Patch Tuesday: Microsoft’s January 2025 Security Update Patches Exploited Elevation of Privilege Attacks

Patch Tuesday: Microsoft’s January 2025 Security Update Patches Exploited Elevation of Privilege Attacks

Microsoft’s latest batch of security patches includes an expanded blacklist for certain Windows Kernel Vulnerable Drivers and fixes for several elevations of privilege vulnerabilities. The January 2025 Security Update addressed 159 vulnerabilities. Security patches should be applied to keep software up-to-date. However, early versions of patches may be unreliable and should be cautiously approached and deployed in test environments first. 1 Pipedrive CRM Employees per Company Size Micro (0-49), Small (50-249), Medium (250-999), Large (1,000-4,999),…

Read More

What Is Patch Tuesday? Microsoft's Monthly Update Explained

What Is Patch Tuesday? Microsoft's Monthly Update Explained

On the second Tuesday of each month, Microsoft and other tech companies release patches for consumer and enterprise users. These updates, including bug fixes and security enhancements from the previous month, are known as “Patch Tuesday.” The monthly update is an important opportunity to ensure that security features and applications are up to date. Microsoft details the official Patch Tuesday release in their Security Update Guide. Below, TechRepublic explores its purpose, how it works, and…

Read More

Windows 11 Media Update Bug Stops Security Updates

Windows 11 Media Update Bug Stops Security Updates

Admins, take caution if you use physical media to install Windows security updates, Microsoft warned on Dec. 24. Installing the October or November 2024 updates for Windows 11, version 24H2 using a CD or a USB flash drive could prevent the operating system from accepting future security updates. How to prevent Windows 11 version 24H2 from locking up security updates The problem with the October or November 2024 update for Windows 11, version 24H2 only…

Read More

Google Launches Gemini 2.0 with Autonomous Tool Linking

Google Launches Gemini 2.0 with Autonomous Tool Linking

Google is embracing “agentic experiences” in the rollout of Gemini 2.0, its new flagship family of generative AI expected to compete with ChatGPT with OpenAI o1, GitHub Copilot, and Amazon Nova. The tech giant released the first model, Gemini 2.0 Flash, on Dec. 11 for global developers through the Gemini API in Google AI Studio and Vertex AI. Consumers can expect Gemini 2.0 to impact Google Search and AI Overviews, with limited testing beginning next…

Read More

Patch Tuesday: Microsoft Patches One Actively Exploited Vulnerability, Among Others

Patch Tuesday: Microsoft Patches One Actively Exploited Vulnerability, Among Others

December brought a relatively mild Patch Tuesday, with one vulnerability having been actively exploited. Of all 70 vulnerabilities fixed, 16 were classified as critical. “This year, cybersecurity professionals must be on Santa’s nice list, or, at the very least, Microsoft’s,” Tyler Reguly, associate director of security R&D at cybersecurity software and services company Fortra, told TechRepublic in an email. Microsoft patches leaky CLFS CVE-2024-49138 is an elevation of privilege vulnerability in the Windows Common Log…

Read More

Dell Unveils AI and Cybersecurity Solutions at Microsoft Ignite 2024

Dell Unveils AI and Cybersecurity Solutions at Microsoft Ignite 2024

Dell pulled the tarp off several new connected services during Microsoft Ignite, an annual conference hosted by Microsoft that is designed for developers and IT professionals. Several services are intended to take guesswork or security concerns from deploying generative AI, particularly on Microsoft’s Copilot+ PCs. Dell takes on the management of APEX File Storage for Azure APEX File Storage has been available for Azure for some time. However, starting with a public preview in the…

Read More

Microsoft Ignite 2024: AI, Security, and Teams Innovations

Microsoft Ignite 2024: AI, Security, and Teams Innovations

Microsoft Ignite 2024, held Nov. 19 – 22 in Chicago, featured nearly 100 announcements and software updates, including an AI feature in Teams that can translate speech and replicate an individual employee’s voice. This year’s overarching theme was expanding generative AI’s summarization and rewriting capabilities to address more niche use cases. AI translator agent can replicate your voice in Teams Microsoft is going all-in on AI “agents” in an effort to further abstract the workings…

Read More

1.1 Million UK NHS Employee Records Exposed

1.1 Million UK NHS Employee Records Exposed

Over a million NHS employee records — including email addresses, phone numbers, and home addresses — were exposed online due to a misconfiguration of the low-code website builder Microsoft Power Pages. In September, researchers with the software-as-a-service security platform AppOmni identified a large shared business service provider for the NHS that was allowing unauthorised access to sensitive data through insecure permission settings on Power Pages. Specifically, the permissions on some tables and columns in Power…

Read More

Patch Tuesday: Four Critical Vulnerabilities Paved Over

Patch Tuesday: Four Critical Vulnerabilities Paved Over

On Patch Tuesday, Windows systems will be updated with a flood of security fixes. In November, Windows patched four zero-day vulnerabilities, two of which have been exploited. Patch Tuesdays are a good time for admin teams to remind employees of the importance of keeping operating systems and applications up to date. In the meantime, software makers like Microsoft and Adobe will have caught problems and closed backdoors. In addition, as XDA pointed out, sharp-eyed Windows…

Read More

AI-Assisted Attacks Top Cyber Threat For Third Consecutive Quarter, Gartner Finds

AI-Assisted Attacks Top Cyber Threat For Third Consecutive Quarter, Gartner Finds

For the third consecutive quarter, Gartner has found that cyber attacks staged using artificial intelligence are the biggest risk for enterprises. The consulting firm surveyed 286 senior risk and assurance executives from July through September, and 80% cited AI-enhanced malicious attacks as the top threat they were concerned about. This isn’t surprising, as evidence suggests AI-assisted attacks are on the rise. Other commonly cited emerging risks outlined in the report include AI-assisted misinformation, escalating political…

Read More
1 2 3 7