Zero-day threat using Microsoft Office documents – even if macros are disabled – it’s called Follina

Office macros slide

I have written about the usefulness and the threat that Microsoft Office document macros can pose to your cyber security. This flaw, called Follina, exploits Office functionality to retrieve an HTML file, and Microsoft Support Diagnostic Tool (MSDT) to run some malicious code, which can lead to privilege escalation attacks. …

Ransomware targets VMware

A new malware strain known as Cheerscrypt or Cheers, is targeting a VMware enterprise virtualisation tool – VMware ESXi systems. Ransomware Cheerscrypt targets VMware ESXi systems • The Register

CISA security advisories

These Cybersecurity and Infrastructure Security Agency advisories, cover a number of packages – possibly the one of most interest is Drupal – a popular website content manager, similar to WordPress. Drupal Releases Security Updates | CISA Citrix Releases Security Updates for ADC and Gateway | CISA

More vulnerabilities to be aware of… Including Microsoft, Adobe, Linux and Google Chrome

software patches are essential cybersecurity

The US Cybersecurity and Infrastructure Security Agency is having a busy week of updating it’s Known Exploited Vulnerabilities Catalog: CISA Adds 34 Known Exploited Vulnerabilities to Catalog | CISA Microsoft and Adobe figure strongly on the list today but there are other products there – go and check. There is …

Twenty more known vulnerabilities added to the CISA database

software patches are essential cybersecurity

Following yesterday’s post, more vulnerabilities have been added to the Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities Catalog. Yesterday: Twenty-one additions to the known exploited database! – Smart Thinking Solutions Today: CISA Adds 20 Known Exploited Vulnerabilities to Catalog | CISA Microsoft, Apple and Cisco figure highly among …