Cyber Defense Advisors

Month: July 2023

  • by
  • July 13, 2023

New Vulnerabilities Disclosed in SonicWall and Fortinet Network Security Products

SonicWall on Wednesday urged customers of Global Management System (GMS) firewall management and Analytics network reporting engine software to apply the latest fixes to secure against a set of 15 security flaws that could be exploited by a threat actor to circumvent authentication and access sensitive information. Of the 15 shortcomings (tracked from CVE-2023-34123 through […]

Cyber News, Cyber Threat Trends
  • by
  • July 13, 2023

U.S. Government Agencies’ Emails Compromised in China-Backed Cyber Attack

An unnamed Federal Civilian Executive Branch (FCEB) agency in the U.S. detected anomalous email activity in mid-June 2023, leading to Microsoft’s discovery of a new China-linked espionage campaign targeting two dozen organizations. The details come from a joint cybersecurity advisory released by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation

Cyber News, Cyber Threat Trends
  • by
  • July 13, 2023

Bug Re-deploying AWS TLS Certificate

Can’t redeploy a TLS certificate on AWS Continue reading on Bugs That Bite »

Cyber News, Cyber Threat Trends
  • by
  • July 13, 2023

Ransomware attacks cost financial organizations US$32.3 billion in downtime since 2018

Ransomware attacks on the global finance sector have cost US$32.3 billion in downtime alone since 2018. That’s according to new research from Comparitech, which found that 225 financial organizations are confirmed to have been hit by a ransomware attack in the last five years, exposing at least 32.3 million individual records. Downtime from attacks varied […]

Cyber News, Cyber Threat Trends
  • by
  • July 12, 2023

Hackers exploit Windows driver signature enforcement loophole for malware persistence

A loophole in a core Windows security mechanism that requires all kernel drivers to be digitally signed by Microsoft allows attackers to forge signatures on maliciously modified drivers. This technique has been automated and used to defeat anti-cheating and digital rights management (DRM) features in games and more recently to deploy highly persistent malware. “From […]

Cyber News, Cyber Threat Trends
  • by
  • July 12, 2023

Mastodon Patches 4 Bugs, but Is the Twitter Killer Safe to Use?

Platform’s independent server “instances” may have different security levels, creating potential for supply chain-like vulnerabilities.

Cyber News, Cyber Threat Trends
  • by
  • July 12, 2023

Microsoft Discloses 5 Zero-Days in Voluminous July Security Update

Fixes for more than 100 vulnerabilities affect numerous products, including Windows, Office, .Net, and Azure Active Directory, among others.

Cyber News, Cyber Threat Trends
  • by
  • July 12, 2023

Apple & Microsoft Patch Tuesday, July 2023 Edition

Microsoft Corp. today released software updates to quash 130 security bugs in its Windows operating systems and related software, including at least five flaws that are already seeing active exploitation. Meanwhile, Apple customers have their own zero-day woes again this month: On Monday, Apple issued (and then quickly pulled) an emergency update to fix a […]

Cyber News, Cyber Threat Trends