phishing Campaign Targets YouTube Creators

The attackers behind the campaign, which distributes cookie theft malware, are attributed to actors recruited in a Russian-speaking forum.