NSA shares tips on blocking BlackLotus UEFI malware attacks June 22, 2023 The U.S. National Security Agency (NSA) released today guidance on how to defend against BlackLotus UEFI bootkit malware attacks. BlackLotus
Microsoft Teams bug allows malware delivery from external accounts June 22, 2023 Security researchers have found a simple way to deliver malware to an organization with Microsoft Teams, despite restrictions in the
Microsoft 365 users report Outlook, Teams won’t start or freezes June 22, 2023 Network and IT admins have been dealing with ongoing Microsoft 365 issues this week, reporting that some end users cannot
Microsoft: Hackers hijack Linux systems using trojanized OpenSSH version June 22, 2023 Microsoft says Internet-exposed Linux and Internet of Things (IoT) devices are being hijacked in brute-force attacks as part of a
Mirai botnet targets 22 flaws in D-Link, Zyxel, Netgear devices June 22, 2023 A variant of the Mirai botnet is targeting almost two dozen vulnerabilities aiming to take control of D-Link, Arris, Zyxel,
CISA orders govt agencies to patch bugs exploited by Russian hackers June 22, 2023 On Thursday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added six more security flaws to its known exploited vulnerabilities
Millions of GitHub repos likely vulnerable to RepoJacking, researchers say June 22, 2023 Millions of GitHub repositories may be vulnerable to dependency repository hijacking, also known as “RepoJacking,” which could help attackers deploy
VMware fixes vCenter Server bugs allowing code execution, auth bypass June 22, 2023 VMware has addressed multiple high-severity security flaws in vCenter Server, which can let attackers gain code execution and bypass authentication
DuckDuckGo browser for Windows available for everyone as public beta June 22, 2023 DuckDuckGo has released its privacy-centric browser for Windows to the general public. It is a beta version available for download
Exploit released for Cisco AnyConnect bug giving SYSTEM privileges June 22, 2023 Proof-of-concept exploit code is now available for a high-severity flaw in Cisco Secure Client Software for Windows (formerly AnyConnect Secure