Secret Backdoor Account Found in Several Zyxel Firewall, VPN Products

Secret Backdoor Account Found in Several Zyxel Firewall, VPN Products https://ift.tt/2MoHL9s Zyxel has released a patch to address a critical vulnerability in its firmware concerning a hardcoded undocumented secret account that could be abused by an attacker to login with administrative privileges and compromise its networking devices. The flaw, tracked as CVE-2020-29583 (CVSS score 7.8), […]

Solorigate Resource Center – updated December 22nd, 2020 – Microsoft Security Response Center

Solorigate Resource Center – updated December 22nd, 2020 – Microsoft Security Response Center https://ift.tt/34zHuXi Alongside our industry partners and the security community, Microsoft continues to investigate the extent of the recent nation-state attack on SolarWinds. Our goal is to provide the latest threat intelligence, Indicators of Compromise (IOC)s, and guidance across our products and solutions to help the community respond, harden infrastructure, and begin to recover from this unprecedented attack. As […]

Protecting Microsoft 365 from on-premises attacks

Protecting Microsoft 365 from on-premises attacks https://ift.tt/2WGMw05 Many customers connect their private corporate networks to Microsoft 365 to benefit their users, devices, and applications. However, there are many well-documented ways these private networks can be compromised. As we have seen in recent events related to the SolarWinds compromise, on-premises compromise can propagate to the cloud. […]

Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers

Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers https://ift.tt/3hd7bCp We, along with the security industry and our partners, continue to investigate the extent of the Solorigate attack. While investigations are underway, we want to provide the defender community with intelligence to understand the scope, impact, […]

Security baseline (FINAL) for Windows 10 and Windows Server, version 20H2

Security baseline (FINAL) for Windows 10 and Windows Server, version 20H2 https://ift.tt/3mpQ3tP We are pleased to announce the final release of the for Windows 10 and Windows Server, version 20H2 (a.k.a. October 2020 Update) security baseline package!   Please download the content from the Microsoft Security Compliance Toolkit, test the recommended configurations, and customize and implement […]