article thumbnail

Patch Tuesday, November 2020 Edition

Krebs on Security

” A chief concern among all these updates this month is CVE-2020-17087 , which is an “important” bug in the Windows kernel that is already seeing active exploitation. Microsoft explained its reasoning behind this shift in a blog post. Not everyone is happy with the new format. 10 is the most dangerous).

Security 275
article thumbnail

Microsoft Patch Tuesday, May 2020 Edition

Krebs on Security

” For example, Satnam Narang from Tenable notes that two remote code execution flaws in Microsoft Color Management ( CVE-2020-1117 ) and Windows Media Foundation ( CVE-2020-1126 ) could be exploited by tricking a user into opening a malicious email attachment or visiting a website that contains code designed to exploit the vulnerabilities.

Risk 272
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Microsoft Patch Tuesday, April 2020 Edition

Krebs on Security

Near the top of the heap is CVE-2020-1020 , a remotely exploitable bug in the Adobe Font Manager library that was first detailed in late March when Microsoft said it had seen the flaw being used in active attacks. Also, keep an eye on the AskWoody blog from Woody Leonhard , who keeps a close eye on buggy Microsoft updates each month.

Libraries 250
article thumbnail

Microsoft Patch Tuesday, March 2020 Edition

Krebs on Security

Recorded Future warns exploit code is now available for one of the critical bugs Redmond patched last month in Microsoft Exchange ( CVE-2020-0688 ), and that nation state actors have been observed abusing the exploit for targeted attacks. CVE-2020-0852 is one just four remote execution flaws Microsoft patched this month in versions of Word.

Security 254
article thumbnail

International Women’s Day 2020: Each for Equal

OpenText Information Management

It is a day to recognize the significant strides we have made so far and look forward with the resolve that we can … The post International Women’s Day 2020: Each for Equal appeared first on OpenText Blogs.

IT 111
article thumbnail

CVE-2020-15782 flaw in Siemens PLCs allows remote hack

Security Affairs

Researchers at industrial cybersecurity firm Claroty have discovered a high-severity vulnerability in Siemens PLCs, tracked as CVE-2020-15782 , that could be exploited by remote and unauthenticated attackers to bypass memory protection. Claroty’s blog post describes the PLC sandbox and the role CVE-2020-15782 could play in an attack.

article thumbnail

A threat actor exploited 11 zero-day flaws in 2020 campaigns

Security Affairs

A hacking group has employed at least 11 zero-day flaws as part of an operation that took place in 2020 and targeted Android, iOS, and Windows users. Google researchers observed two separate waves of attacks that took place in February and October 2020, respectively. ” wrote the popular Project Zero researcher Maddie Stone.

Security 140