Windows Lock Screen Security Feature Bypass Vulnerability (Important, CVE-2020-17099, CVSSv3 6.8/5.9)

Windows Lock Screen Security Feature Bypass Vulnerability (Important, CVE-2020-17099, CVSSv3 6.8/5.9) https://ift.tt/36VPxzp Yesterday, for its December 2020 Patch Tuesday, Microsoft released an important security update addressing a Windows Lock Screen Security Feature Bypass Vulnerability .   About the vulnerability An authenticated user has signed into a device and locks his or her active session. An […]

FireEye and partners release SolarWinds kill-switch

FireEye and partners release SolarWinds kill-switch https://ift.tt/3airWLc FireEye and partners GoDaddy and Microsoft have deployed a so-called kill-switch against the SolarWinds Sunburst/Solarigate malware used by a state-backed actor to compromise multiple US government departments and FireEye, mitigating some of the potential impact of the wide-ranging attack. The cyber attack saw the compromise of SolarWinds’ network […]

Spoofing Vulnerability in DNS Resolver (SAD DNS, Important, CVE-2020-25705, ADV200013)

Spoofing Vulnerability in DNS Resolver (SAD DNS, Important, CVE-2020-25705, ADV200013) https://ift.tt/3oI5kYr On December 8th, 2020, Microsoft issued an advisory for a spoofing vulnerability in the DNS Resolver component. Microsoft refers to the advisory as ADV200013. BleepingComputer.com references CVE-2020-25705 in relationship to this vulnerability. In the advisory notice, Microsoft guides DNS admins to limit the DNS […]

Azure Storage account recovery available via portal is now generally available

Azure Storage account recovery available via portal is now generally available https://ift.tt/2LqxYiF Azure Storage uses a storage account to contain all of your Azure Storage data including: blobs, files,  tables, queues, and disks.  Accidentally deleting a storage account deletes all data in the account and previously could not be recovered.  Today we are announcing that storage account recovery is available with some restrictions and this functionality is available […]

Theft of Cybersecurity Tools | FireEye Breach

Theft of Cybersecurity Tools | FireEye Breach https://ift.tt/2W0S6ty On December 8, 2020, FireEye disclosed theft of their Red Team assessment tools. These tools are used by FireEye to test and validate the security posture of their customers. According to FireEye, the hackers now have an influential collection of new techniques to draw upon. It is unclear today if the attackers intend to use the tools themselves or if […]

Vulnerable TCP/IP stacks open millions of IoT and OT devices to attack

Vulnerable TCP/IP stacks open millions of IoT and OT devices to attack https://ift.tt/3gqHlu9 Forescout researchers have discovered 33 vulnerabilities affecting four open source TCP/IP (communications) stacks used in millions of connected devices worldwide. Collectively dubbed Amnesia:33 because they primarily cause memory corruption, these vulnerabilities may allow attackers to remotely compromise devices, execute malicious code, perform […]