12 Oct Signal will remove support for SMS text messages on Android Signal says it will start to phase out SMS and MMS message support from its Android app to streamline the user experience and prioritize security and privacy. […]
12 Oct Microsoft Defender adds command and control traffic detection Microsoft has added command-and-control (C2) traffic detection capabilities to its Microsoft Defender for Endpoint (MDE) enterprise endpoint security platform. […]
12 Oct Aruba fixes critical RCE and auth bypass flaws in EdgeConnect Aruba has released security updates for the EdgeConnect Enterprise Orchestrator, addressing multiple critical severity vulnerabilities that enable remote attackers to compromise the host. […]
11 Oct All Windows versions can now block admin brute-force attacks Microsoft announced today that IT admins can now configure any Windows system still receiving security updates to automatically block brute force attacks targeting local administrator accounts via a group policy. […]
11 Oct Android leaks some traffic even when ‘Always-on VPN’ is enabled Mullvad VPN has discovered that Android leaks traffic every time the device connects to a WiFi network, even if the “Block connections without VPN,” or “Always-on VPN,” features is enabled. […]
11 Oct VMware vCenter Server bug disclosed last year still not patched VMware informed customers today that vCenter Server 8.0 (the latest version) is still waiting for a patch to address a high-severity privilege escalation vulnerability disclosed in November 2021. […]
11 Oct Windows 11 KB5018427 update released with 30 bug fixes, improvements Microsoft has released the Windows 11 22H2 KB5018427 cumulative update with security updates and improvements, including USB printing and Bluetooth headsets fixes. […]
11 Oct Windows 10 KB5018410 and KB5018419 updates released Microsoft has released the Windows 10 KB5018410 and KB5018419 cumulative updates for versions 21H2, version 21H1, version 20H2, and 1809 to fix security vulnerabilities and resolve twenty bugs and performance issues. […]
10 Oct Caffeine service lets anyone launch Microsoft 365 phishing attacks A phishing-as-a-service (PhaaS) platform named ‘Caffeine’ makes it easy for threat actors to launch attacks, featuring an open registration process allowing anyone to jump in and start their own phishing campaigns. […]
10 Oct Hackers behind IcedID malware attacks diversify delivery tactics The threat actors behind IcedID malware phishing campaigns are utilizing a wide variety of distribution methods, likely to determine what works best against different targets. […]