<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Allerts Archives - Resultworx</title>
	<atom:link href="https://resultworx.com/category/security-highlights/security-allerts/feed/" rel="self" type="application/rss+xml" />
	<link>https://resultworx.com/category/security-highlights/security-allerts/</link>
	<description></description>
	<lastBuildDate>Wed, 15 Nov 2023 18:15:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://resultworx.com/wp-content/uploads/2020/06/cropped-Favicon-32x32.png</url>
	<title>Security Allerts Archives - Resultworx</title>
	<link>https://resultworx.com/category/security-highlights/security-allerts/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Microsoft November 2023 Patch Tuesday fixes 5 zero-days, 58 flaws</title>
		<link>https://resultworx.com/microsoft-november-2023-patch-tuesday-fixes-5-zero-days-58-flaws/</link>
		
		<dc:creator><![CDATA[Pradeep P]]></dc:creator>
		<pubDate>Wed, 15 Nov 2023 18:15:17 +0000</pubDate>
				<category><![CDATA[Security Allerts]]></category>
		<category><![CDATA[Security Highlights]]></category>
		<guid isPermaLink="false">https://resultworx.com/?p=3427</guid>

					<description><![CDATA[<p>Microsoft&#8217;s November 2023 Patch Tuesday, which includes security updates for a total of 58 flaws and five zero-day vulnerabilities. While [&#8230;]</p>
<p>The post <a href="https://resultworx.com/microsoft-november-2023-patch-tuesday-fixes-5-zero-days-58-flaws/">Microsoft November 2023 Patch Tuesday fixes 5 zero-days, 58 flaws</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Microsoft&#8217;s November 2023 Patch Tuesday, which includes security updates for a total of 58 flaws and five zero-day vulnerabilities.</p>
<p>While fourteen remote code execution (RCE) bugs were fixed, Microsoft only rated one as critical. The three critical flaws fixed today are an Azure information disclosure bug, an RCE in Windows Internet Connection Sharing (ICS), and a Hyper-V escape flaw that allows the executions of programs on the host with SYSTEM privileges.</p>
<p>The number of bugs in each vulnerability category is listed below:</p>
<ul>
<li>16 Elevation of Privilege Vulnerabilities</li>
<li>6 Security Feature Bypass Vulnerabilities</li>
<li>15 Remote Code Execution Vulnerabilities</li>
<li>6 Information Disclosure Vulnerabilities</li>
<li>5 Denial of Service Vulnerabilities</li>
<li>11 Spoofing Vulnerabilities</li>
</ul>
<p>The total count of 58 flaws does not include 5 Mariner security updates and 20 Microsoft Edge security updates released earlier this month.</p>
<h2>Five zero-days fixed</h2>
<p>This month&#8217;s Patch Tuesday fixes five zero-day vulnerabilities, with three exploited in attacks and three publicly disclosed.</p>
<p>Microsoft classifies a vulnerability as a zero-day if it is publicly disclosed or actively exploited with no official fix available.</p>
<p>The three actively exploited zero-day vulnerabilities in today&#8217;s updates are:</p>
<p><strong><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2023-36036" target="_blank" rel="nofollow noopener">CVE-2023-36036</a> &#8211; Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability</strong></p>
<p>Microsoft has fixed an actively exploited Windows Cloud Files Mini Filter Elevation of Privileges bug.</p>
<p>&#8220;An attacker who successfully exploited this vulnerability could gain SYSTEM privileges,&#8221; explains Microsoft.</p>
<div id="bleepingcomputer_728x90_300x250__320x100_320x50_dynamic1" class="fs-dynamic" data-slot="complete" data-freestar-ad="__728x90  __554x312">
<div id="bleepingcomputer_728x90_300x250__320x100_320x50_dynamic1_slot" data-google-query-id="CIfG0M_DxoIDFc5KnQkdtbYOEw">
<p data-inc="1">It is not known how the flaw was abused in attacks or by what threat actor.</p>
<p>The flaw was discovered internally by the Microsoft Threat Intelligence Microsoft Security Response Center.</p>
<p><strong><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2023-36033" target="_blank" rel="nofollow noopener">CVE-2023-36033</a> &#8211; Windows DWM Core Library Elevation of Privilege Vulnerability</strong></p>
<p>Microsoft has fixed an actively exploited and publicly disclosed Windows DWM Core Library vulnerability that can be used to elevate privileges to SYSTEM.</p>
<p>&#8220;An attacker who successfully exploited this vulnerability could gain SYSTEM privileges,&#8221; explains Microsoft.</p>
<p>Microsoft says that the flaw was discovered by <a href="https://twitter.com/jq0904" target="_blank" rel="nofollow noopener">Quan Jin(@jq0904)</a> with <a href="https://www.dbappsecurity.com.cn/product/cloud250.html" target="_blank" rel="nofollow noopener">DBAPPSecurity WeBin Lab</a> but did not share details on how they were used in attacks.</p>
<p><strong><a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2023-36025" target="_blank" rel="nofollow noopener">CVE-2023-36025</a> &#8211; Windows SmartScreen Security Feature Bypass Vulnerability</strong></p>
<p>Microsoft has fixed an actively exploited Windows SmartScreen flaw that allows a malicious Internet Shortcut to bypass security checks and warnings.</p>
<p>&#8220;The attacker would be able to bypass Windows Defender SmartScreen checks and their associated prompts,&#8221; explains Microsoft.</p>
<p>&#8220;The user would have to click on a specially crafted Internet Shortcut (.URL) or a hyperlink pointing to an Internet Shortcut file to be compromised by the attacker,&#8221; continues Microsoft.</p>
<p>Microsoft says that the flaw was discovered by Will Metcalf (Splunk), Microsoft Threat Intelligence, and the Microsoft Office Product Group Security Team.</p>
<p>BleepingComputer contacted Splunk about the flaw to learn how it was exploited.</p>
<p data-inc="2">In addition, Microsoft says that two other publicly disclosed zero-day bugs, &#8216;CVE-2023-36413 &#8211; Microsoft Office Security Feature Bypass Vulnerability&#8217; and the &#8216;CVE-2023-36038 &#8212; ASP.NET Core Denial of Service Vulnerability,&#8217; were also fixed as part of today&#8217;s Patch Tuesday.</p>
<p>However, Microsoft says that they were not actively exploited in attacks.</p>
<p><strong>Original Posts:</strong> <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-november-2023-patch-tuesday-fixes-5-zero-days-58-flaws/" target="_blank" rel="noopener">Microsoft November 2023 Patch Tuesday fixes 5 zero-days, 58 flaws</a></p>
</div>
</div>
<p>The post <a href="https://resultworx.com/microsoft-november-2023-patch-tuesday-fixes-5-zero-days-58-flaws/">Microsoft November 2023 Patch Tuesday fixes 5 zero-days, 58 flaws</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Google Chrome to warn when installed extensions are malware</title>
		<link>https://resultworx.com/google-chrome-to-warn-when-installed-extensions-are-malware/</link>
		
		<dc:creator><![CDATA[Pradeep P]]></dc:creator>
		<pubDate>Mon, 21 Aug 2023 19:24:40 +0000</pubDate>
				<category><![CDATA[Security Allerts]]></category>
		<category><![CDATA[Security Highlights]]></category>
		<guid isPermaLink="false">https://resultworx.com/?p=3407</guid>

					<description><![CDATA[<p>Google is testing a new feature in the Chrome browser that will warn users when an installed extension has been [&#8230;]</p>
<p>The post <a href="https://resultworx.com/google-chrome-to-warn-when-installed-extensions-are-malware/">Google Chrome to warn when installed extensions are malware</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Google is testing a new feature in the Chrome browser that will warn users when an installed extension has been removed from the Chrome Web Store, usually indicative of it being malware.</p>
<p>An unending supply of unwanted browser extensions is published on the Chrome Web Store and promoted through popup and redirect ads.</p>
<p>These extensions are made by scam companies and threat actors who use them to inject advertisements, track your search history, redirect you to affiliate pages, or in more severe cases, steal your Gmail emails and Facebook accounts</p>
<p>The problem is that these extensions are churned out quickly, with the developers releasing new ones just as Google removes old ones from the Chrome Web Store.</p>
<p>Unfortunately, if you installed one of these extensions, they will still be installed in your browser, even after Google detects them as malware and removes them from the store.</p>
<p>Due to this, Google is now bringing its Safety Check feature to browser extensions, warning Chrome users when an extension has been detected as malware or removed from the store and that they should be uninstalled from the browser.</p>
<p>This feature will go live in Chrome 117, but you can now test it in Chrome 116 by enabling the browser&#8217;s experimental &#8216;Extensions Module in Safety Check&#8217; feature.</p>
<p>To enable the feature, simply copy the Chrome URL, &#8216;chrome://flags/#safety-check-extensions&#8217;, into the address bar and press enter. You will be brought to the Chrome Flags page with the &#8216;Extensions Module in Safety Check&#8217; feature highlighted.</p>
<p>Now set it to enabled and restart the browser when prompted to enable the feature.</p>
<h2>Google Chrome Safety Check for extensions</h2>
<p>Once enabled, a new option will appear under the &#8216;Privacy and security&#8217; settings page that prompts you to review any extensions removed from the Chrome Web Store, as shown below.</p>
<div>
<figure class="image"><img fetchpriority="high" decoding="async" src="https://www.bleepstatic.com/images/news/web-browsers/chrome/safety-check-extensions/safety-check.jpg" alt="Safety check for Chrome extensions" width="904" height="600" /><figcaption><strong>Safety check for Chrome extensions</strong><br />
<em>Source: Google</em></figcaption></figure>
</div>
<p>Clicking this link will bring you to your extension page, listing the removed extensions and why they were removed and prompting you to uninstall them.</p>
<div>
<figure class="image"><img decoding="async" src="https://www.bleepstatic.com/images/news/web-browsers/chrome/safety-check-extensions/chrome-bad-extensions.jpg" alt="Potentially malicious extensions removed from Chrome Web Store" width="904" height="499" /><figcaption><strong>Potentially malicious extensions removed from Chrome Web Store</strong><br />
<em>Source: Google</em></figcaption></figure>
</div>
<p data-inc="1">Google says that extensions can be removed from the Chrome Web Store because they were unpublished by the developer, violated policies, or were detected as malware.</p>
<p>For extensions detected as malware, it is strongly advised that you remove them immediately to not only protect your data but also to prevent your computer from facing future attacks.</p>
<p>For those that are removed for other reasons, it is advised that you remove them as well, as they are no longer supported or break other policies that are not strictly malware but are not necessarily helpful.</p>
<p>Google has a dedicated <a href="https://developer.chrome.com/docs/webstore/program-policies/" target="_blank" rel="nofollow noopener">Chrome Web Store policies</a> page detailing what content or behavior could lead to an extension being removed from the store.</p>
<div class="cz-related-article-wrapp"><strong>Original Posts:</strong> <a href="https://www.bleepingcomputer.com/news/google/google-chrome-to-warn-when-installed-extensions-are-malware/" target="_blank" rel="noopener">Google Chrome to warn when installed extensions are malware</a></div>
<p>The post <a href="https://resultworx.com/google-chrome-to-warn-when-installed-extensions-are-malware/">Google Chrome to warn when installed extensions are malware</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Google to fight hackers with weekly Chrome security updates</title>
		<link>https://resultworx.com/google-to-fight-hackers-with-weekly-chrome-security-updates/</link>
		
		<dc:creator><![CDATA[Pradeep P]]></dc:creator>
		<pubDate>Fri, 11 Aug 2023 17:31:44 +0000</pubDate>
				<category><![CDATA[Security Allerts]]></category>
		<category><![CDATA[Security Highlights]]></category>
		<guid isPermaLink="false">https://resultworx.com/?p=1419</guid>

					<description><![CDATA[<p>Google has changed the Google Chrome security updates schedule from bi-weekly to weekly to address the growing patch gap problem [&#8230;]</p>
<p>The post <a href="https://resultworx.com/google-to-fight-hackers-with-weekly-chrome-security-updates/">Google to fight hackers with weekly Chrome security updates</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Google has changed the Google Chrome security updates schedule from bi-weekly to weekly to address the growing patch gap problem that allows threat actors extra time to exploit published n-day and zero-day flaws.</p>
<p>This new schedule will start with Google Chrome 116, scheduled for release today.</p>
<p>Google explains that Chromium is an open-source project, allowing anyone to view its source code and scrutinize developer discussions, commits, and fixes made by contributors in real time.</p>
<p>These changes, fixes, and security updates are then added to Chrome&#8217;s development releases (Beta/Canary), where they are tested for stability, performance, or compatibility issues before they can be pushed to the stable Chrome release.</p>
<p>However, this transparency comes with a cost, as it also allows advanced threat actors to identify flaws before fixes reach a massive user base of stable Chrome releases and exploit them in the wild.</p>
<p>&#8220;Bad actors could possibly take advantage of the visibility into these fixes and develop exploits to apply against browser users who haven&#8217;t yet received the fix,&#8221; reads Google&#8217;s announcement.</p>
<p>&#8220;This exploitation of a known and patched security issue is referred to as n-day exploitation.&#8221;</p>
<p>The patch gap is the time it takes a security fix to be released for testing and for it to finally be pushed out to the main population in public releases of software.</p>
<p>Google identified the problem years ago when the patch gap averaged 35 days, and in 2020. With the release of Chrome 77, it switched to biweekly updates to try to reduce this number.</p>
<p>With the switch to weekly stable updates, Google further minimizes the patch gap and reduces the window of n-day exploitation opportunity to a single week.</p>
<p>While this is definitely a step in the right direction and will positively affect Chrome security, it&#8217;s essential to underline that it&#8217;s not ideal in the sense that it won&#8217;t stop all n-day exploitation.</p>
<p data-inc="1">Reducing the interval between updates will stop the exploitation of flaws that demand more complex exploitation paths, which in turn require more time to develop.</p>
<p>However, there are some vulnerabilities for which malicious actors can build an effective exploit using known techniques, and these cases will remain a problem.</p>
<p>Even in those cases, though, active exploitation will still be reduced to a maximum of seven days in the worst-case scenario, given that users apply security updates as soon as they become available.</p>
<p>&#8220;Not all security bug fixes are used for n-day exploitation. But we don’t know which bugs are exploited in practice, and which aren&#8217;t, so we treat all critical and high severity bugs as if they will be exploited,&#8221; explains Chrome Security Team member Amy Ressler.</p>
<p>&#8220;A lot of work goes into making sure these bugs get triaged and fixed as soon as possible.&#8221;</p>
<p>&#8220;Rather than having fixes sitting and waiting to be included in the next bi-weekly update, weekly updates will allow us to get important security bug fixes to you sooner, and better protect you and your most sensitive data.&#8221;</p>
<p>Ultimately, the new update frequency will decrease the need for unplanned updates, enabling users and system administrators to adhere to a more consistent security maintenance schedule.</p>
<p>The vulnerability patch gap has also become a massive problem for Android, with Google recently warning that n-day flaws have become as dangerous as zero-days.</p>
<p>Unfortunately, the Android ecosystem makes it much harder for Google to control, as in many cases, a patch will be released, and it will take manufacturers months to introduce it into their phone&#8217;s operating systems.</p>
<p><strong>Original Posts:</strong> <a href="https://www.bleepingcomputer.com/news/google/google-to-fight-hackers-with-weekly-chrome-security-updates/" target="_blank" rel="noopener">Google to fight hackers with weekly Chrome security updates</a></p>
<p>The post <a href="https://resultworx.com/google-to-fight-hackers-with-weekly-chrome-security-updates/">Google to fight hackers with weekly Chrome security updates</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Windows 11 KB5028254 update fixes VPN performance issues, 27 bugs</title>
		<link>https://resultworx.com/windows-11-kb5028254-update-fixes-vpn-performance-issues-27-bugs/</link>
		
		<dc:creator><![CDATA[Pradeep P]]></dc:creator>
		<pubDate>Fri, 28 Jul 2023 18:58:26 +0000</pubDate>
				<category><![CDATA[Security Allerts]]></category>
		<category><![CDATA[Security Highlights]]></category>
		<guid isPermaLink="false">https://resultworx.com/?p=1363</guid>

					<description><![CDATA[<p>Microsoft has released the July 2023 optional cumulative update for Windows 11, version 22H2, with fixes for 27 issues, including [&#8230;]</p>
<p>The post <a href="https://resultworx.com/windows-11-kb5028254-update-fixes-vpn-performance-issues-27-bugs/">Windows 11 KB5028254 update fixes VPN performance issues, 27 bugs</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Microsoft has released the July 2023 optional cumulative update for Windows 11, version 22H2, with fixes for 27 issues, including ones affecting VPN performance and display or audio devices.</p>
<p>KB5028254 is a monthly non-security preview release that allows Windows administrators and users to test improvements included in the upcoming August 2023 Patch Tuesday release.</p>
<p>According to Microsoft, it addresses issues causing audio and display devices to disappear after the systems resume from sleep.</p>
<p>&#8220;There might be excessive Address Resolution Protocol (ARP) requests to the network gateway,&#8221; Redmond <a href="https://support.microsoft.com/en-us/topic/july-26-2023-kb5028254-os-build-22621-2070-preview-66161ea6-c106-43e9-bef5-8410ccbd34e8" target="_blank" rel="nofollow noopener">says</a>.</p>
<p>&#8220;This occurs when the VPN is on a wireless mesh network that uses an aggressive throttling algorithm. Because of this, network performance is poor.&#8221;</p>
<p>This update also makes brightness settings more accurate and ensures that Widgets no longer unpin from the Windows taskbar unexpectedly.</p>
<p>It&#8217;s also important to note that this monthly &#8220;C&#8221; update is optional and, unlike Patch Tuesday releases, does not include any security-related fixes.</p>
<p>To install KB5028254, you can go to Settings &gt; Windows Update, where they will find the &#8216;Download and install&#8217; button after checking for updates.</p>
<p>You can also download the update from the <a href="https://www.catalog.update.microsoft.com/Search.aspx?q=KB5028254" target="_blank" rel="nofollow noopener">Microsoft Update Catalog</a> and install it manually. After installing this update, Windows 11 22H2 will be updated to build 22621.2070.</p>
<h2>​​​​Other highlights in Windows 11 KB5028254</h2>
<p>Today&#8217;s preview release comes with additional fixes and improvements, with some of the most significant ones outlined below:</p>
<ul>
<li>This update addresses an issue in the Windows Notification Platform. The issue affects how much power your device uses.</li>
<li>This update affects user mode printer drivers. They unload unexpectedly. This occurs when you print from multiple print queues to the same printer driver.</li>
<li>This update affects the Windows Kernel Vulnerable Driver Blocklist, DriverSiPolicy.p7b. It adds drivers that are at risk for Bring Your Own Vulnerable Driver (BYOVD) attacks.</li>
<li>This update addresses an issue that affects Windows Defender Application Control (WDAC). The issue copies unsigned WDAC policies to the Extensible Firmware Interface (EFI) disk partition. This partition is reserved for signed policies.</li>
</ul>
<p>The complete list of fixes and improvements can be found in the <a href="https://support.microsoft.com/en-us/topic/july-26-2023-kb5028254-os-build-22621-2070-preview-66161ea6-c106-43e9-bef5-8410ccbd34e8" target="_blank" rel="nofollow noopener">KB5028254 support bulletin</a> published by Microsoft.</p>
<h2>​​​​Other highlights in Windows 11 KB5028254</h2>
<p>Today&#8217;s preview release comes with additional fixes and improvements, with some of the most significant ones outlined below:</p>
<ul>
<li>This update addresses an issue in the Windows Notification Platform. The issue affects how much power your device uses.</li>
<li>This update affects user mode printer drivers. They unload unexpectedly. This occurs when you print from multiple print queues to the same printer driver.</li>
<li>This update affects the Windows Kernel Vulnerable Driver Blocklist, DriverSiPolicy.p7b. It adds drivers that are at risk for Bring Your Own Vulnerable Driver (BYOVD) attacks.</li>
<li>This update addresses an issue that affects Windows Defender Application Control (WDAC). The issue copies unsigned WDAC policies to the Extensible Firmware Interface (EFI) disk partition. This partition is reserved for signed policies.</li>
</ul>
<p>The complete list of fixes and improvements can be found in the KB5028254 support bulletin published by Microsoft today.</p>
<p><strong>Original Posts:</strong> <a href="https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5028254-update-fixes-vpn-performance-issues-27-bugs/" target="_blank" rel="noopener">Windows 11 KB5028254 update fixes VPN performance issues, 27 bugs</a></p>
<p>The post <a href="https://resultworx.com/windows-11-kb5028254-update-fixes-vpn-performance-issues-27-bugs/">Windows 11 KB5028254 update fixes VPN performance issues, 27 bugs</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Apple rolls out important iOS 16.6 update to fix many security issues, recommends users to install it</title>
		<link>https://resultworx.com/apple-rolls-out-important-ios-16-6-update-to-fix-many-security-issues-recommends-users-to-install-it/</link>
		
		<dc:creator><![CDATA[Pradeep P]]></dc:creator>
		<pubDate>Tue, 25 Jul 2023 17:11:57 +0000</pubDate>
				<category><![CDATA[Security Allerts]]></category>
		<category><![CDATA[Security Highlights]]></category>
		<guid isPermaLink="false">https://resultworx.com/?p=1359</guid>

					<description><![CDATA[<p>Apple has commenced the rollout of iOS 16.6 and iPadOS 16.6, the latest software updates for iPhone and iPad. These [&#8230;]</p>
<p>The post <a href="https://resultworx.com/apple-rolls-out-important-ios-16-6-update-to-fix-many-security-issues-recommends-users-to-install-it/">Apple rolls out important iOS 16.6 update to fix many security issues, recommends users to install it</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Apple has commenced the rollout of iOS 16.6 and iPadOS 16.6, the latest software updates for iPhone and iPad. These updates bring essential fixes for vulnerabilities impacting Apple&#8217;s Neural Engine, and kernel-level patches addressing flaws that could potentially compromise the security of some devices. Additionally, Apple has also pushed macOS 13.5, watchOS 9.6, and tvOS 16.6 updates, all of which contain significant security fixes. Here is all we know.</p>
<p data-t="{&quot;n&quot;:&quot;blueLinks&quot;}">With the latest updates, users can now download the latest software on their compatible devices. Apple strongly recommends users to update their devices due to the critical security fixes included in these updates. To do this, users simply need to open the Settings app, visit the General section &gt; Software Update &gt; Download and Install.</p>
<p data-t="{&quot;n&quot;:&quot;blueLinks&quot;}">The most recent updates from Apple include essential security patches for vulnerabilities linked to the Neural Engine, which is responsible for natural language processing and on-device machine learning. These patches effectively prevent malicious code from being executed on the device through apps. Additionally, the Find My app has been fortified with fixes that safeguard sensitive location information from being accessed by unauthorized apps.</p>
<p class="continue-read-break" data-t="{&quot;n&quot;:&quot;blueLinks&quot;}">People also need to download macOS 13.5 update as it brings vital security measures to fix vulnerabilities that could enable a sandboxed process to bypass security restrictions or allow unauthorized access to user-sensitive data with the help of the Voice Memos app.</p>
<p class="" tabindex="-1" data-t="{&quot;n&quot;:&quot;blueLinks&quot;}" aria-expanded="true">Furthermore, Apple has also rolled out updates to fix multiple vulnerabilities affecting WebKit, which is the company&#8217;s open-source browser engine powering Safari. The WebKit fixes are crucial in preventing malicious code execution and the disclosure of sensitive information when the browser processes web content.</p>
<p class="" tabindex="-1" data-t="{&quot;n&quot;:&quot;blueLinks&quot;}" aria-expanded="true">Apple has taken particular notice of reports claiming that some people are taking advantage of such security issues. In light of this, the company emphasizes that users with compatible iPhone, iPad, Mac, Apple Watch, and Apple TV models should immediately download and install the updates to shield themselves from potential security breaches.</p>
<p class="" tabindex="-1" data-t="{&quot;n&quot;:&quot;blueLinks&quot;}" aria-expanded="true">In conclusion, the rollout of iOS 16.6, iPadOS 16.6, macOS 13.5, watchOS 9.6, and tvOS 16.6 provides critical security fixes for various vulnerabilities across Apple&#8217;s software ecosystem. Users are urged to update their devices promptly to protect themselves from potential security threats and take advantage of the latest improvements and enhancements.</p>
<p tabindex="-1" data-t="{&quot;n&quot;:&quot;blueLinks&quot;}" aria-expanded="true"><strong>Original Posts</strong>: <a href="https://www.msn.com/en-in/money/news/apple-rolls-out-important-ios-16-6-update-to-fix-many-security-issues-recommends-users-to-install-it/ar-AA1ejLeL?ocid=msedgntp&amp;cvid=01adb488ba784e068d29364e5545b6cb&amp;ei=12" target="_blank" rel="noopener">Apple rolls out important iOS 16.6 update to fix many security issues, recommends users to install it</a></p>
<p>The post <a href="https://resultworx.com/apple-rolls-out-important-ios-16-6-update-to-fix-many-security-issues-recommends-users-to-install-it/">Apple rolls out important iOS 16.6 update to fix many security issues, recommends users to install it</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Hackers exploiting critical WordPress WooCommerce Payments bug</title>
		<link>https://resultworx.com/hackers-exploiting-critical-wordpress-woocommerce-payments-bug/</link>
		
		<dc:creator><![CDATA[Pradeep P]]></dc:creator>
		<pubDate>Wed, 19 Jul 2023 17:23:59 +0000</pubDate>
				<category><![CDATA[Security Allerts]]></category>
		<category><![CDATA[Security Highlights]]></category>
		<guid isPermaLink="false">https://resultworx.com/?p=1353</guid>

					<description><![CDATA[<p>Hackers are conducting widespread exploitation of a critical WooCommerce Payments plugin to gain the privileges of any users, including administrators, [&#8230;]</p>
<p>The post <a href="https://resultworx.com/hackers-exploiting-critical-wordpress-woocommerce-payments-bug/">Hackers exploiting critical WordPress WooCommerce Payments bug</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Hackers are conducting widespread exploitation of a critical WooCommerce Payments plugin to gain the privileges of any users, including administrators, on vulnerable WordPress installation.</p>
<p>WooCommerce Payments is a very popular WordPress plugin allowing websites to accept credit and debit cards as payment in WooCommerce stores. According to <a href="https://wordpress.org/plugins/woocommerce-payments/" target="_blank" rel="nofollow noopener">WordPress</a>, the plugin is used on over 600,000 active installations.</p>
<p>On March 23rd, 2023, the <a href="https://developer.woocommerce.com/2023/03/23/critical-vulnerability-detected-in-woocommerce-payments-what-you-need-to-know/" target="_blank" rel="nofollow noopener">developers released</a> version 5.6.2 to fix the critical 9.8-rated vulnerability tracked as CVE-2023-28121. The flaw affects WooCommerce Payment plugin versions 4.8.0 and higher, with it being fixed in versions 4.8.2, 4.9.1, 5.0.4, 5.1.3, 5.2.2, 5.3.1, 5.4.1, 5.5.2, 5.6.2, and later.</p>
<p>As the vulnerability allows any remote user to impersonate an administrator and take complete control over a WordPress site, Automattic force installed the security fix of WordPress installations utilizing the plugin.</p>
<p>At the time, WooCommerce said there was no known active exploitation of the vulnerability, but researchers warned that due to the critical nature of the bug, we would likely see exploitation in the future.</p>
<h2>Flaw actively exploited</h2>
<p>This month, researchers at RCE Security analyzed the bug and released a <a href="https://www.rcesecurity.com/2023/07/patch-diffing-cve-2023-28121-to-compromise-a-woocommerce/" target="_blank" rel="nofollow noopener">technical blog</a> on the CVE-2023-28121 vulnerability and how it can be exploited.</p>
<p>The researchers explain that attackers can simply add an &#8216;<em>X-WCPAY-PLATFORM-CHECKOUT-USER</em>&#8216; request header and set it to the user ID of the account they wish to impersonate.</p>
<p>When WooCommerce Payments sees this header, it will treat the request as if it was from the specified user ID, including all of the user&#8217;s privileges.</p>
<p>As part of the blog post, RCE Security released a proof-of-concept exploit that uses this flaw to create a new admin user on vulnerable WordPress sites, making it easy for threat actors to take complete control over the site.</p>
<div>
<figure class="image"><img decoding="async" src="https://www.bleepstatic.com/images/news/security/vulnerabilities/w/woocommerce/woocommerce-payments/CVE-2023-28121%20/woocommerce-payments-auth-bypass-4%5B1%5D.png" alt="Using the exploit to create the 'hacked' administrator account" width="1219" height="400" /><figcaption><strong>Using the exploit to create the &#8216;hacked&#8217; administrator account</strong><br />
<em>Source: RCE Security</em></figcaption></figure>
</div>
<p>Today, WordPress security firm Wordfence warned that threat actors are exploiting this vulnerability in a massive campaign targeting over 157,000 sites by Saturday.</p>
<p>&#8220;Large-scale attacks against the vulnerability, assigned CVE-2023-28121, began on Thursday, July 14, 2023 and continued over the weekend, peaking at 1.3 million attacks against 157,000 sites on Saturday, July 16, 2023,&#8221; explains <a href="https://www.wordfence.com/blog/2023/07/massive-targeted-exploit-campaign-against-woocommerce-payments-underway/?utm_medium=email&amp;_hsmi=266639985&amp;_hsenc=p2ANqtz-8AxrS0jQ-RkxVtD0SfniOq77V_8TP6U08rEjcEDj_b8n3bXW3pcEeNGxsBvY58nI-AEfYwqBRm9q3Xeub5y8sJZSw9rzqT5rAlvdnt2riEjE_XnEc&amp;utm_content=266639985&amp;utm_source=hs_email" target="_blank" rel="nofollow noopener">Wordfence</a>.</p>
<p data-inc="1">Wordfence says the threat actors use the exploit to install the <a href="https://wordpress.org/plugins/wp-console/" target="_blank" rel="nofollow noopener">WP Console plugin</a> or create administrator accounts on the targeted device.</p>
<p>For those systems that WP Console was installed, the threat actors used the plugin to execute PHP code that installs a file uploader on the server that can be used as a backdoor even after the vulnerability is fixed.</p>
<div>
<figure class="image"><img loading="lazy" decoding="async" src="https://www.bleepstatic.com/images/news/security/vulnerabilities/w/woocommerce/woocommerce-payments/CVE-2023-28121%20/wordfence-wp-console-backdoor.jpg" alt="Exploit to drop a PHP file uploaded on WordPress sites" width="887" height="350" /><figcaption><strong>Exploit to drop a PHP file uploaded on WordPress sites</strong><br />
<em>Source: Wordfence</em></figcaption></figure>
</div>
<p>Wordfence says they have seen other attackers using the exploit to create administrator accounts with random passwords.</p>
<p>To scan for vulnerable WordPress sites, the threat actors try to access the &#8216;/wp-content/plugins/woocommerce-payments/readme.txt&#8217; file, and if it exists, they exploit the flaw.</p>
<p>The researchers have shared seven IP addresses responsible for these attacks, with IP address 194.169.175.93 scanning 213,212 sites.</p>
<p>Due to the ease with which CVE-2023-28121 can be exploited, it is strongly advised that all sites utilizing the WooCommerce Payment plugin ensure that their installations are up-to-date.</p>
<p>If you have not updated your installation recently, it is also advised that site admins scan their sites for unusual PHP files and suspicious administrator accounts and delete any that are found.</p>
<p>&nbsp;</p>
<p><strong>Original Posts:</strong> <a href="https://www.bleepingcomputer.com/news/security/hackers-exploiting-critical-wordpress-woocommerce-payments-bug/" target="_blank" rel="noopener">Hackers exploiting critical WordPress WooCommerce Payments bug</a></p>
<p>The post <a href="https://resultworx.com/hackers-exploiting-critical-wordpress-woocommerce-payments-bug/">Hackers exploiting critical WordPress WooCommerce Payments bug</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Apple re-releases zero-day patch after fixing browsing issue</title>
		<link>https://resultworx.com/apple-re-releases-zero-day-patch-after-fixing-browsing-issue/</link>
		
		<dc:creator><![CDATA[Pradeep P]]></dc:creator>
		<pubDate>Fri, 14 Jul 2023 17:47:03 +0000</pubDate>
				<category><![CDATA[Security Allerts]]></category>
		<category><![CDATA[Security Highlights]]></category>
		<guid isPermaLink="false">https://resultworx.com/?p=1350</guid>

					<description><![CDATA[<p>Apple fixed and re-released emergency security updates addressing a WebKit zero-day vulnerability exploited in attacks. The initial patches had to be [&#8230;]</p>
<p>The post <a href="https://resultworx.com/apple-re-releases-zero-day-patch-after-fixing-browsing-issue/">Apple re-releases zero-day patch after fixing browsing issue</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Apple fixed and re-released emergency security updates addressing a WebKit zero-day vulnerability exploited in attacks. The initial patches had to be withdrawn on Monday due to browsing issues on certain websites.</p>
<p>&#8220;Apple is aware of an issue where recent Rapid Security Responses might prevent some websites from displaying properly,&#8221; Apple said on Tuesday.</p>
<p>The company added it would soon release fixed versions of the buggy updates and advised customers to remove them if they were experiencing issues while browsing the web after updating.</p>
<p>While Apple did not share why some websites were prevented from rendering correctly after installing the iOS 16.5.1 (a), iPadOS 16.5.1 (a), and macOS 13.4.1 (a) updates, this likely happened because the new Safari user agent containing an &#8220;(a)&#8221; string prevented websites from detecting it as a valid version of Safari, causing it to display &#8220;browser not supported&#8221; error messages.</p>
<p>Today, Apple started pushing iOS 16.5.1 (c), iPadOS 16.5.1 (c), and macOS 13.4.1 (c) Security Response updates that address the web browsing issues.</p>
<p>Apple uses RSR patches to address security issues impacting iPhone, iPad, and Mac devices and to quickly patch vulnerabilities actively exploited in attacks between major OS releases.</p>
<div style="text-align: center;">
<figure class="image"><img loading="lazy" decoding="async" src="https://www.bleepstatic.com/images/news/u/1109292/2023/Fixed%20macOS%20Security%20Response%20update.png" alt="Fixed macOS Security Response update" width="609" height="400" /><figcaption><em>Fixed macOS Security Response update </em></figcaption></figure>
</div>
<p>The zero-day flaw (CVE-2023-37450) patched today impacts the WebKit browser engine, and it allows attackers to gain arbitrary code execution by tricking targets into opening maliciously crafted web pages.</p>
<p>&#8220;This Rapid Security Response provides important security fixes and is recommended for all users,&#8221; Apple warns customers on devices where these emergency patches are delivered.</p>
<p>&#8220;Apple is aware of a report that this issue may have been actively exploited,&#8221; the company says in <a href="https://support.apple.com/en-us/HT213823" target="_blank" rel="nofollow noopener">iOS</a> and <a href="https://support.apple.com/en-us/HT213825" target="_blank" rel="nofollow noopener">macOS</a> security advisories describing the CVE-2023-37450 flaw patched in today&#8217;s re-released emergency security updates.</p>
<p>Since the start of 2023, the company addressed a total of ten zero-day flaws exploited in the wild to hack iPhones, Macs, or iPads.</p>
<p>&nbsp;</p>
<p><strong>Original Posts:</strong> <a href="https://www.bleepingcomputer.com/news/apple/apple-re-releases-zero-day-patch-after-fixing-browsing-issue/" target="_blank" rel="noopener">Apple re-releases zero-day patch after fixing browsing issue</a></p>
<p>The post <a href="https://resultworx.com/apple-re-releases-zero-day-patch-after-fixing-browsing-issue/">Apple re-releases zero-day patch after fixing browsing issue</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Chinese hackers breach email of Commerce Secretary Raimondo and State Department officials</title>
		<link>https://resultworx.com/chinese-hackers-breach-email-of-commerce-secretary-raimondo-and-state-department-officials/</link>
		
		<dc:creator><![CDATA[Pradeep P]]></dc:creator>
		<pubDate>Thu, 13 Jul 2023 18:58:47 +0000</pubDate>
				<category><![CDATA[Security Allerts]]></category>
		<category><![CDATA[Security Highlights]]></category>
		<guid isPermaLink="false">https://resultworx.com/?p=1347</guid>

					<description><![CDATA[<p>The State Department discovered the Microsoft vulnerability, which affected unclassified government systems, last month Chinese cyberspies, exploiting a fundamental gap [&#8230;]</p>
<p>The post <a href="https://resultworx.com/chinese-hackers-breach-email-of-commerce-secretary-raimondo-and-state-department-officials/">Chinese hackers breach email of Commerce Secretary Raimondo and State Department officials</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2 class="font--subhead font-light offblack mb-sm pb-xxs-ns subheadline" data-qa="subheadline">The State Department discovered the Microsoft vulnerability, which affected unclassified government systems, last month</h2>
<p>Chinese cyberspies, exploiting a fundamental gap in Microsoft’s cloud, hacked email accounts at the Commerce and State departments, including that of Commerce Secretary Gina Raimondo — whose agency has imposed stiff <a href="https://www.washingtonpost.com/national-security/2022/12/15/china-military-tech-export-ban/?itid=lk_inline_manual_2" target="_blank" rel="noopener">export controls</a> on Chinese technologies that Beijing has denounced as a malicious attempt to suppress its companies.</p>
<div class="teaser-content grid-center">
<div class="article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">Raimondo is the only known Cabinet-level official to have their account compromised in the targeted cyberespionage campaign, according to U.S. officials familiar with the matter, who spoke on the condition of anonymity due to the matter’s sensitivity.</p>
</div>
</div>
<div>The breaches have been mitigated, officials said, but an FBI investigation continues.</div>
<div data-qa="article-body"></div>
<div class="article-body" data-qa="article-body">The Microsoft vulnerability was discovered last month by the State Department. Also targeted were the email accounts of a congressional staffer, a U.S. human rights advocate, and U.S. think tanks, officials and security professionals said. State and Commerce were the only two executive branch agencies known to be breached, officials said.</div>
<div data-qa="article-body">
<div class="article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">The hackers, looking for information useful to the Chinese government, had access to the email accounts for about a month before the issue was discovered and access cut off, said officials. The intrusion was discovered around the time of Secretary of State Antony Blinken’s <a href="https://www.washingtonpost.com/national-security/2023/06/17/blinken-china-trip/?itid=lk_inline_manual_9" target="_blank" rel="noopener">trip to Beijing</a>.</p>
</div>
<div class="article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">“U.S. government safeguards identified an intrusion in Microsoft’s cloud security, which affected unclassified systems,” National Security Council spokesman Adam Hodges said in a statement Tuesday to The Washington Post. “Officials immediately contacted Microsoft to find the source and vulnerability in their cloud service. We continue to hold the procurement providers of the U.S. government to a high security threshold.”</p>
</div>
<div class="article-body" data-qa="article-body">A senior FBI official said that no classified information was taken and that there was no evidence that the hackers got anywhere except the inboxes. He said the government was not yet attributing the attack to any country or group but would seek to “impose costs” on the adversary.</div>
</div>
<div data-qa="article-body"></div>
<div data-qa="article-body">A senior Department of Homeland Security official said that nine organizations were victimized in the United States, with a small number of email accounts compromised at each. Microsoft said a total of about 25 organizations worldwide were hacked.</div>
<div data-qa="article-body"></div>
<div data-qa="article-body">Since taking office, the Biden administration has moved to limit the export of U.S. technologies that it says can aid China’s aggressive military modernization, surveillance capabilities and deployment of weapons of mass destruction. Such controls are overseen by the Commerce Department, which has also placed Chinese companies on export blacklists.</div>
<div data-qa="article-body">
<div data-qa="article-body"></div>
<div class="article-body" data-qa="article-body">The administration is preparing an expansion of export controls as well as new restrictions on Chinese investment in advanced technologies. Given the forward role that these tools are playing in the administration’s strategy to compete with China, Beijing sees Raimondo as a “particularly important target … to understand her personal views,” said Emily Kilcrease, senior fellow at the Center for a New American Security and an economic security official at the Commerce Department in the Obama and Trump administrations.</div>
<div class="article-body" data-qa="article-body">
<div class="article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">Microsoft <a href="https://blogs.microsoft.com/on-the-issues/2023/07/11/mitigation-china-based-threat-actor/" target="_blank" rel="noopener">disclosed late Tuesday</a> that it had mitigated an attack by “a China-based threat actor” that primarily targets government agencies in Western Europe and focuses on espionage and data theft.</p>
</div>
<div class="article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">The Redmond, Wash.-based tech giant said the hackers, whom the firm calls Storm-0558, gained access on May 15. They did this by using forged authentication tokens to access user email using “an acquired Microsoft account consumer signing key,” according to a blog written by Charlie Bell, Microsoft’s executive vice president of security.</p>
</div>
<div class="article-body" data-qa="article-body">The hackers could create that key only with a more powerful internal key controlled by Microsoft, said Adam Meyers, senior vice president of CrowdStrike, suggesting that Microsoft itself had been hacked or compromised by an insider.</div>
<div class="article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">U.S. officials said they were investigating how the signing keys were obtained from Microsoft, which did not respond to written questions from The Post. “That is an area of urgent focus,” said the DHS official.</p>
<p dir="null" data-testid="drop-cap-letter" data-el="text">“This attack used a stolen key that Microsoft’s design failed to properly validate,” said Jason Kikta, chief information security officer at Automox and former head of private sector partnerships at U.S. Cyber Command. “The inability to do proper validation for authentication is a habit, not an anomaly.”</p>
<div class="article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">Microsoft has completed its mitigation of the attack for all customers, Bell wrote in the blog.</p>
</div>
<div class="article-body" data-qa="article-body">“There are some hard questions they have to answer,” though, said the person familiar with the matter.</div>
<div class="article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">The State Department discovered the intrusion on June 16 and notified the company the same day, officials said. The diplomatic agency is a favorite target for foreign spy services. Russian government hackers have breached its networks at least twice, in 2014 and during the 2020 Solar Winds campaign.</p>
<div class="article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">In the latter incident, Russian hackers <a href="https://www.washingtonpost.com/business/2021/03/01/solarwinds-sec-inquiry/?itid=lk_inline_manual_33" target="_blank" rel="noopener">accessed U.S. government email accounts</a> after exploiting software made by a Texas company called SolarWinds. Once inside a target network, the hackers exploited weaknesses in Microsoft’s system for authenticating users, using tokens that would improperly give them the same access as an administrator.</p>
</div>
<div class="article-body" data-qa="article-body">
<p><span class="wpds-c-gnhuPA wpds-c-gnhuPA-hqeSyH-variant-interstitial wpds-c-gnhuPA-iPJLV-css hide-for-print"><a href="https://www.washingtonpost.com/national-security/russia-hack-microsoft-cloud/2020/12/24/dbfaa9c6-4590-11eb-975c-d17b8815a66d_story.html?itid=lk_interstitial_manual_34" data-qa="interstitial-link">Russian hackers compromised Microsoft cloud customers through third party</a></span></p>
</div>
<div class="article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">Officials stressed the latest breach was much narrower than the SolarWinds breach, which officials say affected nearly a dozen U.S. agencies.</p>
</div>
<div class="article-body" data-qa="article-body">In early 2021, Microsoft found that its Exchange email servers were also subject to widespread exploitation, this time by Chinese hackers using a separate flaw.</div>
<div class="article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">Further underscoring Microsoft’s continuing security woes, the company confirmed Tuesday that its validation procedure had been manipulated to digitally sign dozens of pieces of software. And in <a href="https://www.microsoft.com/en-us/security/blog/2023/07/11/storm-0978-attacks-reveal-financial-and-espionage-motives/" target="_blank" rel="noopener">yet a third incident</a>, it warned that Russian actors it blames for espionage and financial crimes were exploiting a previously unknown vulnerability in its Office program.</p>
<div class="article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">After the SolarWinds hack, Microsoft President Brad Smith <a href="https://www.reuters.com/article/us-cyber-solarwinds/solarwinds-microsoft-fireeye-cro[%E2%80%A6]defend-actions-in-major-hack-u-s-senate-hearing-idUSKBN2AN1Q4" target="_blank" rel="noopener">testified to the Senate</a> that its code had not been vulnerable, instead blaming customers for common configuration mistakes and poor controls, including cases “where the keys to the safe and the car were left out in the open.”</p>
</div>
<div class="article-body" data-qa="article-body">Homeland Security officials complained that basic security tools, such as the ability to review logs, were available only at more expensive tiers of service.</div>
<div class="article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">Following the SolarWinds fiasco, Microsoft agreed to provide more log access free to government customers. It was that capability that allowed the government to identify the latest intrusion, the DHS official said.</p>
</div>
<div class="article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">Not everyone had that visibility, however.</p>
</div>
<div class="article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">“It is our perspective that every organization using a technology service like Microsoft 365 should have access to logging and other security data out of the box,” said the DHS official.</p>
</div>
<div class="article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">The latest incident strengthens the administration’s hand as it pushes for cloud and software providers to be held more accountable for security failings, a key part of its <a href="https://www.whitehouse.gov/wp-content/uploads/2023/03/National-Cybersecurity-Strategy-2023.pdf" target="_blank" rel="noopener">National Cybersecurity Strategy</a>.</p>
</div>
<div class="article-body" data-qa="article-body">
<p class="wpds-c-cYdRxM wpds-c-cYdRxM-iPJLV-css overrideStyles font-copy" dir="null" data-testid="drop-cap-letter" data-el="text">The U.S. government has already tightened cybersecurity rules for vendors whose software and hardware it uses.</p>
</div>
<p dir="null" data-testid="drop-cap-letter" data-el="text"><strong>Original Posts:</strong> <a href="https://www.washingtonpost.com/national-security/2023/07/12/microsoft-hack-china/" target="_blank" rel="noopener">Chinese hackers breach U.S. government email through Microsoft cloud</a></p>
</div>
</div>
</div>
</div>
</div>
<div data-qa="article-body"></div>
<div data-qa="article-body"></div>
<p>The post <a href="https://resultworx.com/chinese-hackers-breach-email-of-commerce-secretary-raimondo-and-state-department-officials/">Chinese hackers breach email of Commerce Secretary Raimondo and State Department officials</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Apps with 1.5M installs on Google Play send your data to China</title>
		<link>https://resultworx.com/apps-with-1-5m-installs-on-google-play-send-your-data-to-china/</link>
		
		<dc:creator><![CDATA[Pradeep P]]></dc:creator>
		<pubDate>Fri, 07 Jul 2023 18:29:33 +0000</pubDate>
				<category><![CDATA[Security Allerts]]></category>
		<category><![CDATA[Security Highlights]]></category>
		<guid isPermaLink="false">https://resultworx.com/?p=1343</guid>

					<description><![CDATA[<p>Security researchers discovered two malicious file management applications on Google Play with a collective installation count of over 1.5 million [&#8230;]</p>
<p>The post <a href="https://resultworx.com/apps-with-1-5m-installs-on-google-play-send-your-data-to-china/">Apps with 1.5M installs on Google Play send your data to China</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Security researchers discovered two malicious file management applications on Google Play with a collective installation count of over 1.5 million that collected excessive user data that goes well beyond what&#8217;s needed to offer the promised functionality.</p>
<p>The apps, both from the same publisher, can launch without any interaction from the user to steal sensitive data and send it to servers in China.</p>
<p>Despite being reported to Google, the two apps continue to be available in Google Play at the time of publishing.</p>
<div>
<figure class="image"><img decoding="async" class="" style="width: 100%; height: 100%;" src="https://www.bleepstatic.com/images/news/u/1220909/2023/Android/21/apps.jpg" alt="The two spyware apps discovered by Pradeo" width="100%" height="100%" /><figcaption><strong>Malicious apps still in Google Play</strong> </figcaption></figure>
</div>
<p>File Recovery and Data Recovery, identified as &#8220;com.spot.music.filedate&#8221; on devices, has at least 1 million installs. The install count for File Manager reads at least 500,000 and it can be identified on devices as  &#8220;com.file.box.master.gkd.&#8221;</p>
<p>The two apps were discovered by the behavioral analysis engine from mobile security solutions company Pradeo and their description states that they do not collect any user data from the device on the Data Safety section of their Google Play entry</p>
<div style="text-align: center;">
<figure class="image"><img decoding="async" class="" style="width: 100%; height: 100%;" src="https://www.bleepstatic.com/images/news/u/1220909/2023/Android/21/data-collection.jpg" alt="Data collection declaration on Google Play" width="100%" height="100%" /><figcaption><strong>Data collection declaration on Google Play</strong></figcaption></figure>
</div>
<p>However, <a href="https://blog.pradeo.com/spyware-tied-china-found-google-play-store" target="_blank" rel="nofollow noopener">Pradeo found</a> that the mobile apps exfiltrate the following data from the device:</p>
<ul>
<li>Users&#8217; contact list from on-device memory, connected email accounts, and social networks.</li>
<li>Pictures, audio, and video that are managed or recovered from within the applications.</li>
<li>Real-time user location</li>
<li>Mobile country code</li>
<li>Network provider name</li>
<li>Network code of the SIM provider</li>
<li>Operating system version number</li>
<li>Device brand and model</li>
</ul>
<p>While the apps might have a legitimate reason to collect some of the above to ensure good performance and compatibility, much of the collected data is not necessary for file management or data recovery functions. To make matters worse, this data is collected secretly and without gaining the user&#8217;s consent.</p>
<p>Pradeo adds that the two apps hide their home screen icons to make it more difficult to find and remove them. They can also abuse the permissions the user approves during installation to restart the device and launch in the background.</p>
<p>It is likely that the publisher used emulators or install farms to bloat popularity and make their products appear more trustworthy, Pradeo speculates.</p>
<p>This theory is supported by the fact that the number of user reviews on the Play store is way too small compared to the reported userbase.</p>
<p>It is always recommended to check user reviews before installing an app, pay attention to the requested permissions during app installation, and only trust software published by reputable developers.</p>
<p><em>Update 7/6/23 5:51 PM ET: </em>Google shared the following statement with BleepingComputer and said that they removed the apps from Google Play.</p>
<p>&nbsp;</p>
<p><strong>Original Posts:</strong> <a href="https://www.bleepingcomputer.com/news/security/apps-with-15m-installs-on-google-play-send-your-data-to-china/" target="_blank" rel="noopener">Apps with 1.5M installs on Google Play send your data to China</a></p>
<p>The post <a href="https://resultworx.com/apps-with-1-5m-installs-on-google-play-send-your-data-to-china/">Apps with 1.5M installs on Google Play send your data to China</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cisco fixes AnyConnect bug giving Windows SYSTEM privileges</title>
		<link>https://resultworx.com/cisco-fixes-anyconnect-bug-giving-windows-system-privileges/</link>
		
		<dc:creator><![CDATA[Pradeep P]]></dc:creator>
		<pubDate>Wed, 07 Jun 2023 21:46:07 +0000</pubDate>
				<category><![CDATA[Security Allerts]]></category>
		<category><![CDATA[Security Highlights]]></category>
		<guid isPermaLink="false">https://resultworx.com/?p=1307</guid>

					<description><![CDATA[<p>Cisco has fixed a high-severity vulnerability found in Cisco Secure Client (formerly AnyConnect Secure Mobility Client) software that can let [&#8230;]</p>
<p>The post <a href="https://resultworx.com/cisco-fixes-anyconnect-bug-giving-windows-system-privileges/">Cisco fixes AnyConnect bug giving Windows SYSTEM privileges</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Cisco has fixed a high-severity vulnerability found in Cisco Secure Client (formerly AnyConnect Secure Mobility Client) software that can let attackers escalate privileges to the SYSTEM account used by the operating system.</p>
<p>Cisco Secure Client enables employees to work from anywhere via a secure Virtual Private Network (VPN) and provides admins with endpoint management and telemetry features.</p>
<p>Low-privileged, local attackers can exploit this security flaw (tracked as CVE-2023-20178) in low-complexity attacks that don&#8217;t require user interaction</p>
<p>&#8220;This vulnerability exists because improper permissions are assigned to a temporary directory that is created during the upgrade process,&#8221; Cisco says.</p>
<p>&#8220;An attacker could exploit this vulnerability by abusing a specific function of the Windows installer process.&#8221;</p>
<p>The bug was fixed in AnyConnect Secure Mobility Client for Windows 4.10MR7 and Cisco Secure Client for Windows 5.0MR2.</p>
<p>According to Cisco, CVE-2023-20178 doesn&#8217;t impact the following macOS, Linux, and mobile products:</p>
<ul>
<li>Cisco AnyConnect Secure Mobility Client for Linux</li>
<li>Cisco AnyConnect Secure Mobility Client for MacOS</li>
<li>Cisco Secure Client-AnyConnect for Android</li>
<li>Cisco Secure Client AnyConnect VPN for iOS</li>
<li>Cisco Secure Client for Linux</li>
<li>Cisco Secure Client for MacOS</li>
</ul>
<h2>No signs of active exploitation</h2>
<p>The company&#8217;s Product Security Incident Response Team (PSIRT) is yet to find any evidence of malicious use in the wild or public exploit code targeting the bug.</p>
<p>In October, Cisco <a href="https://www.bleepingcomputer.com/news/security/cisco-warns-admins-to-patch-anyconnect-flaws-exploited-in-attacks/" target="_blank" rel="noopener">warned customers</a> to patch two other AnyConnect security flaws—with public exploit code and addressed three years ago—due to in-the-wild exploitation.</p>
<p>The bugs (CVE-2020-3433 and CVE-2020-3153) let threat actors execute arbitrary code on targeted Windows devices with SYSTEM privileges when chained with other privilege escalation flaws.</p>
<p>As CISA also <a href="https://www.cisa.gov/uscert/ncas/current-activity/2022/10/24/cisa-adds-six-known-exploited-vulnerabilities-catalog" target="_blank" rel="nofollow noopener">said</a> when adding them to its list of known exploited bugs, &#8220;these types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.&#8221;</p>
<p>Two years ago, Cisco <a href="https://www.bleepingcomputer.com/news/security/cisco-fixes-6-month-old-anyconnect-vpn-zero-day-with-exploit-code/" target="_blank" rel="noopener">patched an AnyConnect zero-day</a> (CVE-2020-3556) with public exploit code in May 2021 with a six-month delay after providing mitigation measures to decrease the attack surface when it was disclosed<a href="https://www.bleepingcomputer.com/news/security/cisco-discloses-anyconnect-vpn-zero-day-exploit-code-available/" target="_blank" rel="noopener"> in November 2020</a>.</p>
<p>&nbsp;</p>
<p><strong>Original Posts:</strong> <a href="https://www.bleepingcomputer.com/news/security/cisco-fixes-anyconnect-bug-giving-windows-system-privileges/" target="_blank" rel="noopener">Cisco fixes AnyConnect bug giving Windows SYSTEM privileges</a></p>
<p>The post <a href="https://resultworx.com/cisco-fixes-anyconnect-bug-giving-windows-system-privileges/">Cisco fixes AnyConnect bug giving Windows SYSTEM privileges</a> appeared first on <a href="https://resultworx.com">Resultworx</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
