Categories
Technology

Apple fixes two new iOS zero-days in emergency updates

Apple released emergency security updates to fix two zero-day vulnerabilities exploited in attacks and impacting iPhone, iPad, and Mac devices, reaching 20 zero-days patched since the start of the year.
Categories
Technology

Windows Hello auth bypassed on Microsoft, Dell, Lenovo laptops

Security researchers bypassed Windows Hello fingerprint authentication on Dell Inspiron, Lenovo ThinkPad, and Microsoft Surface Pro X laptops in attacks exploiting security flaws found in the embedded fingerprint sensors.
Categories
Technology

Discord will switch to temporary file links to block malware delivery

Discord will switch to temporary CDN links for all users by the end of the year to block attackers from using its content delivery network for malware delivery.
Categories
Technology

Microsoft plans to kill off NTLM authentication in Windows 11

Microsoft announced earlier this week that the NTLM authentication protocol will be killed off in Windows 11 in the future.
Categories
Technology

Microsoft 365 admins warned of new Google anti-spam rules

Microsoft urged Microsoft 365 email senders this week to authenticate outbound messages following new anti-spam rules for bulk senders announced earlier this week by Google.
Categories
Technology

Microsoft releases new, faster Teams app for Windows and Mac PCs

A new, redesigned, and faster Microsoft Teams application is generally available for all Windows and macOS users starting today.
Categories
Technology

Iranian hackers breach US aviation org via Zoho, Fortinet bugs

State-backed hacking groups have breached a U.S. aeronautical organization using exploits targeting critical Zoho and Fortinet vulnerabilities, a joint advisory published by CISA, the FBI, and the United States Cyber Command (USCYBERCOM) revealed on Thursday.
Categories
Technology

Apple zero-click iMessage exploit used to infect iPhones with spyware

Citizen Lab says two zero-days fixed by Apple today in emergency security updates were actively abused as part of a zero-click exploit chain to deploy NSO Group's Pegasus commercial spyware onto fully patched iPhones.
Categories
Technology

Apple discloses 2 new zero-days exploited to attack iPhones, Macs

Apple released emergency security updates to fix two new zero-day vulnerabilities exploited in attacks targeting iPhone and Mac users, for a total of 13 exploited zero-days patched since the start of the year.
Categories
Technology

Hackers stole Microsoft signing key from Windows crash dump

Microsoft says Storm-0558 Chinese hackers stole a signing key used to breach government email accounts from a Windows crash dump after compromising a Microsoft engineer's corporate account.