Patch Tuesday Updates: Intel Flaws, Chinese Inverters, and Cyber Incident Response
N2K NetworksMay 14, 202533 min371 views
25 connections·40 entities in this video→May Patch Tuesday Vulnerabilities
- 💻 Microsoft addressed 78 vulnerabilities in its May Patch Tuesday, including five actively exploited zero-days across Windows, Office, Azure, and Defender.
- 🚀 One critical zero-day in Azure DevOps Server received a perfect CVSS score of 10.
- ⚠️ SAP patched a second zero-day in its Netweaver servers, which had been exploited in the wild.
- 🔌 Ivanti fixed vulnerabilities in its Endpoint Manager Mobile software that attackers chained for unauthenticated remote code execution.
- 📞 Fortinet patched a critical remote code execution vulnerability in its FortiVoice enterprise phone system, also exploited in the wild.
- 🌐 Juniper, VMware, and Zoom released patches for numerous bugs, including nearly 90 in Juniper's secure analytics platform and a cross-site scripting flaw in VMware Aria Automation.
- 🏭 Industrial control system giants Siemens, Schneider Electric, and Phoenix Contact issued advisories for vulnerabilities in their products.
- 📄 Adobe fixed at least 39 vulnerabilities, with seven critical flaws in Adobe Cold Fusion carrying a CVSS score of 9.1.
Emerging Threats and Investigations
- 🇨🇳 US energy officials are investigating undocumented communication devices found in Chinese-made power inverters, raising concerns about grid security and potential remote disruptions.
- 🧠 A newly discovered Branch Privilege Injection flaw affects Intel CPUs from the 9th generation onward, potentially leaking sensitive kernel data.
- 🇬🇧 A UK retailer, Marks & Spencer, may claim up to £100 million from cyber insurers following a major cyberattack that compromised customer data and disrupted operations.
- 🌐 A Kosovo national was extradited to the US for allegedly running Blackdb.cc, an illegal online marketplace selling stolen account data.
- 📢 CISA reversed its decision to scale back cyber security alerts on its website following industry backlash, opting to maintain its .gov platform for verified alerts.
Cyber Incident Response and CVE Program
- 🤝 Neil Hare-Brown, CEO at STORM Guidance, emphasizes that cyber incident response extends beyond technical aspects to include legal, PR, and trauma counseling.
- 💡 He stresses the importance of proactive preparation, including exercising response plans and separating strategic and operational response groups.
- ☁️ Organizations relying on cloud services or MSPs need to carefully consider the roles and potential conflicts of interest for providers during incident investigations.
- 💰 Retainer services should offer onboarding activities and proactive measures, allowing clients to maximize their investment even if no incident occurs.
- 🏛️ The CVE program faced a near-disruption due to funding issues but received an 11-month contract extension from CISA, prompting discussions about a more resilient, distributed funding model.
Knowledge graph40 entities · 25 connections
How they connect
An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.
Hover · drag to explore
40 entities
Chapters12 moments
Key Moments
Transcript119 segments
Full Transcript
Topics25 themes
What’s Discussed
Patch TuesdayZero-day VulnerabilitiesMicrosoftSAPIvantiFortinetJuniper NetworksVMwareZoomSiemensSchneider ElectricPhoenix ContactAdobeChinese InvertersIntel CPUsBranch Privilege InjectionCyber InsuranceCyberattackIllegal Online MarketplaceCISACyber Incident ResponseCVE ProgramSTORM GuidanceManaged Service Providers (MSPs)Cloud Security
Smart Objects40 · 25 links
Concepts· 11
People· 5
Companies· 12
Location· 1
Products· 10
Media· 1