Microsoft’s Patch Tuesday bundle for this month is a big one: 74 documented vulnerabilities in multiple Windows products and components, some serious enough to lead to remote code execution attacks.
Adobe Patches ‘Critical’ Security Flaws in Illustrator, After Effects
Software maker Adobe on Tuesday shipped urgent security updates to fix code execution vulnerabilities in the widely deployed Illustrator and After Effects products.
Medical, IoT Devices From Many Manufacturers Affected by ‘Access:7’ Vulnerabilities
Many IoT and medical devices are affected by seven potentially serious vulnerabilities discovered in widely used remote management software, according to enterprise security company Forescout.
Webinar Today: Protect the Software Supply Chain, Eliminate Risks in Code
U.S. State Governments Targeted by Chinese Hackers via Zero-Day in Agriculture Tool
A threat group believed to be sponsored by the Chinese government has breached the networks of U.S. state governments, including through the exploitation of a zero-day vulnerability.
CISA Urges Organizations to Patch Recent Firefox Zero-Days
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday announced the inclusion of 11 security holes in its Known Exploited Vulnerabilities Catalog.
Millions of APC Smart UPS Devices Can Be Remotely Hacked, Damaged
Uninterruptible power supply (UPS) products made by Schneider Electric subsidiary APC are affected by critical vulnerabilities that can be exploited to remotely hack and damage devices, according to enterprise device security company Armis.
Android’s March 2022 Security Updates Patch 39 Vulnerabilities
Google this week announced the release of patches for 39 vulnerabilities as part of the March 2022 security update for Android.
The most serious vulnerability is CVE-2021-39708, a remotely exploitable elevation of privilege issue identified in the System component.
Emergency Firefox Update Patches Two Actively Exploited Zero-Day Vulnerabilities
Mozilla over the weekend issued an emergency security update for Firefox to address two zero-day vulnerabilities that have been exploited in attacks.
CISA Informs Organizations of Flaws in Unsupported Industrial Telecontrol Devices
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) last week released an advisory to inform organizations about potentially serious vulnerabilities affecting ipDIO telecontrol communication devices that are no longer supported by the vendor.













