Meet unprecedented security challenges by leveraging MXDR services

Credit to Author: Microsoft Security Experts| Date: Mon, 10 Jul 2023 16:00:00 +0000

Microsoft is excited to announce the general availability of Microsoft Defender Experts for XDR, a first-party MXDR offering that gives security teams air cover with end-to-end protection and expertise.

The post Meet unprecedented security challenges by leveraging MXDR services appeared first on Microsoft Security Blog.

Read more

Apple issues Rapid Security Response for zero-day vulnerability

Categories: Exploits and vulnerabilities

Categories: News

Tags: Apple

Tags: Safari

Tags: WebKit

Tags: macOS

Tags: iOS

Tags: iPadOs

Tags: CVE-2023-37450

Tags: drive-by

Tags: code execution

Apple has issued an update for a zero-day vulnerability in the WebKit browser engine which may be actively exploited.

(Read more…)

The post Apple issues Rapid Security Response for zero-day vulnerability appeared first on Malwarebytes Labs.

Read more

“TootRoot” Mastodon vulnerabilities fixed: Admins, patch now!

Categories: Personal

Tags: tootroot

Tags: mastodon

Tags: server

Tags: patch

Tags: update

Tags: CVE

Tags: flaw

Tags: vulnerability

Tags: social media

Tags: network

Tags: networking

We take a look at a collection of issues (now patched) which were affecting Mastodon servers. It’s time to apply the fix for TootRoot.

(Read more…)

The post “TootRoot” Mastodon vulnerabilities fixed: Admins, patch now! appeared first on Malwarebytes Labs.

Read more

Threatening rogue finance apps removed from the Apple Store

Categories: Personal

Tags: app

Tags: finance

Tags: india

Tags: loan

Tags: rogue

Tags: Apple Store

Tags: play store

Tags: google

Tags: threaten

Tags: blackmail

Tags: sextortion

Tags: fake

Tags: deepfake

Tags: deepfakes

Tags: morph

Multiple finance apps have been removed from the App Store after making dubious charges and issuing blackmail threats and other awful behavior.

(Read more…)

The post Threatening rogue finance apps removed from the Apple Store appeared first on Malwarebytes Labs.

Read more

Apple & Microsoft Patch Tuesday, July 2023 Edition

Credit to Author: BrianKrebs| Date: Tue, 11 Jul 2023 22:55:07 +0000

Microsoft Corp. today released software updates to quash 130 security bugs in its Windows operating systems and related software, including at least five flaws that are already seeing active exploitation. Meanwhile, Apple customers have their own zero-day woes again this month: On Monday, Apple issued (and then quickly pulled) an emergency update to fix a zero-day vulnerability that is being exploited on MacOS and iOS devices.

Read more

Guide to Operationalizing Zero Trust

Credit to Author: Alifiya Sadikali| Date: Tue, 11 Jul 2023 00:00:00 +0000

Zero Trust is no longer a buzzword but an essential element in enterprise security architecture. Operating on the ‘never trust, always verify’ principle, Zero Trust plays a vital role in protecting enterprise assets and data. However, operationalizing Zero Trust can be challenging for businesses.

Read more

Microsoft Revokes Malicious Drivers in Patch Tuesday Culling

Credit to Author: Andrew Brandt| Date: Tue, 11 Jul 2023 17:20:38 +0000

In December 2022, Microsoft published their monthly Windows Update packages that included an advisory about malicious drivers, signed by Microsoft and other code-signing authorities, that Sophos X-Ops (and others) observed threat actors abusing during attacks. Today, Microsoft issued Security Advisory ADV230001 as part of their July Windows Update that addresses Sophos’ discovery of more than […]

Read more

Apple's disappearing Rapid Security Response update (u)

Apple on Monday distributed its latest Rapid Security Response update to iPhones, iPads, and Macs, rolling out an important security patch to protect devices against a recently identified attack Apple says is already in active use.

“Apple is aware of a report that this issue may have been actively exploited,” the company said in its security note.

That’s bad, as it means someone somewhere has already been attacked using this vulnerability. The patch repairs a flaw found in WebKit in which processing web content could lead to arbitrary code execution.

To read this article in full, please click here

Read more