Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Microsoft Patches Defender Antivirus Zero-day Exploited In The Wild

Microsoft Patches Defender Antivirus Zero-day Exploited In The Wild

Microsoft has addressed a zero-day vulnerability in the Microsoft Defender antivirus, exploited in the wild by threat actors before the patch was released.

Zero-days are vulnerabilities actively exploited in the wild before the vendor issues an official patch or bugs that have publicly available proof-of-concept exploits.

The zero-day patched today by Microsoft is being tracked as CVE-2021-1647 and it is a remote code execution (RCE) found in the Malware Protection Engine component (mpengine.dll).

Proof-of-concept available

Microsoft says that a proof-of-concept exploit for this zero-day is available, although exploitation might not be possible on most systems or the PoC might fail in some situations.

The last Microsoft Malware Protection Engine version affected by this vulnerability is version 1.1.17600.5. The zero-day was addressed in version 1.1.17700.4.

Also Read: Letter of Consent MOM: Getting the Details Right

More details on how to verify the Malware Protection Engine version number are available here. Systems that aren’t affected by this vulnerability should run Microsoft Malware Protection Engine version is 1.1.17700.4 or later.

“Customers should verify that the latest version of the Microsoft Malware Protection Engine and definition updates are being actively downloaded and installed for their Microsoft antimalware products,” Microsoft says.

Defender security update installs automatically

Redmond’s advisory also adds that customers don’t need to take any action to install the CVE-2021-1647 security update as it will install automatically on systems running vulnerable Microsoft Defender versions.

“In response to a constantly changing threat landscape, Microsoft frequently updates malware definitions and the Microsoft Malware Protection Engine,” Microsoft says.

Microsoft Defender keeps both the Malware Protection Engine (the component used for scanning, detection, and cleaning) and malware definitions automatically up to date for both enterprise deployments as well as end-users.

Usually, Microsoft Malware Protection Engine updates are released once a month or when needed to protect against newly discovered threats while malware definitions are updated three times per day.

Even though Microsoft Defender can check for engine and definition updates several times a day, users can also manually check at any time if they want to immediately install the security update.

Also Read: A Look at the Risk Assessment Form Singapore Government Requires

Microsoft has not yet released an official patch for a zero-day privilege escalation vulnerability in the Microsoft PSExec utility. The bug received a free micropatch through the 0patch platform last week.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us