Security Leftovers
-
Install Latest Windows Update ASAP! Patches Issued for 6 Actively Exploited Zero-Days [Ed: Delete Windows. Microsoft knew about these flaws and did not patch until it was too late and they were actively exploited a lot (at least 4 such holes, based on CISA)]
Microsoft's latest round of monthly security updates has been released with fixes for 68 vulnerabilities spanning its software portfolio, including patches for six actively exploited zero-days. 12 of the issues are rated Critical, two are rated High, and 55 are rated Important in severity.
-
VMware Warns of 3 New Critical Flaws Affecting Workspace ONE Assist Software [Ed: Proprietary software again; VMware cannot keep blaming "FOSS" for its shoddy software's holes]
VMware has patched five security flaws affecting its Workspace ONE Assist solution, some of which could be exploited to bypass authentication and obtain elevated permissions.
Topping the list, are three critical vulnerabilities tracked as CVE-2022-31685, CVE-2022-31686, and CVE-2022-31687. All the shortcomings are rated 9.8 on the CVSS vulnerability scoring system.
-
They See Me Roaming: Following APT29 by Taking a Deeper Look at Windows Credential Roaming [Ed: Microsoft as national security threat and a major liability]
In early 2022, Mandiant detected and responded to an incident where APT29 successfully phished a European diplomatic entity and ultimately abused the Windows Credential Roaming feature. The diplomatic-centric targeting is consistent with Russian strategic priorities as well as historic APT29 targeting. Mandiant has been tracking APT29—a Russian espionage group that is sponsored by the Foreign Intelligence Service (SVR)—since at least 2014. Some APT29 activity is also publicly referred to as Nobelium by Microsoft.
-
Patches for 6 zero-days under active exploit are now available from Microsoft [Ed: Microsoft and security are opposites]
It’s the second Tuesday of the month, and that means it’s Update Tuesday, the monthly release of security patches available for nearly all software Microsoft supports. This time around, the software maker has fixed six zero-days under active exploit in the wild, along with a wide range of other vulnerabilities that pose a threat to end users.