Category Archives: Security

First supply chain attack on open source software targeting banks discovered

Security researchers say they have discovered the first attack on the open source software supply chain specifically targeting the banking sector. That's according to a report published by Checkmarx on July 21, 2023. On April 5 and 7, a threat … Continue reading →

Posted in Security | Tagged | Leave a comment

Apple security updates for iOS, macOS (July 24, 2023)

Small addendum from this week, already on July 24, 2023 Apple has released a slew of updates for the Safari browser, for iOS on iPhones and iPadOS for the iPads. In addition, there are updates for macOS, Apple TV and … Continue reading →

Posted in ios, macOS, Security, Software | Tagged , , | Leave a comment

Sophos UTM Firewall: Update closes CVE-2023-0286, CVE-2023-0215 (OpenSSL) and more

Vendor Sophos has released an update to UTM Up2date 9.716 for its UTM firewall, which is intended to fix a number of vulnerabilities CVE-2023-0286, CVE-2023-0215, CVE-2002-20001, CVE-2022-40735, CVE-2002-20001, CVE-2022-40735, CVE-2023-3367, CVE-2002-20001, CVE-2022-40735 as well as various bugs. The vulnerabilities affect … Continue reading →

Posted in Security, Software, Update | Tagged , , | Leave a comment

Privilege escalation vulnerability CVE-2023-30799 in MikroTik routers, patch urgently

In case you haven't noticed, MikroTik RouterOS Stable before version 6.49.7 and in the long-term version up to 6.48.6 contains a vulnerability CVE-2023-30799 that allows an attacker to escalate privileges, but the attacker must be authenticated. However, he can then … Continue reading →

Posted in Security | Tagged | Leave a comment

Patch your Ivanti EPMM – Norwegian government hacked via 0-day

[German]Administrators should ugently patch its Ivanti EPMM used in their environment, because older version contains a 0-day vulnerability. In Norway, the ICT platform (information and communications system) on which 12 ministries operate was attacked via this 0-day vulnerability.

Posted in Security | Tagged , | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


Atlassian updates Confluence and Bambo due to critical vulnerabilities

[German]Another addendum from July 18, 2023 – that's when vendor Atlassian released its security bulletin for July 2023. Vulnerabilities in Confluence Data Center & Server (CVE-2023-22505 and CVE-2023-22508) and Bamboo Data Center (CVE-2023-22506) have become public. An attacker can exploit … Continue reading →

Posted in Security, Software | Tagged , | Leave a comment

Outlook blocks hyperlinks after July 2023 update; a workaround from Microsoft

[German]Since installing the July 11, 2023 security updates that closed a Security Feature Bypass vulnerability in Outlook, some users can no longer use hyperlinks without restrictions. Either a warning comes up or the hyperlinks no longer work. Now Microsoft has … Continue reading →

Posted in issue, Office, Security, Software, Update | Tagged , | 4 Comments

Super Mario Game Installer Spreads SupremeBot Malware

[German]Another small addendum in terms of security. At the end of June 2023, security researchers from Cyble issued a warning about a Super Mario Game installer. Security researchers have come across a corresponding installer that contains a Trojan and spreads … Continue reading →

Posted in Security, Software | Tagged , | Leave a comment

Edge 114.0.1823.90 and 115.0.1901.183

[German]Microsoft has updated the Edge browser to version 1114.0.1823.90 as of July 21, 2023, as well as released version 115.0.1901.183 (thanks to the reader for the tip). They are security updates that fix bugs and vulnerabilities.

Posted in browser, Security, Update | Tagged | Leave a comment

Stolen AAD key allowed (Storm-0558) wide-ranging access to Microsoft cloud services

[German]Microsoft had to admit on begin of July 2023 that suspected Chinese hackers from the Storm-0558 group were able to forge security tokens using a stolen private MSA key. Then then gain broad access to Microsoft cloud services, as Wiz … Continue reading →

Posted in Cloud, Security | Tagged , , | Leave a comment