The US government Cybersecurity and Infrastructure Security Agency (CISA) has added a number of products to its Known Exploited Vulnerabilities Catalog, including products from Microsoft, Red Hat, Arm and Google. Known Exploited Vulnerabilities Catalog | CISA Our penetration testing suite and this database is probably one of my most visited …
More Apple Out-0f-Band patches
These patches to iPadOS and iOS address an exploited vulnerability in WebRTC. About the security content of iOS 17.0.3 and iPadOS 17.0.3 – Apple Support Get them done – and check the rest of your team get them done as well.
Cyber Security and a Piece of Paper
It all starts with a bit of paper… There has been a lot of coverage of the Conservative Government’s on and off plans for HS2 – this article is not about that, but how this whole debate started. It started with a photograph of discussion papers that should not have …
Is this really my last word on passwords?
I am not sure it will be, but I think it does round off my Passwords Mini-series for the time being. Back to Basics – Passwords Passwords – Back to Basics Back to Basics – The Password Part 2 Back to Basics – The Password Keyboard Walk Part 3 Back …
Continue reading “Is this really my last word on passwords?”
A zero-day story. If you use or used MOVEit then you need to read this.
MOVEit is (was) a very popular software package used by many to “securely” share files both internally and between organisations. But it has a security flaw which was exploited by the Clop ransomware gang before Progress Software, the owners of MOVEit knew there was a problem – but by then …
Continue reading “A zero-day story. If you use or used MOVEit then you need to read this.”
