+44 (0)203 88 020 88

News

September Patch Tuesday fixes Critical and Zero Day vulnerabilities

The September Patch Tuesday security bundle from Microsoft fixes 60 vulnerabilities including some rated as Critical and a zero-day vulnerability under active attack affecting Microsoft Office. Microsoft Security updates for September Microsoft MSHTML Remote Code Execution Vulnerability (CVE-2021-40444) was publicised in early September when Microsoft warned Office 365 customers about the vulnerability.  The flaw was

September Patch Tuesday fixes Critical and Zero Day vulnerabilities Read More »

Microsoft warns Office 365 targeted by zero-day RCE

A zero-day Remote Code Execution attack targeting Office 365 and Office 2019 users has prompted Microsoft to issue a security advisory with a workaround to protect your network until a patch is available. According to the security advisory released by Microsoft: Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects

Microsoft warns Office 365 targeted by zero-day RCE Read More »

Yet another Exchange Server vulnerability

Details have emerged of (another) Exchange Server vulnerability, called ProxyToken, which allows an attacker to reconfigure an Exchange server remotely without needing to know any passwords. Reported by the Zero Day Initiative the vulnerability affects Exchange server versions 2013 through 2019: With this vulnerability, an unauthenticated attacker can perform configuration actions on mailboxes belonging to

Yet another Exchange Server vulnerability Read More »

PrintNightmare vulnerabilities exploited in the wild

Cyber-criminals have been exploiting the Windows PrintNightmare vulnerability to attack networks around the world.  PrintNightmare is the name given to a collection of vulnerabilities in the Windows Print Spooler. According to reports from Talos and CrowdStrike, several threat actors have now incorporated the PrintNightmare vulnerabilities into attacks on their victims networks. The PrintNightmare vulnerabilities were

PrintNightmare vulnerabilities exploited in the wild Read More »

VPN insecurity woes continue for Pulse Secure and Cisco

Cisco and Pulse Secure have both issued security advisories warning of critical Remote Code Execution vulnerabilities that affect some of their VPN servers. Pulse Secure Pulse Secure has shipped a patch to resolve several Remote Code Execution vulnerabilities in its Connect Secure VPN appliances.  The August release addresses these issues and the vendor ‘strongly advises’

VPN insecurity woes continue for Pulse Secure and Cisco Read More »

Scroll to Top