Latest Updates
Security and municipal technology
Recent developments that may affect networks, public services, critical infrastructure, employees, Microsoft environments, and technology planning.
Microsoft Security
Microsoft releases emergency Windows updates to fix RDS failures
Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates, along with Hyper-V and USB audio problems on some Windows versions. [...]
Read the original article →
Data Breach
Japan's Digital Agency says VPN flaw exposed 246,000 personnel records
Japan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. [...]
Read the original article →
Network Security
Multiple Vulnerabilities in Mikrotik Routers Could Allow for Admin Hijacking
Multiple vulnerabilities have been discovered in MikroTik Routers, the most severe of which could allow for admin hijacking. MikroTik routers are network devices that use the RouterOS operating system to provide advanced routing, firewall, wireless, VPN, bandwidth…
Read the original article →
Security News
Homebrew 7.0.0 gets built-in GUI, better security controls
Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface. [...]
Read the original article →
Security News
Twitch extension with 30K installs exposes users’ OAuth tokens
A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users' Twitch OAuth session tokens to a commercial bot service. [...]
Read the original article →
Microsoft Security
Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. [...]
Read the original article →
Microsoft Security
Hackers target exposed Vite dev servers to steal AWS, Azure secrets
A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments. [...]
Read the original article →
Public Sector Security
A Vulnerability in GitLab Could Allow for Disclosure of Sensitive Data
A vulnerability has been discovered in GitLab, which could allow disclosure of sensitive data. GitLab GitLab is a DevOps platform that provides source code management, CI/CD pipelines, issue tracking, and collaboration tools in a single application for software de…
Read the original article →
AI & Technology
Newsom signs legislation establishing framework for third party AI auditors
The laws create a framework for independent verification organizations that can assess AI systems and models and establish a state registry for AI auditors.
Read the original article →
Government Technology
Indiana taps its director of digital governance to also serve as chief privacy officer
John Stark takes on the role as the state’s privacy lead in addition to his role leading the state’s digital governance efforts.
Read the original article →
Microsoft Security
Protecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH payment fraud. The post Protecting organizations from AI-assisted executive impersonation and invoice fraud ap…
Read the original article →
Public Sector Security
Multiple Vulnerabilities in Ivanti Products Could Allow for Arbitrary Code Execution
Multiple vulnerabilities have been discovered in Ivanti products, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the…
Read the original article →
Government Technology
States confront growing cyber gaps as critical infrastructure threats rise, report finds
The joint report from NASCIO and GDIT highlights unreliable funding sources, fewer resources in smaller jurisdictions and the increased risks in connecting critical infrastructure systems to the internet as major concerns for state chief information officers.
Read the original article →
Microsoft Security
Detect and disrupt AI-themed attacks with Microsoft Defender
See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog.
Read the original article →
Microsoft Security
Threat matrix: Mapping threats across cloud web applications
Microsoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms. The post Threat matrix: Mapping threats across clou…
Read the original article →
AI & Technology
California launches AI assistant to help residents navigate state services
The tool uses Anthropic’s Claude model and will rely on state subject matter experts to help validate responses from verified sources, rather than simply generate conversational answers like many commercial AI chatbots.
Read the original article →
Public Sector Security
A Vulnerability in SAP Extended Passport (EPP) Processing Could Allow for Remote Code Execution
A vulnerability has been discovered in SAP Extended Passport (EPP) Processing that could allow for remote code execution. SAP Extended Passport (EPP) Processing is a core system data structure and tracing mechanism within SAP Kernel code used to track, log, and mo…
Read the original article →
Microsoft Security
Passkey-themed social engineering leads to identity and cloud compromise
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key…
Read the original article →