Month: August 2022

  • CISA Releases Cybersecurity Toolkit to Protect U.S. Elections

    Original release date: August 10, 2022 CISA—through the Joint Cyber Defense Collaborative (JCDC)—has released a toolkit of free cybersecurity resources for the election community. The toolkit aims to help state and local government officials, election officials, and vendors enhance the cybersecurity and cyber resilience of U.S. election infrastructure. The toolkit resources, which come from CISA,… Read more

  • Microsoft Patches ‘Dogwalk’ Zero-Day and 17 Critical Flaws

    August Patch Tuesday tackles 121 CVEs, 17 critical bugs and one zero-day bug exploited in the wild. Read more

  • Vulnerability Summary for the Week of August 1, 2022

    Original release date: August 8, 2022 | Last revised: August 9, 2022   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info There were no high vulnerabilities recorded this week. Back to top   Medium Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info There were… Read more

  • Microsoft Releases August 2022 Security Updates

    Original release date: August 9, 2022 Microsoft has released updates to address multiple vulnerabilities in Microsoft software. An attacker can exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review Microsoft’s August 2022 Security Update Guide and Deployment Information and apply the necessary updates. This product is provided… Read more

  • Open Redirect Flaw Snags Amex, Snapchat User Data

    Separate phishing campaigns targeting thousands of victims impersonate FedEx and Microsoft, among others, to trick victims. Read more

  • AA22-216A: 2021 Top Malware Strains

    Original release date: August 4, 2022 Summary Immediate Actions You Can Take Now to Protect Against Malware: • Patch all systems and prioritize patching known exploited vulnerabilities. • Enforce multifactor authentication (MFA). • Secure Remote Desktop Protocol (RDP) and other risky services. • Make offline backups of your data. • Provide end-user awareness and training… Read more

  • VMWare Urges Users to Patch Critical Authentication Bypass Bug

    Vulnerability—for which a proof-of-concept is forthcoming—is one of a string of flaws the company fixed that could lead to an attack chain. Read more

  • VMware Releases Security Updates

    Original release date: August 3, 2022 VMware has released security updates to address multiple vulnerabilities in VMware’s Workspace ONE Access, Access Connector, Identity Manager, Identity Manager Connector, and vRealize Automation. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.  CISA encourages users and administrators to review VMware Security… Read more

  • Universities Put Email Users at Cyber Risk

    DMARC analysis by Proofpoint shows that institutions in the U.S. have among some of the poorest protections to prevent domain spoofing and lack protections to block fraudulent emails. Read more

  • Vulnerability Summary for the Week of July 25, 2022

    Original release date: August 1, 2022 | Last revised: August 2, 2022   High Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info There were no high vulnerabilities recorded this week. Back to top   Medium Vulnerabilities Primary Vendor — Product Description Published CVSS Score Source & Patch Info There were… Read more