Security Updates & Patches

Securezoo Cybersecurity Threat Center blog posts of new security updates and patches.

Microsoft April 2020 Security Updates (with fixes for 2 zero-days)

Microsoft released the April 2020 Security Updates that includes 113 unique vulnerability fixes, 18 of those rated critical. The updates also include patches for two Adobe Font Manager zero day vulnerabilities disclosed in March.

Microsoft April 2020 Security Updates (with fixes for 2 zero-days) Read More »

Oracle Critical Patch Update for April 2020

Oracle has released its Critical Patch Update for April 2020 to include 297 vulnerability fixes across multiple products. The company also continues to receive reports of remote attackers attempting to maliciously exploit unpatched vulnerabilities.

Oracle Critical Patch Update for April 2020 Read More »

FBI warns of video-teleconferencing hijacking “Zoom-bombing”

As the COVID-19 crisis continues to spread, larger numbers of enterprises and learning organizations are moving meetings and classrooms online via video-teleconferencing (VTC) platforms. The FBI has issued a new warning of recent VTC attacks and also offered guidance on how to better security VTC platforms.

FBI warns of video-teleconferencing hijacking “Zoom-bombing” Read More »

APT41 launches broad cyber campaign with multiple exploits

Researchers from FireEye have discovered Chinese cyber threat group APT41 carry out a broad cyber campaign between January 20 and March 11, 2020. The actors have attempted to exploit vulnerabilities in Citrix NetScaler/ADC, Cisco routers, and Zoho ManageEngine Desktop Central products against 75 FireEye customers.

APT41 launches broad cyber campaign with multiple exploits Read More »

Microsoft issues advisory for two zero-day RCE vulnerabilities exploited in the wild (updated)

Microsoft has issued a new security advisory for two remote code execution (RCE) vulnerabilities in Adobe Type Manager (ATM) Library exploited in the wild. Microsoft also published several workarounds to reduce risk until a patch is rolled out.

Microsoft issues advisory for two zero-day RCE vulnerabilities exploited in the wild (updated) Read More »