#1 Trending Cybersecurity News & Magazine
Saturday, September 16, 2023
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Anime About Hacking

    Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    John Blackmon

    Leveraging VR to Train Human Firewall: An Exclusive Interview with John Blackmon

    American Steel & Aluminum data breach

    American Steel & Aluminum Co. Faces Data Breach by Akira Ransomware Group

    Greater Manchester Police Cyber Attack

    Greater Manchester Police Cyber Attack Exposes Extent of Data Vulnerability

    Gerchik Trading Ecosystem data breach

    Gerchik Trading Ecosystem Faces Data Breach Risk: What You Need to Know

    MGM Resorts Cyber Attack

    MGM Resorts Cyber Attack: The Assault, Intrusion, and the ‘Unknown User’ Through the Hacker’s Lens

    DBGB Cyber Attack

    Indian Banks Under Attack: Hackers Target Dakshin Bihar Gramin Bank, City Union Bank

    Mom's Meals data breach

    Mom’s Meals Data Breach Sparks Legal Battle as 1.2 Million Affected

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    National Cyber Workforce and Education Strategy

    Everything You Need to Know About the National Cyber Workforce and Education Strategy (NCWES)

    Montclair cyber attack

    Montclair Cyber Attack Kicks Up the Ransom Payment Dilemma

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    Cyble Partner Network

    Cyble Revolutionizes Cybersecurity Collaboration With Launch of Global Partner Program ‘Cyble Partner Network’

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
SUBSCRIBE
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Anime About Hacking

    Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    John Blackmon

    Leveraging VR to Train Human Firewall: An Exclusive Interview with John Blackmon

    American Steel & Aluminum data breach

    American Steel & Aluminum Co. Faces Data Breach by Akira Ransomware Group

    Greater Manchester Police Cyber Attack

    Greater Manchester Police Cyber Attack Exposes Extent of Data Vulnerability

    Gerchik Trading Ecosystem data breach

    Gerchik Trading Ecosystem Faces Data Breach Risk: What You Need to Know

    MGM Resorts Cyber Attack

    MGM Resorts Cyber Attack: The Assault, Intrusion, and the ‘Unknown User’ Through the Hacker’s Lens

    DBGB Cyber Attack

    Indian Banks Under Attack: Hackers Target Dakshin Bihar Gramin Bank, City Union Bank

    Mom's Meals data breach

    Mom’s Meals Data Breach Sparks Legal Battle as 1.2 Million Affected

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    National Cyber Workforce and Education Strategy

    Everything You Need to Know About the National Cyber Workforce and Education Strategy (NCWES)

    Montclair cyber attack

    Montclair Cyber Attack Kicks Up the Ransom Payment Dilemma

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    Cyble Partner Network

    Cyble Revolutionizes Cybersecurity Collaboration With Launch of Global Partner Program ‘Cyble Partner Network’

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

Microsoft Patch Tuesday July 2023: 132 Bugs Including Exploited Vulnerabilities Patched

Microsoft Patch Tuesday vulnerabilities could lead to privilege escalation, information theft, code execution, security bypass, and DoS attacks on unpatched devices.

Vishwa Pandagle by Vishwa Pandagle
July 12, 2023
in Firewall Daily, Vulnerabilities
0
Microsoft Patch Tuesday
600
SHARES
3.3k
VIEWS
Share on LinkedInShare on Twitter

The Microsoft Patch Tuesday for July addressed 132 vulnerabilities as reports of zero-day exploitation surface in the media.

Out of the vulnerabilities addressed in the July Patch Tuesday, six zero-day flaws were found to be exploited in the wild.

You might also like

Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

Ransomed Interview: Operator Speaks About No Mercy and All Gain

Leveraging VR to Train Human Firewall: An Exclusive Interview with John Blackmon

Details about the Microsoft Patch Tuesday for July 2023

Microsoft Patch Tuesday

Nine were critical vulnerabilities, and 122 were marked as important in the July Microsoft Patch Tuesday report.

CVE-2023-32046, CVE-2023-32049, CVE-2023-35311, and CVE-2023-36874 were among the known exploited vulnerabilities in a CISA advisory.

The vulnerabilities addressed in the Microsoft Patch Tuesday for July this year were in Microsoft Office, Components, Windows Layer-2 Bridge Network Driver, Windows Media, Microsoft Power Apps, and Windows Message Queuing among others.

The latest Microsoft Patch Tuesday also had a Defense-in-depth update with ADV230001 and another for the Trend Micro EFI Modules – ADV230002.

Exploitation of vulnerabilities addressed in the Microsoft Patch Tuesday update

Microsoft Patch Tuesday

The exploitation of the named vulnerabilities in the Microsoft Patch Tuesday update could result in the elevation of privilege, information theft, remote code execution, security bypass, and DoS attacks on unpatched devices.

There were 13 security bypass vulnerabilities, 37 remote code execution vulnerabilities, and 33 privilege elevation vulnerabilities addressed in the July Microsoft Patch Tuesday report.

Some of the vulnerabilities named in the Microsoft Patch Tuesday report were –

  1. CVE-2023-21526 in Windows Netlogin with a score of 7.4
  2. CVE-2023-21756 in Microsoft Graphics Component with a score of 7.8
  3. CVE-2023-32033 in Windows Cluster Server with a score of 6.6
  4. CVE-2023-32038 in Windows ODBC Driver with a score of 8.8
  5. CVE-2023-32049 in Windows SmartScreen with a score of 8.8
  6. CVE-2023-32051 in Microsoft Windows Codec Library with a score of 7.8
  7. CVE-2023-32055 in Windows Active Template Library with a score of 6.7
  8. CVE-2023-33134 in Microsoft Office SharePoint with a score of 8.8
  9. CVE-2023-33157 in Microsoft Office SharePoint with a score of 8.8
  10. CVE-2023-35306 in Windows Printer Drivers with a score of 5.5

The exploited vulnerabilities in the wild were addressed by Microsoft in an advisory with helpful information to mitigate risk.

Hackers were using Microsoft-signed drivers with reports stating the drivers were certified by Microsoft Windows hardware developer programs.

Out of the vulnerabilities named in the important category, four were found being exploited in the wild. They were CVE-2023-32046, CVE-2023-32049, CVE-2023-35311 and CVE-2023-36874. Microsoft found similar malicious activities in February 2023.

Cyber Espionage by China-based cybercriminals

Microsoft updated readers about mitigating threat traced to China. The risk has been mitigated by Microsoft which was posed by a group named Storm-0558. They accessed customer emails to engage in cyber espionage.

Their primary targets were government agencies in Western Europe to steal credentials and other data. The hackers were found to gain access to accounts that belonged to nearly 25 organizations on May 15, 2023.

They also targeted consumer accounts that are suspected to be associated with the targeted organizations. “The actor used an acquired MSA key to forge tokens to access OWA and Outlook.com. MSA (consumer) keys and Azure AD (enterprise) keys are issued and managed from separate systems and should only be valid for their respective systems,” the Microsoft blog added.

The hackers are suspected to have conducted the cybercrime using forged authentication tokens for account access.

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Tags: July 2023 patch TuesdayMicrosoft Patch Tuesday JulyMicrosoft VulnerabilityMicrosoft zero-dayThe Cyber ExpressThe Cyber Express News
Previous Post

NoName Hackers Target Lithuanian Media, Hits ‘Alfa’ and ‘Lithuania in a Week’

Next Post

GhostSec and Stormous Forge Alliance, Target Government Ministries in Cuba

Vishwa Pandagle

Vishwa Pandagle

Vishwa Pandagle is a Technical Writer at The Cyber Express. She writes cybersecurity news related to data breaches, ransomware, phishing, and best practices among others. She also writes about cybersecurity developments and likes interacting with experts in this field. When not working, she likes self-reflecting, meditating, volunteering, and going for long walks.

Related Posts

Anime About Hacking
Features

Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

by Ashish Khaitan
September 16, 2023
Ransomed Interview: Operator Speaks About No Mercy and All Gain
Firewall Daily

Ransomed Interview: Operator Speaks About No Mercy and All Gain

by Vishwa Pandagle
September 16, 2023
John Blackmon
Firewall Daily

Leveraging VR to Train Human Firewall: An Exclusive Interview with John Blackmon

by Editorial
September 16, 2023
American Steel & Aluminum data breach
Firewall Daily

American Steel & Aluminum Co. Faces Data Breach by Akira Ransomware Group

by Ashish Khaitan
September 15, 2023
Greater Manchester Police Cyber Attack
Data Breach News

Greater Manchester Police Cyber Attack Exposes Extent of Data Vulnerability

by Ishita Tripathi
September 15, 2023
Next Post
GhostSec and Stormous

GhostSec and Stormous Forge Alliance, Target Government Ministries in Cuba

Latest Issue is Out. Subscribe Now



Follow Us On Google News

Latest Cyber News

Anime About Hacking
Features

Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

September 16, 2023
Ransomed Interview: Operator Speaks About No Mercy and All Gain
Firewall Daily

Ransomed Interview: Operator Speaks About No Mercy and All Gain

September 16, 2023
John Blackmon
Firewall Daily

Leveraging VR to Train Human Firewall: An Exclusive Interview with John Blackmon

September 16, 2023
American Steel & Aluminum data breach
Firewall Daily

American Steel & Aluminum Co. Faces Data Breach by Akira Ransomware Group

September 15, 2023

Categories

Web Stories

Top 10 CISOs to Follow in 2023
Top 10 CISOs to Follow in 2023
Top 10 Ransomware Gangs in 2023
Top 10 Ransomware Gangs in 2023
Top 5 IoT Security Risks in 2023
Top 5 IoT Security Risks in 2023
Top 10 CTF Platforms in 2023
Top 10 CTF Platforms in 2023
Types of Risks Covered by Cyber Insurance
Types of Risks Covered by Cyber Insurance

About

The Cyber Express by Cyble

#1 Trending Cybersecurity News and Magazine

The Cyber Express  by Cyble is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

For Events & Conferences related information: [email protected]

 

Quick Links

  • About Us
  • Advertise With Us
  • Contact Us
  • Editorial Calendar

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News
  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    •  Cyber Security Webinar
    • Endorsed Events
  • Products
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Top 10 CISOs to Follow in 2023 Top 10 Ransomware Gangs in 2023 Top 5 IoT Security Risks in 2023 Top 10 CTF Platforms in 2023 Types of Risks Covered by Cyber Insurance