Patch now to address critical Windows zero-day flaw

The first Patch Tuesday of the year from Microsoft addresses 98 security vulnerabilities, with 10 classified as critical for Windows. One vulnerability (CVE-2023-21674) in a core section of Windows code is a zero-day that requires immediate attention. And Adobe has returned with a critical update, paired with a few low-profile patches for the Microsoft Edge browser.

We have added the Windows and Adobe updates to our “Patch Now” list, recognizing that this month’s patch deployments will require significant testing and engineering effort. The team at Application Readiness has provided a helpful infographic that outlines the risks associated with each of the updates for this January update cycle.

To read this article in full, please click here

Read more

Microsoft doc details the dos and don’ts of Mac ransomware <u>

As enterprise adoption of the Apple platform accelerates, it’s important to note that Macs can and sometimes do get hit by ransomware. So it’s good to stay tuned to security concerns on a platform and application level — and take precautions.

Knowledge is power

With this in mind, extensive insights into Mac ransomware recently published only to be subsequently removed by Microsoft, can help explain these threats. The impact of such attack can be huge – ransomware already costs victims hundreds of billions each year, and no one is immune. 

To read this article in full, please click here

Read more

WhatsApp lawsuit against NSO Group greenlit by Supreme Court

Categories: News

Tags: Pegasus

Tags: spyware

Tags: Pegasus spyware

Tags: NSO Group

Tags: NSO

Tags: Apple

Tags: WhatsApp

Tags: Meta

Tags: Foreign Sovereign Immunity Act

The US Supreme Court essentially gave Meta’s WhatsApp the go ahead to pursue their case against Pegasus’s NSO Group.

(Read more…)

The post WhatsApp lawsuit against NSO Group greenlit by Supreme Court appeared first on Malwarebytes Labs.

Read more

Update now! Patch Tuesday January 2023 includes one actively exploited vulnerability

Categories: Exploits and vulnerabilities

Categories: News

Tags: patch Tuesday

Tags: CVE-2023-21674

Tags: APLC

Tags: CVE-2023-21743

Tags: Sharepoint

Tags: CVE-2023-21563

Tags: BitLocker

The second Tuesday of the year brings us many updates, including one for an actively exploited vulnerability that could lead to elevation of privileges

(Read more…)

The post Update now! Patch Tuesday January 2023 includes one actively exploited vulnerability appeared first on Malwarebytes Labs.

Read more

4 Predictions for Cyber Insurance Requirements 2023

Credit to Author: Vince Kearns| Date: Thu, 12 Jan 2023 00:00:00 +0000

As the threat landscape evolves and the cost of data breaches increase, so will cyber insurance requirements from carriers. Cyber Risk Specialist Vince Kearns shares his 4 predictions for 2023.

Read more