+44 (0)203 88 020 88

Menu

Search

microsoft

Excel XLM Macros to be disabled by default – sometimes

Three decades ago, Microsoft released Excel 4.0 with support for XLM macro files.  A firm favourite with threat actors, XLM macros can be easily subverted to drop malware onto a victim’s computer through email campaigns that deliver malicious Office365 documents such as fake invoices and reports.  Microsoft has now announced that XLM macros will be

Excel XLM Macros to be disabled by default – sometimes Read More »

October Security Updates

The October security patch updates include fixes for critical flaws and zero-day vulnerabilities from Microsoft, Apple and Apache. Microsoft October Updates October’s security patch bundle from Microsoft includes fixes for four zero-day vulnerabilities, at least one of which is actively being exploited in the wild. Overall Microsoft fixes 70 vulnerabilities include the first inclusion of

October Security Updates Read More »

Exchange can now automatically mitigate new vulnerabilities

The September update for Microsoft Exchange includes a new security feature for on-premises servers – they can now automatically mitigate new vulnerabilities just like the cloud versions used by Office 365. The last 12 months have not been fun for Exchange administrators with a series of high-profile vulnerabilities affecting on-premise Exchange servers resulting in the

Exchange can now automatically mitigate new vulnerabilities Read More »

September Patch Tuesday fixes Critical and Zero Day vulnerabilities

The September Patch Tuesday security bundle from Microsoft fixes 60 vulnerabilities including some rated as Critical and a zero-day vulnerability under active attack affecting Microsoft Office. Microsoft Security updates for September Microsoft MSHTML Remote Code Execution Vulnerability (CVE-2021-40444) was publicised in early September when Microsoft warned Office 365 customers about the vulnerability.  The flaw was

September Patch Tuesday fixes Critical and Zero Day vulnerabilities Read More »

Microsoft warns Office 365 targeted by zero-day RCE

A zero-day Remote Code Execution attack targeting Office 365 and Office 2019 users has prompted Microsoft to issue a security advisory with a workaround to protect your network until a patch is available. According to the security advisory released by Microsoft: Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects

Microsoft warns Office 365 targeted by zero-day RCE Read More »

Yet another Exchange Server vulnerability

Details have emerged of (another) Exchange Server vulnerability, called ProxyToken, which allows an attacker to reconfigure an Exchange server remotely without needing to know any passwords. Reported by the Zero Day Initiative the vulnerability affects Exchange server versions 2013 through 2019: With this vulnerability, an unauthenticated attacker can perform configuration actions on mailboxes belonging to

Yet another Exchange Server vulnerability Read More »

0

No products in the basket.

No products in the basket.