Security


U.S. CERT Issues Advisory on VPN Apps

The United States Computer Emergency Readiness Team issued an alert this week about the improper storage of session data by virtual private network applications.

Support Ending in July for SCCM 2007 and Forefront Endpoint Protection 2010

Microsoft published a notice on Wednesday that System Center Configuration Manager 2007 (SCCM) and Forefront Endpoint Protection 2010 (FEP) both will fall out of support on July 9, 2019.

Microsoft's April Security Patch Bundle Released

Microsoft announced the release of its April security patches on Tuesday, addressing 74 unique vulnerabilities.

Yellow Fence Graphic

Microsoft Finally Lets Windows Defender Protect Itself

A recently added "tamper protection" feature finally corrects an obvious security gap in Microsoft's anti-malware solution.

Microsoft Goes Live with Password Protection for Azure AD Users

Microsoft's Azure Active Directory Password Protection feature is now deemed ready for deployment by organizations, having reached "general availability" status, according to Microsoft's announcement on Tuesday.

Microsoft Releases Configuration Manager Update 1902, Plus Security and Compliance Tools

Microsoft this week announced release milestones for some of its management, security and compliance tools.

Red Shapes

Asus Computers Targeted for Attack Using Compromised Update Software

Software security firm Kaspersky Lab announced that Asus computer users were targeted last year with malware via Asus' update utility in a so-called "supply-chain attack."

Microsoft Expands Security Products and Adds Threat Protection for Macs

Microsoft this week announced a bunch of security product enhancements.

Microsoft Addresses Zero-Day Flaws in March Security Patch Release

Microsoft released security patches on "update Tuesday" to address 64 common vulnerabilities and exposures (CVEs), which were typically associated with products like Windows, Office services and Microsoft's browsers.

Google Issues Update for Zero-Day Flaw, But 32-Bit Windows 7 Systems Still Subject to Attack

Google on Thursday described two "zero-day" vulnerabilities affecting both the Google Chrome browser and Windows 7 systems that are being actively used in targeted attacks.

How To Grade Your Organization's Office 365 Security Level

With Office 365 emerging as a big target for today's hackers, it's important to know how your organization's security measures up.

Microsoft Adds Threat Intelligence to Azure Firewall

Microsoft added a few improvements to Azure Firewall, its firewall-as-a-service security offering for organizations using Azure virtual machines.

W3C Affirms WebAuthn Standard for Authentications Without Passwords

The World Wide Web Consortium (W3C) announced on Monday that the Web Authentication (WebAuthn) specification is now considered to be an official W3C standard, which likely will accelerate passwordless authentications for Web transactions.

Windows 7 Extended Security Updates Plan Available Next Month

Microsoft plans to start selling its Windows 7 Extended Security Updates plan to organizations on April 1, 2019, according to a Friday announcement.

Silver Pins

How To Control Your Microsoft Office Metadata

Metadata can say a lot about a given document -- as well as the document's creator. Here's how to manage what types metadata appear in your Office documents to protect your security while still giving useful information.

Windows Defender ATP Support for Windows 7 and Windows 8.1 Reaches 'General Availability'

The Windows Defender Advanced Threat Protection service can now be used to help address security issues with Windows 7 and Windows 8.1 clients.

Microsoft Issues Windows Server HTTP/2 Attack Advisory

Microsoft issued Security Advisory ADV190005 on Wednesday concerning a potential HTTP/2 settings issue for users of Internet Information Services (IIS) on Windows Server.

Microsoft Publishes Windows Deadlines on Upgrading to SHA-2

Microsoft on Friday described its 2019 timeline for when it will start distrusting Secure Hash Algorithm-1 (SHA-1) in supported Windows systems, as well as in the Windows Server Update Services 3.0 Service Pack 2 management product.

Vendors Issue Patches for Linux Container Runtime Flaw Enabling Host Attacks

This week, the National Institute of Standards and Technology (NIST) described a high-risk security vulnerability (CVE-2019-5736) for organizations using containers that could lead to compromised host systems.

Windows 10 Version 1809 Users May Get Visual Studio Crashes

Microsoft on Friday issued an advisory for Windows 10 version 1809 users about possible Visual Studio crashes.

Subscribe on YouTube