More stories

  • in

    Microsoft March 2020 Patch Tuesday fixes 115 vulnerabilities

    Microsoft has released today its monthly roll-up of security updates known as Patch Tuesday. This month, the Redmond-based company patched 115 vulnerabilities, marking this month’s patches as the biggest in the company’s history. However, despite this month’s pretty bulky release, nobody will be talking about it today. Instead, they’ll be busy talking about how a […] More

  • in

    Details about new SMB wormable bug leak in Microsoft Patch Tuesday snafu

    Image: Geralt on Pixabay Details about a new “wormable” vulnerability in the Microsoft Server Message Block (SMB) protocol have accidentally leaked online today during the preamble to Microsoft’s regular Patch Tuesday update cycle. No technical details have been published, but short summaries describing the bug have been posted on the websites of two cyber-security firms, […] More

  • in

    Microsoft orchestrates coordinated takedown of Necurs botnet

    Microsoft announced today a coordinated takedown of Necurs, one of the largest spam and malware botnets known to date, believed to have infected more than nine million computers worldwide. The takedown effort came after Microsoft and industry partners broke the Necurs DGA — the botnet’s domain generation algorithm, the component that generates random domain names. […] More

  • in

    Intel CPUs vulnerable to new LVI attacks

    Today, a team of academics from universities across the world, along with vulnerability researchers from Bitdefender, have disclosed a new security flaw in Intel processors. Named Load Value Injection, or LVI for short, this is a new class of theoretical attacks against Intel CPUs. While the attack has been deemed only a theoretical threat, Intel […] More

  • in

    Avast AntiTrack certificate bug allowed others to snoop on your online activities

    A vulnerability impacting Avast and AVG AntiTrack privacy software opened up user PCs to Man-in-The-Middle (MiTM) attacks, browser session hijack, and data theft.  Disclosed by David Eade on March 9, the security researcher said the security flaw, tracked as CVE-2020-8987, is a certification validation issue that affects Avast AntiTrack before 1.5.1.172 and AVG AntiTrack before […] More