Showing posts with label updates. Show all posts
Showing posts with label updates. Show all posts

Friday, August 19, 2022

Safeguard iPhones, iPads & Macs: Apply security updates now. Microsoft 365 Basic Authentication ends October 1, 2022

Safeguard your iPhones, iPads and Macs: Apply these security updates now

Apple urges users to patch their devices as newly disclosed vulnerabilities 'may have been actively exploited'.

There are reports that Apple products to include iPhones, iPads and Macs are actively being targeted by hackers due to a series of vulnerabilities in the IOS's of the devices.

In the wake of the heightened political tensions with state actors as well as plain old criminal hackers, it would be wise to apply Apple's latest security updates to your devices ASAP.

To read the more click on the following link,

https://www.zdnet.com/article/safeguard-your-iphones-ipads-and-macs-apply-these-security-updates-now/?ftag=TRE-03-10aaa6b&bhid=%7B%24external_id%7D&mid=%7B%24MESSAGE_ID%7D&cid=%7B%24contact_id%7D


Microsoft is turning off Basic Authentication for Exchange Online customers.

On October 1, 2022, Microsoft is turning off Basic Authentication in Exchange Online for all tenants.

If you have Microsoft Exchange as part of your Microsoft Office subscription, you need to enable MFA, Multi-Factor Authentication.  This will require you to receive a code either via email or cell phone each time you login to http://office.com.

In addition, a secured password will be required for any desktop email app such as Outlook or Mozilla Thunderbird.

As more sophisticated cyber criminals take aim at hybrid and remote workers, Microsoft is working to raise awareness among Exchange Online customers that one of the most important security steps they can take is to move away from outdated, less secure protocols, like Basic Authentication.

Basic Authentication puts companies at greater risk of data breaches and disruption of email. There are 921 password attacks every second, almost doubling the frequency of attacks from 2021. In addition, the FBI’s Internet Crime Complaint Center (IC3) received 19,954 business email compromise (BEC) and email account compromise (EAC) complaints with adjusted losses at nearly USD2.4 billion.

To read more, click on the following link:

It's Time to Disable Basic Authentication in Office 365  - Office 365 Reports (o365reports.com)


Other security news:

Reported ransomware attacks are just the tip of the iceberg. That's a problem for everyone

Shame or just trying to avoid bad publicity means there's very little useful data recorded on ransomware attacks.

https://www.zdnet.com/article/reported-ransomware-attacks-are-just-the-tip-of-the-iceberg-thats-a-problem-for-everyone/?ftag=TRE-03-10aaa6b&bhid=%7B%24external_id%7D&mid=%7B%24MESSAGE_ID%7D&cid=%7B%24contact_id%7D


Federal courts hit by "significant and sophisticated" cyberattack in 2020

https://www.zdnet.com/article/federal-courts-hit-by-significant-and-sophisticated-cyber-attack-in-2020/


TikTok 'Kia Challenge' fuels rise in using USB cables to steal cars

https://www.insider.com/tiktok-kia-challenge-using-usb-cables-to-steal-cars-2022-7


Warning: Malicious browser extension targets Gmail and AOL users

https://www.komando.com/security-privacy/malicious-browser-extension/848631/


How to find and remove spyware from your phone

Surveillance apps are becoming more advanced. Here's what to do if you think you're being tracked.

https://www.zdnet.com/article/how-to-find-and-remove-spyware-from-your-phone/







Wednesday, February 12, 2020

Security Updates: Last night was Update Tuesday, Microsoft's February 2020 Patch Tuesday fixes 99 security bugs

Microsoft's February 2020 Patch Tuesday fixes 99 security bugs

The second Tuesday of each month has become known as Patch Tuesday.  Microsoft released yesterday the February 2020 Patch Tuesday security updates. This month's updates include fixes for a whopping 99 vulnerabilities, making this Microsoft's biggest Patch Tuesday known to date.

With the possible combination and variety of installed programs not to mention a myriad of hardware configurations, issues are always a possibility.  Many users postpone updates, however, if possible install updates when available.  The internet is criminal infested and users and their info are under constant assault whether by Google, Alphabet, Facebook, and others gathering information discretely about you or criminals trying to steal your financial information.  There are many legit firms who collect your information and sell it to marketers and then they are hacked and your info is stolen along with millions of others.

On January 17, Microsoft disclosed ongoing attacks where hackers were using this IE zero-day, however, at the time, the OS maker could not provide a patch. This patch is now included with this month's cumulative security updates.

Read about this important update the following link;

https://www.zdnet.com/article/microsofts-february-2020-patch-tuesday-fixes-99-security-bugs/?ftag=TREc64629f&bhid=2219791


Wednesday, September 25, 2019

Microsoft releases Emergency Security Update, please update ASAP

Microsoft releases out-of-band security update to fix IE zero-day Defender bug

Generally, Microsoft releases updates on the 2nd Tuesday of each month.  However an emergency update was issued yesterday by Microsoft and it is urging Windows users to install these updates as soon as possible.

The updates patch 2 bugs, one an Internet Explorer zero-day bug is the most serious and has already been exploited in active attacks in the wild.

The attack requires luring an Internet Explorer user on a malicious website, which is a rather trivial task, as it can be achieved by various methods such as spam email, IM spam, search engine ads, malvertising campaigns, and others.

for more details about this and the other bug fix, click on the following link;

https://www.zdnet.com/article/microsoft-releases-out-of-band-security-update-to-fix-ie-zero-day-defender-bug/?ftag=TRE-03-10aaa6b&bhid=2219791


TEST