Previous All Posts Next

Windows Update Patches Critical Spyware Vulnerability

Posted: September 14, 2017 to Technology.

Tags: Malware, Data Breach, AI

Microsoft recently released a bunch of patches to shore up security on 81 vulnerabilities, nearly half of which would allow hackers to execute commands on your computer. The patch fixes a wide variety of issues. The biggest one is a zero day exploit that has been actively used already. It allows a hacker to install programs, create users, and manipulate files. Even scarier, it allows hackers to access and record from a webcam, log keystrokes, and intercept Skype calls. This exploit is usually the result of a phishing campaign. There are three other publically-disclosed vulnerabilities this patch takes care of. The problems it fixes include redirecting people to fake websites and injecting malicious code. Further, it fixes a recently-discovered vulnerability in Bluetooth devices called BlueBorne, which lets hackers take control of Bluetooth devices and spread malware. Then there are fixes such as a DDoS flaw, memory corruption issues and other hackable vulnerabilities. The patch fixes problems in a number of products, including the Windows OS, web browsers, MS Office, Exchange, Adobe Flash and others. Given how many huge vulnerabilities are fixed in this patch, including a number that are already being exploited, you should make sure to update your Windows systems as soon as possible by going to Settings > Update & Security > Windows Update > Check for Updates. Go ahead and do it now.
Need help implementing these strategies? Our cybersecurity experts can assess your environment and build a tailored plan.
Get Free Assessment

About the Author

Craig Petronella, CEO and Founder of Petronella Technology Group
CEO, Founder & AI Architect, Petronella Technology Group

Craig Petronella founded Petronella Technology Group in 2002 and has spent 20+ years professionally at the intersection of cybersecurity, AI, compliance, and digital forensics. He holds the CMMC Registered Practitioner credential issued by the Cyber AB and leads Petronella as a CMMC-AB Registered Provider Organization (RPO #1449). Craig is an NC Licensed Digital Forensics Examiner (License #604180-DFE) and completed MIT Professional Education programs in AI, Blockchain, and Cybersecurity. He also holds CompTIA Security+, CCNA, and Hyperledger certifications.

He is an Amazon #1 Best-Selling Author of 15+ books on cybersecurity and compliance, host of the Encrypted Ambition podcast (95+ episodes on Apple Podcasts, Spotify, and Amazon), and a cybersecurity keynote speaker with 200+ engagements at conferences, law firms, and corporate boardrooms. Craig serves as Contributing Editor for Cybersecurity at NC Triangle Attorney at Law Magazine and is a guest lecturer at NCCU School of Law. He has served as a digital forensics expert witness in federal and state court cases involving cybercrime, cryptocurrency fraud, SIM-swap attacks, and data breaches.

Under his leadership, Petronella Technology Group has served hundreds of regulated SMB clients across NC and the southeast since 2002, earned a BBB A+ rating every year since 2003, and been featured as a cybersecurity authority on CBS, ABC, NBC, FOX, and WRAL. The company leverages SOC 2 Type II certified platforms and specializes in AI implementation, managed cybersecurity, CMMC/HIPAA/SOC 2 compliance, and digital forensics for businesses across the United States.

CMMC-RP NC Licensed DFE MIT Certified CompTIA Security+ Expert Witness 15+ Books
Related Service
Enterprise IT Solutions & AI Integration

From AI implementation to cloud infrastructure, Petronella Technology Group helps businesses deploy technology securely and at scale.

Explore AI & IT Services
Previous All Posts Next
Free cybersecurity consultation available Schedule Now