NCSC Releases 2020 Annual Review

This article is contributed. See the original author and article here.

Original release date: December 3, 2020

The United Kingdom (UK) National Cyber Security Centre (NCSC) has released its Annual Review 2020, which focuses on its response to evolving and challenging cyber threats. Recognizing cybersecurity as a “team sport,” the publication includes highlights of NCSC’s collaboration with many partners, including the Cybersecurity and Infrastructure Security Agency (CISA). A few examples:

This product is provided subject to this Notification and this Privacy & Use policy.

Apple Releases Security Updates for iCloud for Windows

This article is contributed. See the original author and article here.

Original release date: December 3, 2020

Apple has released security updates to address vulnerabilities in iCloud for Windows. An attacker could exploit some of these vulnerabilities to take control of an affected system.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Apple security page for iCloud for Windows 11.5 and apply the necessary updates.

This product is provided subject to this Notification and this Privacy & Use policy.

IBM Releases Report on Cyber Actors Targeting the COVID-19 Vaccine Supply Chain

This article is contributed. See the original author and article here.

Original release date: December 3, 2020

IBM X-Force has released a report on malicious cyber actors targeting the COVID-19 cold chain—an integral part of delivering and storing a vaccine at safe temperatures. Impersonating a biomedical company, cyber actors are sending phishing and spearphishing emails to executives and global organizations involved in vaccine storage and transport to harvest account credentials. The emails have been posed as requests for quotations for participation in a vaccine program.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages Operation Warp Speed (OWS) organizations and organizations involved in vaccine storage and transport to review the IBM X-Force report Attackers Are Targeting the COVID-19 Vaccine Cold Chain for more information, including indicators of compromise. For tips on avoiding social engineering and phishing attacks, see CISA Insights: Enhance Email & Web Security.

This product is provided subject to this Notification and this Privacy & Use policy.

Find COVID-19 scam resources (and more) in multiple languages at ftc.gov/languages

This article was originally posted by the FTC. See the original article here.

Searching for in-language information on how to avoid COVID-19 scams and other types of fraud? Check out ftc.gov/languages, the FTC’s one-stop resource for consumer education in Traditional and Simplified Chinese, Korean, Tagalog, Vietnamese, and other languages.

Brought to you by Dr. Ware, Microsoft Office 365 Silver Partner, Charleston SC.

Mozilla Releases Security Update for Thunderbird

This article is contributed. See the original author and article here.

Original release date: December 2, 2020

Mozilla has released a security update to address a vulnerability in Thunderbird. An attacker could exploit this vulnerability to take control of an affected system.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the Mozilla Security Advisory for Thunderbird 78.5.1 and apply the necessary update.

This product is provided subject to this Notification and this Privacy & Use policy.

Xerox Releases Security Updates for DocuShare

This article is contributed. See the original author and article here.

Original release date: December 2, 2020

Xerox has released security updates for DocuShare 6.6.1, 7.0, and 7.5 to address a vulnerability that could allow an unauthenticated attacker to obtain sensitive information.

The Cybersecurity and Infrastructure Security Agency (CISA) urges users and administrators review Xerox Mini Bulletin XRX20W and apply the necessary updates.

This product is provided subject to this Notification and this Privacy & Use policy.