Get a Pentest and security assessment of your IT network.

Cyber Security

Microsoft fixes actively exploited Windows bug reported 2 years ago

As part of the August 2020 Patch Tuesday, Microsoft fixed a vulnerability that allowed MSI files to be converted into malicious Java executables while retaining a legitimate company’s digital signature. The vulnerability is tracked as CVE-2020-1464 and is described by Microsoft as a spoofing vulnerability in how Windows validates signature files. It was later noted in a blog post by security researchers Tal Be’ery, of Zengo, and Peleg Hadar, of SafeBreach Labs, that this update is for a bug reported two years ago that Microsoft originally stated they would not be fixing.

Source: https://www.bleepingcomputer.com/news/security/microsoft-fixes-actively-exploited-windows-bug-reported-2-years-ago/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security