Microsoft fixes exploited zero-day (CVE-2024-49138)
11
Dec
2024

Microsoft fixes exploited zero-day (CVE-2024-49138)

On December 2024 Patch Tuesday, Microsoft resolved 71 vulnerabilities in a variety of its products, including a zero-day (CVE-2024-49138) that’s…

Telstra fined $3m over Triple Zero outage
11
Dec
2024

Telstra fined $3m over Triple Zero outage – Telco/ISP

Telstra has been fined $3 million for a Triple Zero outage earlier this year that led to 127 calls not…

Windows 11
11
Dec
2024

Windows 11 KB5048667 & KB5048685 cumulative updates released

Microsoft has released the Windows 11 KB5048667 and KB5048685 cumulative updates for versions 24H2 and 23H2 to fix security vulnerabilities and issues. Both…

US sanctions Chinese cybersecurity company for firewall compromise, ransomware attacks
10
Dec
2024

US sanctions Chinese cybersecurity company for firewall compromise, ransomware attacks

The Department of the Treasury is sanctioning Chinese cybersecurity company Sichuan Silence, and one of its employees, Guan Tianfeng, for…

Optus lands CBA's Jesse Arundell for its new AI division
10
Dec
2024

Optus lands CBA’s Jesse Arundell for its new AI division – Software – Telco/ISP

Optus has brought former Commonwealth Bank head of emerging tech Jesse Arundell into its new artificial intelligence unit.  Holding the…

Ivanti
10
Dec
2024

Ivanti warns of maximum severity CSA auth bypass vulnerability

Today, Ivanti warned customers about a new maximum-severity authentication bypass vulnerability in its Cloud Services Appliance (CSA) solution. The security…

Australia Post's new POS beset by technical problems
10
Dec
2024

Australia Post’s new POS beset by technical problems – Cloud – Software

Australia Post’s new point-of-sale platform has been beset by multiple technical troubles, including outages and missing transactions, since its launch…

WordPress
10
Dec
2024

WPForms bug allows Stripe refunds on millions of WordPress sites

A vulnerability in WPForms, a WordPress plugin used in over 6 million websites, could allow subscriber-level users to issue arbitrary…

US sanctions Chinese firm over potentially deadly ransomware attack
10
Dec
2024

US sanctions Chinese firm over potentially deadly ransomware attack – Security

The United States sanctioned a Chinese cyber security company over an ambitious cyberattack that US Treasury officials say could have…

Patch Tuesday
10
Dec
2024

Microsoft December 2024 Patch Tuesday fixes 1 exploited zero-day, 71 flaws

Tag CVE ID CVE Title Severity GitHub CVE-2024-49063 Microsoft/Muzic Remote Code Execution Vulnerability Important Microsoft Defender for Endpoint CVE-2024-49057 Microsoft…

Windows Common Log File System Zero-day
10
Dec
2024

Windows Common Log File System Zero-day (CVE-2024-49138) Exploited in the Wild

A new high-severity security vulnerability, CVE-2024-49138, has been identified as a zero-day in the Windows Common Log File System (CLFS)…

Black Basta Ransomware Uses MS Teams, Email Bombing to Spread Malware
10
Dec
2024

Black Basta Gang Uses MS Teams, Email Bombing to Spread Malware

SUMMARY Black Basta Campaign Resurgence: Rapid7 researchers report a sophisticated social engineering campaign by the Black Basta ransomware group, refining…