Author: DEFENDEDGE

  • Here’s REALLY How to Do Zero-Trust Security

    It’s not about buying security products! Joseph Carson, chief security scientist from ThycoticCentrify, offers practical steps to start the zero-trust journey. Read more

  • Citrix Releases Security Update for Workspace App for Linux

    Original release date: January 11, 2022 Citrix has released a security update to address a vulnerability in Workspace App for Linux. An attacker could exploit this vulnerability to take control of an affected system. CISA encourages users and administrators to review Citrix Security Update CTX338435 and apply the necessary update. This product is provided subject to… Read more

  • Microsoft Releases January 2022 Security Updates

    Original release date: January 11, 2022 Microsoft has released updates to address multiple vulnerabilities in Microsoft software. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review Microsoft’s January 2022 Security Update  Summary and Deployment Information and apply the necessary updates. This product is provided… Read more

  • Microsoft Faces Wormable, Critical RCE Bug & 6 Zero-Days

    The large January 2022 Patch Tuesday update covers nine critical CVEs, including a self-propagator with a 9.8 CVSS score. Read more

  • SAP Releases January 2022 Security Updates

    Original release date: January 11, 2022 SAP has released security updates to address vulnerabilities affecting multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review the SAP Security Notes for January 2022 and apply the necessary updates. This product is provided subject… Read more

  • MacOS Bug Could Let Creeps Snoop On You

    The flaw could allow attackers to bypass Privacy preferences, giving apps with no right to access files, microphones or cameras the ability to record you or grab screenshots. Read more

  • WordPress Bugs Exploded in 2021, Most Exploitable

    Record-number WordPress plugin vulnerabilities are wicked exploitable even with low CVSS scores, leaving security teams blind to their risk. Read more

  • Samba Releases Security Update

    Original release date: January 11, 2022 The Samba Team has released a security update to address a vulnerability in multiple versions of Samba. An attacker could exploit this vulnerability to take control of an affected system. CISA encourages users and administrators to review Samba Security Announcement CVE-2021-43566 and apply the necessary update.  This product is provided… Read more

  • AA22-011A: Understanding and Mitigating Russian State-Sponsored Cyber Threats to U.S. Critical Infrastructure

    Original release date: January 11, 2022 Summary Actions Critical Infrastructure Organizations Should Implement to Immediately Strengthen Their Cyber Posture. • Patch all systems. Prioritize patching known exploited vulnerabilities. • Implement multi-factor authentication. • Use antivirus software. • Develop internal contact lists and surge support. Note: this advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge… Read more

  • Critical SonicWall NAC Vulnerability Stems from Apache Mods

    Researchers offer more detail on the bug, which can allow attackers to completely take over targets. Read more