Cyber Defense Advisors

News

  • by
  • November 15, 2023

Three Ways Varonis Helps You Fight Insider Threats

What do basketball teams, government agencies, and car manufacturers have in common? Each one has been breached, having confidential, proprietary, or private information stolen and exposed by insiders. In each case, the motivations and methods varied, but the risk remained the same: insiders have access to too much data with too few controls. Insider threats […]

Cyber News
  • by
  • November 15, 2023

Reptar: New Intel CPU Vulnerability Impacts Multi-Tenant Virtualized Environments

Intel has released fixes to close out a high-severity flaw codenamed Reptar that impacts its desktop, mobile, and server CPUs. Tracked as CVE-2023-23583 (CVSS score: 8.8), the issue has the potential to “allow escalation of privilege and/or information disclosure and/or denial of service via local access.” Successful exploitation of the vulnerability could also permit a […]

Cyber News
  • by
  • November 15, 2023

Alert: Microsoft Releases Patch Updates for 5 New Zero-Day Vulnerabilities

Microsoft has released fixes to address 63 security bugs in its software for the month of November 2023, including three vulnerabilities that have come under active exploitation in the wild. Of the 63 flaws, three are rated Critical, 56 are rated Important, and four are rated Moderate in severity. Two of them have been listed […]

Cyber News
  • by
  • November 15, 2023

Urgent: VMware Warns of Unpatched Critical Cloud Director Vulnerability

VMware is warning of a critical and unpatched security flaw in Cloud Director that could be exploited by a malicious actor to get around authentication protections. Tracked as CVE-2023-34060 (CVSS score: 9.8), the vulnerability impacts instances that have been upgraded to version 10.5 from an older version. “On an upgraded version of VMware Cloud Director […]

Cyber News
  • by
  • November 15, 2023

Microsoft Zero-Days Allow Defender Bypass, Privilege Escalation

Another two bugs in this month’s set of fixes for 63 CVEs were publicly disclosed previously but have not been exploited yet.

Cyber News, Cyber Threat Trends
  • by
  • November 15, 2023

Danish Energy Attacks Portend Targeting More Critical Infrastructure

Targeted attacks against two dozen related companies is just the latest evidence that hackers want a piece of energy.

Cyber News, Cyber Threat Trends
  • by
  • November 14, 2023

Microsoft Patch Tuesday, November 2023 Edition

Microsoft today released updates to fix more than five dozen security holes in its Windows operating systems and related software, including three “zero day” vulnerabilities that Microsoft warns are already being exploited in active attacks. The zero-day threats targeting Microsoft this month include CVE-2023-36025, a weakness that allows malicious content to bypass the Windows SmartScreen […]

Cyber News

Upcoming Speaking Engagements

This is a current list of where and when I am scheduled to speak: I’m speaking at the AI Summit New York on December 6, 2023. The list is maintained on this page.

Cyber News, Cyber Threat Trends