4 over-hyped security vulnerabilities of 2022

Categories: Exploits and vulnerabilities

Categories: News

Tags: wormable

Tags: zero-day

Tags: spring4shell

Tags: cve-2022-34718

Tags: log4j

Tags: openssl

Tags: cve-2022-36934

Tags: cve-2022-27492

Tags: cve-2022-22965

Tags: cve-2022-22963

What does it take to make the discussion of vulnerabilities useful? And where did this go wrong in 2022?

(Read more…)

The post 4 over-hyped security vulnerabilities of 2022 appeared first on Malwarebytes Labs.

Read more

A week in security (December 12 – 18)

Categories: News

Tags: week in security

Tags: AWIS

Tags: weekly blog recap

Tags: Indiana

Tags: TikTok

Tags: MSP

Tags: electronic sales suppression tools

Tags: iPhone

Tags: Play ransomware

Tags: ransomware

Tags: Nebula

Tags: Quarantine for Cloud Storage Scanning

Tags: SOC

Tags: ROI

Tags: Uber

Tags: Apple

Tags: virtual kidnapping

Tags: DDoS booter service

Tags: law enforcement takedown

Tags: InfraGuard

Tags: InfraGuard breach

The most interesting security related news from the week of December 12 to 18.

(Read more…)

The post A week in security (December 12 – 18) appeared first on Malwarebytes Labs.

Read more

Gatekeeper’s Achilles heel: Unearthing a macOS vulnerability

Credit to Author: Microsoft Security Threat Intelligence| Date: Mon, 19 Dec 2022 18:00:00 +0000

Microsoft discovered a vulnerability in macOS, referred to as “Achilles”, allowing attackers to bypass application execution restrictions enforced by the Gatekeeper security mechanism.

The post Gatekeeper’s Achilles heel: Unearthing a macOS vulnerability appeared first on Microsoft Security Blog.

Read more

Forrester names Microsoft a Leader in Q4 2022 Security Analytics Platforms Wave report

Credit to Author: Christine Barrett| Date: Mon, 19 Dec 2022 17:00:00 +0000

We’re excited to announce that Microsoft is named a Leader in the 2022 Forrester Wave™: Security Analytics Platforms. Microsoft achieved the highest possible score in 17 different criteria, including partner ecosystem, innovation roadmap, product security, case management, and architecture.

The post Forrester names Microsoft a Leader in Q4 2022 Security Analytics Platforms Wave report appeared first on Microsoft Security Blog.

Read more

The trials and tribulations of Microsoft’s KB5012170 patch

KB5012170 is many things to many Windows users. First, it’s a patch that either installs with no problems or leads to a blue screen of death (BSOD). It can also be an indicator we have a problem getting updated drivers on our systems. It can demonstrate how users don’t keep up with Bios updates. And it shows that some OEMs enable Bitlocker on the systems they sell (not necessarily in a good way).

In short, it’s a problematic patch that just keeps rearing its head.

Also known as “Security Update for Secure Boot DBX,” KB5012170 was released earlier this year and makes improvements to the Secure Boot Forbidden Signature Database (DBX).  Windows devices that have Unified Extensible Firmware Interface (UEFI)-based firmware have Secure Boot enabled. It ensures only trusted software can be loaded and executed on during the boot process by using cryptographic signatures to verify the integrity of the process and the software being loaded.

To read this article in full, please click here

Read more