+44 (0)203 88 020 88

Menu

Search

News

Bluekeep – critical Windows vulnerability

Microsoft included a fix for a serious RDP remote code execution vulnerability known as BlueKeep in the May patch Tuesday update. The vulnerability, which has become known as BlueKeep or CVE-2019-0708, remains unpatched on millions of internet connected systems.  It affects all Windows-NT based operating systems ranging from Windows 2000 and Windows XP up to […]

Bluekeep – critical Windows vulnerability Read More »

Dell SupportAssist remote code execution vulnerability

Dell SupportAssist software prior to 3.2.0.90 contains two critical remote code execution vulnerabilities. Dell has just released a new version of their SupportAssist software which comes pre-installed on most systems to correct CVE-2019-3719. A 17 year old security researcher discovered a weakness in the way the Dell software validated the identity of the dell.com website. This made

Dell SupportAssist remote code execution vulnerability Read More »

Cybercriminals shift focus from consumers to businesses

Compared to Q1 2018, malware detections in businesses has increased 235% while dropping 24% for consumers. Anti-virus and security firm Malwarebytes reports in their latest Cybercrime Tactics and Techniques report that cybercriminals are following the money and shifting their focus from consumers to businesses that have more valuable assets and possibly the financial resources to

Cybercriminals shift focus from consumers to businesses Read More »

Atlassian issues critical security advisory for Confluence

Many modern software factories adopting Agile development methodologies also take on the tools of Atlassian such as Jira to managed their feature backlog and Confluence for documentation.  A critical path traversal vulnerability has been discovered in the on-premises version of Confluence Server and Data Centre which will allow a remote user who has permission to

Atlassian issues critical security advisory for Confluence Read More »

windows code signing

Microsoft improve code-signing on security updates with SHA-2

Microsoft is changing the way it digitally signs updates to Windows to improve protection against supply chain attacks – ensuring only valid original patches from Microsoft are installed through the Windows update utility. Currently, Windows patches are digitally-signed using both the SHA-1 and SHA-2 algorithms; however, because of known vulnerabilities in the SHA-1 hashing algorithm,

Microsoft improve code-signing on security updates with SHA-2 Read More »

apple virus

Novel application package allows Windows malware to target MacOS and Linux

In the eternal arms race between malware creators and security vendors, a novel new tactic has emerged.  Trend Micro has recently reported that Windows executables (.EXE files) are being created that target non-windows platforms such as MacOS.  Because .EXE files are not supported as an executable on MacOS the built in Gatekeeper protection layer in

Novel application package allows Windows malware to target MacOS and Linux Read More »

0

No products in the basket.

No products in the basket.