01 May Google Chrome is getting a new Progressive Web App feature In the latest effort to improve the web apps experience, Google appears to be working on a new API that will allow Chrome progressive web apps (PWAs) to ‘handle’ (read) files in the operating system’s file system. […]
01 May Office 365 security baseline adds macro signing, JScript protection Microsoft has updated the security baseline for Microsoft 365 Apps for enterprise (formerly Office 365 Professional Plus) to include protection from JScript code execution attacks and unsigned macros. […]
01 May Python also impacted by critical IP address validation vulnerability Python 3.3 standard library ‘ipaddress’ suffers from a critical IP address vulnerability (CVE-2021-29921) identical to the flaw that was reported in the “netmask” library earlier this year. […]
30 Apr The Week in Ransomware – April 30th 2021 – Attacks Escalate Ransomware gangs continue to target organizations large and small, including a brazen attack on the Washington DC police department. […]
30 Apr First Horizon bank online accounts hacked to steal customers’ funds Bank holding company First Horizon Corporation disclosed the some of its customers had their online banking accounts breached by unknown attackers earlier this month. […]
30 Apr Babuk quits ransomware encryption, focuses on data-theft extortion A new message today from the operators of Babuk ransomware clarifies that the gang has decided to close the affiliate program and move to an extortion model that does not rely on encrypting victim computers. […]
30 Apr Microsoft is bringing the AAC Bluetooth audio codec to Windows 10 Microsoft has added AAC (Advanced Audio Coding) support for Bluetooth audio devices with the release of Windows 10 Build 21370 to the Dev Channel. […]
30 Apr Microsoft PowerToys now requires Windows 10 1903 and later Microsoft released PowerToys v0.37.0 yesterday with minor improvements and a significant change – it now requires a minimum version of Windows 10 1903. […]
29 Apr Microsoft finds critical code execution bugs in IoT, OT devices Microsoft security researchers have discovered over two dozen critical remote code execution (RCE) vulnerabilities in Internet of Things (IoT) devices and Operational Technology (OT) industrial systems. […]
29 Apr New ransomware group uses SonicWall zero-day to breach networks A financially motivated threat actor exploited a zero-day bug in Sonicwall SMA 100 Series VPN appliances to deploy new ransomware known as FiveHands on the networks of North American and European targets. […]