April 2019

Microsoft April 2019 Security Updates, patches two 0-days

Microsoft issued the April 2019 Security Updates that include 74 unique vulnerability fixes, 16 of them rated critical and two zero-days that were being actively exploited.

Microsoft April 2019 Security Updates, patches two 0-days Read More »

Apache Web Server “Carpe Diem” vulnerability update

The Apache Foundation has patched a high severity privilege escalation vulnerability in Apache HTTP Server 2.4 (releases 2.4.17 to 2.4.38). Web servers should be patched as soon as possible since the bug could allow attackers a way to gain “root” or full admin access to server.

Apache Web Server “Carpe Diem” vulnerability update Read More »

CIS Controls Version 7.1 released

The Center for Internet Security (CIS) has released its new version 7.1 of the top 20 Critical Security Controls. The updated version includes new Implementation Groups designed to identify relevant CIS controls that are reasonable for an organization with a similar risk profile and available cybersecurity resources.

CIS Controls Version 7.1 released Read More »

Xwo botnet scans for exposed web services and default passwords

A newly discovered botnet dubbed Xwo has been scanning the internet for exposed web services and default passwords. The malware was discovered by AT&T’s Alien Labs back in March and is related to malware families MongoLock and Xbash.

Xwo botnet scans for exposed web services and default passwords Read More »