+44 (0)203 88 020 88

Vulnerabilities

Install patches to protect Domain Controllers warns Microsoft

Proof of Concept code has been published showing how to exploit two vulnerabilities that would allow an attacker to obtain domain admin privilege on your Windows Domain Controllers. In the November security patch bundle, Microsoft released patches to resolve two vulnerabilities ( CVE-2021-42287 and CVE-2021-42278 ) in the Windows Active Directory Domain Services.  On December 12th a proof

Install patches to protect Domain Controllers warns Microsoft Read More »

Mozilla warns of digital signature vulnerability

Mozilla has published a security advisory warning of a critical security vulnerability in the Network Security Services libraries which are widely used by open-source software. While the bug does not impact Mozilla Firefox, it is thought to affect many other email clients and PDF viewers that use the electronic signature verification features of the Network

Mozilla warns of digital signature vulnerability Read More »

Attackers rapidly target Microsoft vulnerabilities

This week there have been several exploits published that target recently published (and patched) vulnerabilities in Microsoft Exchange Server and Windows 10/11 systems. Coming just a week after Microsoft published patches for these vulnerabilities, already proof of concept code has been made available on GitHub and threat actors have started targeting the exploits hoping to

Attackers rapidly target Microsoft vulnerabilities Read More »

Palo Alto Networks patches VPN/Firewalls

Palo Alto Networks has released a critical patch for their firewalls with GlobalProtect  Portal or Gateway interfaces.  With a critical severity rating of 9.8, this memory corruption vulnerability could allow an attacker to execute remote code on the firewall with root privileges. According to the security advisory published by Palo Alto Networks: This issue is

Palo Alto Networks patches VPN/Firewalls Read More »

Javascript supply chain attack hits millions of users

A javascript library downloaded millions of times each week was compromised in a supply chain attack which targeted the npm software registry. npm describes itself as the worlds largest software registry, and is used to host and share thousands of open source and private software projects. The javascript library in question is used by companies

Javascript supply chain attack hits millions of users Read More »

Scroll to Top