Security


New Microsoft Autopatch Service Aims To Patch PCs Automatically

Microsoft on Tuesday unveiled Windows Autopatch, which lets Microsoft take over quality and security patching operations in organizations, including Windows operating system feature updates, plus driver updates.

White Cloud Graphic

Google: Microsoft Tech Is Bad for Government Security

Google is pointing to government organizations' reliance on Microsoft technology as a serious security threat.

VMware Confirms Zero-Day Vulnerability in Spring Framework Dubbed 'Spring4Shell'

The Spring Framework can be subject to newly a disclosed "zero-day" vulnerability (CVE-2022-22965) that's deemed "Critical," according to a Thursday announcement by Spring developer VMware.

Globant Apparently Hacked by Lapsus Gang

Software development and IT services company Globant appears to have confirmed getting hacked, and it likely was done by the Lapsus$ criminal gang.

Microsoft on Metaverse: 'Trust Cannot End at the Doorway of a Virtual Meeting Space'

The metaverse is coming and, with it, a new landscape for cyber threats.

Data Privacy Framework Agreed to by U.S. and EU

A new "Trans-Atlantic Data Privacy Framework" was agreed to "in principle," as announced on Friday by the European Commission and the Biden White House.

Arrests Made Against Lapsus Hacking Group

Seven individuals connected with the Lapsus$ hacking group, including the suspected ringleader, were arrested on Thursday in the surrounding areas of London.

366 Okta Customers Affected by Lapsus Attack

Okta issued a follow-up statement on Wednesday regarding an attack by the Lapsus$ group, indicating that 366 of its customers (about 2.5 percent) at maximum may have been affected.

Microsoft Expanding Cybersecurity Worker Shortage Initiative

In three years there will be 3.5 million vacant cybersecurity jobs across the globe. And that's going to lead to real problems in addressing the growing threat landscape, according to Microsoft.

Okta Confirms Lapsus$ Attack, While Microsoft Investigates Breach Claim

Identity services provider Okta on Tuesday stated that its service wasn't breached by Lapsus$ attackers, although the account of a third-party support engineer working with Okta did get hacked back in January.

U.S. Infrastructure Operators Urged To Harden Security Immediately

The Biden White House this week warned that U.S. "critical infrastructure" operators should "harden their cyberdefenses immediately" against possible Russian attacks.

Microsoft Previews Delaying Brute-Force NTLM Logon Guesses in Windows Server

Microsoft this week announced a preview of its next Windows Server ("VNext") enhancements, which includes a new approach for deterring brute-force attempts to guess system passwords and gain network access.

Misconfigured Multifactor Authentication Subject to Russian Attackers

Organizations should not only use multifactor authentication (MFA), but they should also ensure that it's not misconfigured to ward off possible Russian state-sponsored attacks.

Microsoft's Commitment To Addressing the Gender Gap in Cybersecurity

Women accounted for just 25 percent of the global cybersecurity force in 2021, according to Microsoft.

Microsoft 365 Services Getting Root Certificate Authority Switch in 2025

Microsoft gave notice this week that currently used Transport Layer Security (TLS) certificates associated with Microsoft 365 services and Azure Communication Services "will expire in May 2025."

Microsoft Packs 71 Flaw Fixes in March Patch Tuesday

Microsoft on Tuesday released its monthly patch rollout, addressing 71 vulnerabilities and exposures (CVEs), three of those tackling "critical" flaws.

Google To Acquire Security Firm Mandiant for $5.4 Billion

Google announced on Tuesday it's going big on security with the purchase of Virginia-based security firm Mandiant.

Defender for Azure Cosmos DB Preview Announced by Microsoft

Microsoft Defender for Cloud users are getting a preview of Microsoft Defender for Azure Cosmos DB, per a Tuesday Microsoft announcement.

Microsoft IDs FoxBlade Malware Attack Hours Before Russia's Invasion of Ukraine

Microsoft is not only voicing support for the Ukrainian people, it's also supplying what aid it can to the European country.

New Defender for Business Product Now Getting Released to Some Microsoft 365 Subscribers

Microsoft Defender for Business, a new security solution for small-to-medium organizations, is now at the "general availability" commercial-release stage for Microsoft 365 Business Premium subscribers, per a Tuesday Microsoft announcement.

Subscribe on YouTube