Guild Wars 2 – Insecure Folder Permissions
from Exploit-DB.com RSS Feed https://ift.tt/2SUaItL
via IFTTT
Guild Wars 2 – Insecure Folder Permissions
from Exploit-DB.com RSS Feed https://ift.tt/2SUaItL
via IFTTT
NodeBB Forum 1.12.2-1.14.2 – Account Takeover
from Exploit-DB.com RSS Feed https://ift.tt/2GZbqDB
via IFTTT
The third-generation Xeon processors build in hardware security features to provide extra protection to data in transit, at rest, and in use.
from Dark Reading: https://ift.tt/2Iww1jd
via IFTTT
The National Institute of Standards and Technology’s first post-quantum cryptography standard will address key issues, approaches, an arms race, and the technology’s uncertain future.
from Dark Reading: https://ift.tt/3lKwPzd
via IFTTT
Bad actors have accessed US elections support systems, although there’s no evidence to suggest that election data has been compromised, say FBI and CISA
The post Attackers chain Windows, VPN flaws to target US government agencies appeared first on WeLiveSecurity
from WeLiveSecurity https://ift.tt/315UGkW
via IFTTT
No one has figured out how to run code with this bug yet – but if they do, you can bet that someone will turn it into a computer worm.
from Naked Security https://ift.tt/34TE553
via IFTTT
The October 2020 Patch Tuesday fixed 87 vulnerabilities, including 21 remote code execution flaws, in Microsoft products and services.
from Dark Reading: https://ift.tt/33T6CZ6
via IFTTT
The Five Eyes international law enforcement group had called for implementing backdoors for law enforcement in all encryption implementations.
from Dark Reading: https://ift.tt/313VneA
via IFTTT
It’s Cybersecurity Awareness Month! In keeping with that theme, if you (ab)use Microsoft Windows computers you should be aware the company shipped a bevy of software updates today to fix at least 87 security problems in Windows and programs that run on top of the operating system. That means it’s once again time to backup and patch up.

Eleven of the vulnerabilities earned Microsoft’s most-dire “critical” rating, which means bad guys or malware could use them to gain complete control over an unpatched system with little or no help from users.
Worst in terms of outright scariness is probably CVE-2020-16898, which is a nasty bug in Windows 10 and Windows Server 2019 that could be abused to install malware just by sending a malformed packet of data at a vulnerable system. CVE-2020-16898 earned a CVSS Score of 9.8 (10 is the most awful).
Security vendor McAfee has dubbed the flaw “Bad Neighbor,” and in a blog post about it said a proof-of-concept exploit shared by Microsoft with its partners appears to be “both extremely simple and perfectly reliable,” noting that this sucker is imminently “wormable” — i.e. capable of being weaponized into a threat that spreads very quickly within networks.
“It results in an immediate BSOD (Blue Screen of Death), but more so, indicates the likelihood of exploitation for those who can manage to bypass Windows 10 and Windows Server 2019 mitigations,” McAfee’s Steve Povolny wrote. “The effects of an exploit that would grant remote code execution would be widespread and highly impactful, as this type of bug could be made wormable.”
Trend Micro’s Zero Day Initiative (ZDI) calls special attention to another critical bug quashed in this month’s patch batch: CVE-2020-16947, which is a problem with Microsoft Outlook that could result in malware being loaded onto a system just by previewing a malicious email in Outlook.
“The Preview Pane is an attack vector here, so you don’t even need to open the mail to be impacted,” said ZDI’s Dustin Childs.
While there don’t appear to be any zero-day flaws in October’s release from Microsoft, Todd Schell from Ivanti points out that a half-dozen of these flaws were publicly disclosed prior to today, meaning bad guys have jump start on being able to research and engineer working exploits.
Other patches released today tackle problems in Exchange Server, Visual Studio, .NET Framework, and a whole mess of other core Windows components.
For any of you who’ve been pining for a Flash Player patch from Adobe, your days of waiting are over. After several months of depriving us of Flash fixes, Adobe’s shipped an update that fixes a single — albeit critical — flaw in the program that crooks could use to install bad stuff on your computer just by getting you to visit a hacked or malicious website.
Chrome and Firefox both now disable Flash by default, and Chrome and IE/Edge auto-update the program when new security updates are available. Mercifully, Adobe is slated to retire Flash Player later this year, and Microsoft has said it plans to ship updates at the end of the year that will remove Flash from Windows machines.
It’s a good idea for Windows users to get in the habit of updating at least once a month, but for regular users (read: not enterprises) it’s usually safe to wait a few days until after the patches are released, so that Microsoft has time to iron out any chinks in the new armor.
But before you update, please make sure you have backed up your system and/or important files. It’s not uncommon for a Windows update package to hose one’s system or prevent it from booting properly, and some updates even have known to erase or corrupt files.
So do yourself a favor and backup before installing any patches. Windows 10 even has some built-in tools to help you do that, either on a per-file/folder basis or by making a complete and bootable copy of your hard drive all at once.
And if you wish to ensure Windows has been set to pause updating so you can back up your files and/or system before the operating system decides to reboot and install patches on its own schedule, see this guide.
As always, if you experience glitches or problems installing any of these patches this month, please consider leaving a comment about it below; there’s a better-than-even chance other readers have experienced the same and may chime in here with some helpful tips.
from Krebs on Security https://ift.tt/3do7FDC
via IFTTT
Even if you can’t see your employees in the office, they still need to be reminded that criminals are always trying to spot a weak link in the chain.
from Dark Reading: https://ift.tt/3nMptgy
via IFTTT