Talk With an Expert

Internet Storm Center Tech Corner

Microsoft Patch Tuesday December 2024

https://isc.sans.edu/diary/Microsoft+Patch+Tuesday+December+2024/31508

Apple Updates Everything (iOS, iPadOS, macOS, watchOS, tvOS, visionOS)

https://isc.sans.edu/diary/Apple+Updates+Everything+iOS+iPadOS+macOS+watchOS+tvOS+visionOS/31514/

Vulnerability Symbiosis: vSphere's CVE-2024-38812 and CVE-2024-38813

https://isc.sans.edu/diary/Vulnerability+Symbiosis+vSpheres+CVE202438812+and+CVE202438813+Guest+Diary/31510

Windows 11 and TPM

https://techcommunity.microsoft.com/blog/windows-itpro-blog/tpm-2-0-%E2%80%93-a-necessity-for-a-secure-and-future-proof-windows-11/4339066

https://www.forbes.com/sites/zakdoffman/2024/12/12/microsoft-warns-400-million-windows-users-do-not-update-your-pc/

Microsoft Azure MFA Bypass

https://www.oasis.security/resources/blog/oasis-security-research-team-discovers-microsoft-azure-mfa-bypass

Struts 2 Arbitrary File Upload CVE-2024-53677

https://cwiki.apache.org/confluence/display/WW/S2-067

Russian actor Secret Blizzard using tools of other groups to attack Ukraine

https://www.microsoft.com/en-us/security/blog/2024/12/11/frequent-freeloader-part-ii-russian-actor-secret-blizzard-using-tools-of-other-groups-to-attack-ukraine/

Widespread exploitation of Cleo file transfer software (CVE-2024-50623)

https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild

https://labs.watchtowr.com/cleo-cve-2024-50623/

Ivanti Security Advisory

https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Services-Application-CSA-CVE-2024-11639-CVE-2024-11772-CVE-2024-11773?language=en_US

Visual Studio Code Tunnels

https://www.sentinelone.com/labs/operation-digital-eye-chinese-apt-compromises-critical-digital-infrastructure-via-visual-studio-code-tunnels/

Mitigating NTLM Relay Attacks

https://msrc.microsoft.com/blog/2024/12/mitigating-ntlm-relay-attacks-by-default/

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive