US Cybersecurity and Infrastructure Security Agency advisories on security updates – Chrome, Oracle, Drupal, Apple, Cisco and Atlassian

Patch now logo

CISA has issued advisories on the following: Google Releases Security Updates for Chrome | CISA Drupal Releases Security Update  | CISA Oracle Releases July 2022 Critical Patch Update | CISA Apple Releases Security Updates for Multiple Products | CISA – SANS had a good round-up of these updates here. Cisco …

Here’s something new from SANS – Apple Patches Everything Day”

software patches are essential cybersecurity

It does not have the same ring as “Patch Tuesday” but it gets the job done: Apple Patches Everything Day – SANS Internet Storm Centre There are patches and updates available across Apple’s platforms, MacOS versions Catalina, BigSur, and Monterey, tvOS, iOS, iPadOS and watchOS. These should all automatically install, …

More on Follina exploits including advice on how to protect your organisation – now executing in File Explorer preview pane… UPDATE 15 June 2022

Follina email phishing

This post was originally made on 9 June 2022 Update 15 June 2022 Microsoft has included updates in it’s Patch Tuesday bundle to address this issue: Microsoft Patch Tuesday – Follina zero-day fixed – Smart Thinking Solutions Get the updates done as soon as possible. Let’s hope this is really …

Active exploit for Follina – the still unpatched flaw in Microsoft Word

phishing email threat

Here is another excellent breakdown, with screen shots, of phishing emails exploiting the Microsoft Word/Follina/ms-msdt flaw. Being aware of the types of phishing emails the threat actors use is part of the defence in depth you need to have great cyber security. TA570 Qakbot (Qbot) tries CVE-2022-30190 (Follina) exploit (ms-msdt) …