??This just in - November 20th Cybersecurity Update from our CSO, Adam Winston ?? Check out the video below for insights on what’s come across his desk this week.
?? November 20th Cybersecurity Update ?? Network Security: ? Palo Alto Networks has released a critical update for a flaw in their web management interface, tracked as CVE-2024-0012. This is separate from the vulnerability disclosed in June and emphasizes the importance of securing remote interfaces on firewalls. #PaloAltoNetworks ? CISA has flagged a vulnerability in Progress Software’s Kemp LoadMaster (CVE-2024-1212), reportedly being exploited in the wild. Organizations using LoadMaster should prioritize patching. #ProgressSoftware #KempLoadMaster ?? Cloud Security: ? WordPress has disclosed an authentication bypass vulnerability in the Really Simple Security plugin (CVE-2024-10924), which could allow full administrative access to a site. ? Google announced earlier this month that Multi-Factor Authentication (MFA) will become mandatory for all users by late 2025, aligning with existing MFA requirements from AWS and Microsoft Azure. #WordPress #GoogleCloud #AWS #MicrosoftAzure ?? Endpoint Security: ? Microsoft has released an update addressing a Kerberos remote code execution vulnerability (CVE-2024-43639) affecting millions of servers. Immediate patching is recommended. #Microsoft ? VMware ESX updates address two vulnerabilities: CVE-2024-38812 (remote code execution) and CVE-2024-38813 (privilege escalation). Organizations should ensure their systems are patched promptly. #VMware ?? Mobile Security: ? Apple’s iOS 18.1.1 and macOS 15.1.1 address vulnerabilities in JavaScriptCore (CVE-2024-44308) and WebKit (CVE-2024-44309), which are actively being exploited. Users are encouraged to update immediately. #Apple ? Samsung’s Galaxy S24 November update resolves 52 vulnerabilities in its software, highlighting the importance of maintaining mobile security updates. #Samsung ?? Ensuring systems are up-to-date is critical to mitigating risks. Organizations should monitor vendor advisories and prioritize patches based on active exploit reports. #CyberSecurity #NetworkSecurity #CloudSecurity #EndpointSecurity #MobileSecurity