Topic: security patch management
-
Philips, GE probe Clop ransomware data theft claims
GE and Philips confirmed investigating Clop ransomware breach claims, with Philips admitting a contained breach of an internal server that posed no risk to customers, while GE only acknowledged assessing the potential issue. The three companies,including Shell,were among 43 new victims targeted v...
Read More » -
Microsoft patches 400+ flaws, including zero-day under attack
Microsoft's August 2026 Patch Tuesday fixes over 400 vulnerabilities, including an actively exploited zero-day (CVE-2026-68820) in Windows AFD.sys linked to North Korean threat actors, plus three other publicly disclosed flaws. Additional critical fixes address remote code execution in Microsoft ...
Read More » -
Laundry Bear exploits Exchange zero-day on email open (CVE-2026-42897)
Russia-linked group Laundry Bear is exploiting CVE-2026-42897, a Microsoft Exchange XSS flaw, to breach government and private networks via emails with no malicious links or attachments, making lures difficult to detect. The attack delivers the OWAReaper backdoor that runs in Outlook Web Access, ...
Read More » -
Estée Lauder data breach linked to Oracle E-Business flaw
Estée Lauder suffered a data breach on August 9, 2025, after a threat actor exploited a vulnerability in its Oracle E-Business Suite HR management system, exposing sensitive personal and financial information including names, Social Security numbers, bank account details, and health records. The ...
Read More » -
Microsoft's Digital Crimes Unit threat to researchers sparks cybersecurity backlash
A security researcher known as Nightmare Eclipse publicly disclosed six major Windows vulnerabilities (RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, MiniPlasma) without prior coordination, claiming retaliation after Microsoft allegedly threatened to ruin their life. Microsoft condemned th...
Read More » -
Microsoft Patch Tuesday Fixes Critical Security Bugs
Microsoft's April 2026 Patch Tuesday addressed a record 165 vulnerabilities, including a critical, actively exploited SharePoint Server spoofing flaw (CVE-2026-32201) that could allow unauthorized data access or alteration. The massive update, the company's second-largest ever, is speculated to b...
Read More » -
Chrome Zero-Day CVE-2026-5281 Exploited, Patch Available
Google has released a critical Chrome update patching 21 vulnerabilities, including a high-severity zero-day flaw (CVE-2026-5281) that is already being actively exploited, the fourth such flaw addressed this year. The exploited vulnerability is a use-after-free bug in the Dawn WebGPU component, w...
Read More » -
Microsoft Warns Admins: Patch Critical Exchange Flaw (CVE-2025-53786)
Microsoft warns of a critical Exchange Server vulnerability (CVE-2025-53786) allowing privilege escalation in hybrid cloud environments due to a shared authentication mechanism. Mitigation steps include installing updates, deploying a dedicated hybrid app, and resetting credentials, with Microsof...
Read More »