Author: DEFENDEDGE

  • Apache Releases Security Advisory for Apache Tomcat

    Original release date: December 4, 2020 The Apache Software Foundation has released a security advisory to address a vulnerability in Apache Tomcat. An attacker could exploit this vulnerability to cause a denial-of-service condition. The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Apache security advisory for CVE-2020-17527 upgrade to the… Read more

  • VMware Rolls a Fix for Formerly Critical Zero-Day Bug

    VMware has issued a full patch and revised the severity level of the NSA-reported vulnerability to “important.” Read more

  • VMware Releases Security Updates to Address CVE-2020-4006

    Original release date: December 3, 2020 VMware has released security updates to address a vulnerability—CVE-2020-4006—in VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector. An attacker could exploit this vulnerability to take control of an affected system.  The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review VMware Security… Read more

  • TrickBot Returns with a Vengeance, Sporting Rare Bootkit Functions

    A new “TrickBoot” module scans for vulnerable firmware and has the ability to read, write and erase it on devices. Read more

  • Heightened Awareness for Iranian Cyber Activity

    Original release date: December 3, 2020 Iranian cyber threat actors have been continuously improving their offensive cyber capabilities. They continue to engage in more conventional offensive cyber activities ranging from website defacement, distributed denial of service (DDoS) attacks, and theft of personally identifiable information (PII), to more advanced activities—including social media-driven influence operations, destructive malware,… Read more

  • NCSC Releases 2020 Annual Review

    Original release date: December 3, 2020 The United Kingdom (UK) National Cyber Security Centre (NCSC) has released its Annual Review 2020, which focuses on its response to evolving and challenging cyber threats. Recognizing cybersecurity as a “team sport,” the publication includes highlights of NCSC’s collaboration with many partners, including the Cybersecurity and Infrastructure Security Agency… Read more

  • As Modern Mobile Enables Remote Work, It Also Demands Security

    Lookout’s Hank Schless discusses accelerated threats to mobile endpoints in the age of COVID-19-sparked remote working. Read more

  • Apple Releases Security Updates for iCloud for Windows

    Original release date: December 3, 2020 Apple has released security updates to address vulnerabilities in iCloud for Windows. An attacker could exploit some of these vulnerabilities to take control of an affected system. The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Apple security page for iCloud for Windows 11.5… Read more

  • Google Play Apps Remain Vulnerable to High-Severity Flaw

    Patches for a flaw (CVE-2020-8913) in the Google Play Core Library have not been implemented by several popular Google Play apps, including Cisco Teams and Edge. Read more

  • IBM Releases Report on Cyber Actors Targeting the COVID-19 Vaccine Supply Chain

    Original release date: December 3, 2020 IBM X-Force has released a report on malicious cyber actors targeting the COVID-19 cold chain—an integral part of delivering and storing a vaccine at safe temperatures. Impersonating a biomedical company, cyber actors are sending phishing and spearphishing emails to executives and global organizations involved in vaccine storage and transport… Read more