Microsoft Fixes Fewer Than 100 Bugs for First Time Since February

Microsoft Fixes Fewer Than 100 Bugs for First Time Since February

Microsoft has issued its first patch update for eight months fixing fewer than 100 CVEs, although six are related to publicly disclosed bugs and will need prioritizing.

October’s Patch Tuesday yesterday addressed 87 vulnerabilities including 11 rated critical.

Many experts pointed to CVE-2020-16898, which has a CVSS score of 9.8, as a priority.

“This is a remote code execution vulnerability in Microsoft’s TCP/IP stack. The vulnerability is in the way the Windows TCP/IP stack handles ICMPv6 Router Advertisement packets,” explained Recorded Future senior security architect, Allan Liska.

“For successful exploitation of this vulnerability, all an attacker has to do is send a specially crafted ICMPv6 Router Advertisement packet to a remote Windows computer. This vulnerability impacts Windows 10 and Windows Server 2019 and should be patched immediately.”

Elsewhere, five of the six bugs affect Windows 10 and related server editions: CVE-2020-16908CVE-2020-16909CVE-2020-16901CVE-2020-16885 and CVE-2020-16938. The sixth affects the .Net Framework (CVE-2020-16937).

Todd Schell, senior product manager at Ivanti, also pointed to CVE-2020-16947, a vulnerability in Microsoft Outlook which could allow remote code execution just by viewing a specially crafted email.

“The Preview Pane is an attack vector here, so you don’t even need to open the mail to be impacted,” he added. “The flaw exists within the parsing of HTML content in an email. Patch this one quickly. It will be an attractive target for threat actors.”

Another RCE flaw, this time in Windows Hyper-V, is CVE-2020-16891.

“This patch corrects a bug that allows an attacker to run a specially crafted program on an affected guest OS to execute arbitrary code on the host OS. A guest OS escape like this would also be very attractive to threat actors,” said Schell.

Microsoft also released a preview of its new update guide this month. It’s designed to provide a more intuitive layout so sysadmins can get to the risk-based information they need quicker, including exploited and publicly disclosed vulnerabilities.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Hackers Claim to Have Access to 50,000 Home Security Cameras

Hackers Claim to Have Access to 50,000 Home Security Cameras

A hacking group is selling access to more than 50,000 hacked home security cameras, including footage of children in various states of undress, it has emerged.

The group, which has over 1000 global members, has been using messaging platform Discord to advertise its wares, according to a report on AsiaOne.

It’s reportedly offering access to the camera footage for a one-off subscription fee of $150 and claims to have already shared over 3TB of clips with scores of members. A 700MB sample featuring around 4000 videos and stills is reportedly available for free.

That may account for the fact that some of the clips, lasting from just seconds to over 20 minutes, have ended up on pornographic sites, according to the report.

As well as existing video clips, the group is apparently claiming to have a list of over 50,000 cameras on its files which VIP members can “explore, watch live and even record.”

The clips are said to feature victims in compromising positions, including breastfeeding mothers and even school children. It’s most likely that they are taken from the IP security cameras now commonplace in many smart homes.

It’s claimed that victims come from all over the globe, including Thailand, South Korea, Singapore and Canada.

ESET cybersecurity specialist, Jake Moore, argued that poor access controls are most likely to blame for the hijacked cameras.

“As worrying as it may seem, this comes as a clear reminder that when cameras are placed on the internet, they must be properly installed with security in mind. When smart devices are set up, they are still regularly placed around the home with no second thought for privacy,” he added.

“As we have seen, it can be extremely damaging if such footage gets into the wrong hands. However, this will hopefully act as a deterrent to users to be aware of smart cameras within the home and put in place security measures such as replacing the default passwords and adding multi-factor authentication.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Security Serious Unsung Heroes Awards Winners Announced

Security Serious Unsung Heroes Awards Winners Announced

The winners of the fifth annual Security Serious Unsung Heroes Awards have been announced.

The awards celebrate the people making a difference within the cybersecurity industry. The winners were announced at a virtual ceremony compèred by Brian Higgins, security specialist at Comparitech and Yvonne Eskenzi, co-founder of Eskenzi PR, and supported by sponsors KnowBe4, Protiviti and Qualys. The judging panel for the awards included representatives from InfosecurityISACA, Higgins and Eskenzi.

“It is perhaps more important this year than ever before to honor the cybersecurity professionals who have kept us all up and running during lockdown,” said Yvonne Eskenzi.  “The cyber-skills gap is a huge issue for this country and an event like this really shows off what a great industry it is to be a part of and the wonderful people that make it.”

The winners from all categories were:

Security Leader/Mentor 
Winner: David Chan – entrepreneur in residence at CyLon 

Cyber Writer 
Winner: Davey Winder – freelance tech writer 
Highly Commended: Raef Meeuwisse – author at Cyber Simplicity 

Best Security Awareness Campaign 
Winner: Cygenta for CV-19  

Apprentice/Rising Star 
Winner: Ben Chater – junior security analyst at Pinsent Masons 
Highly Commended: Madeline Howard – Cygenta/Cynam 

Best Educator 
Winner: Toni Scullion – founder of dressCode 

Godparent of Security 
Winner: Pat Ryan – founder of Cyber Girls First 

Best Ethical Hacker / Pen Tester 
Winner: James Mullen – senior security consultant at Edgescan 

Data Guardian 
Winner: Dominic Hartley – DPO at the Department of Works and Pensions 

DevSecOps Trailblazer 
Winner: Didar Gelici – data privacy and cybersecurity risk professional  

Captain Compliance 
Winner: Ian Bernhardt – head of governance and compliance at Sprout IT 

Security Avengers 
Winner: Chani Simms and the SHe CISO Bootcamp Team 

CISO Supremo 
Winner: Emma Leith – CISO at Santander 

COVID Hero
Winner: Lisa Forte – partner of Red Goat Cyber Security

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk