Advertisement
Top

Tag: vulnerabilities


Cloud security, Security

Cisco Secure Application provides business risk insights for cloud native apps

September 13, 2023

Via: Help Net Security

Cisco has unveiled Cisco Secure Application (previously Security Insights for Cloud Native Application Observability) on the Cisco Full-Stack Observability Platform, enabling organizations to bring together application and security teams to securely develop and deploy applications. The latest release of Cisco […]


Threats & Malware, Vulnerabilities

CISA Warning: Nation-State Hackers Exploit Fortinet and Zoho Vulnerabilities

September 8, 2023

Via: The Hacker News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday warned that multiple nation-state actors are exploiting security flaws in Fortinet FortiOS SSL-VPN and Zoho ManageEngine ServiceDesk Plus to gain unauthorized access and establish persistence on compromised systems. “Nation-state advanced […]


Threats & Malware, Vulnerabilities

Coding Tips to Sidestep JavaScript Vulnerabilities

September 7, 2023

Via: Dark Reading

The Internet was all about gray backgrounds and dull text boxes in the ’90s. But JavaScript changed that, allowing us to enjoy dynamic text, interactive websites, and clickable elements without sacrificing performance. JavaScript is one of the most commonly used […]


Threats & Malware, Vulnerabilities

9 Alarming Vulnerabilities Uncovered in SEL’s Power Management Products

September 6, 2023

Via: The Hacker News

Nine security flaws have been disclosed in electric power management products made by Schweitzer Engineering Laboratories (SEL). “The most severe of those nine vulnerabilities would allow a threat actor to facilitate remote code execution (RCE) on an engineering workstation,” Nozomi […]


Cyber-crime, Malware

Cybercriminals Team Up to Upgrade ‘SapphireStealer’ Malware

August 31, 2023

Via: Dark Reading

Cybercriminals are mining the capabilities of an open source infostealer called “SapphireStealer,” developing a legion of variants that are helping to democratize the cybercrime landscape when it comes to carrying out data-theft attacks. Ever since a Russian-language hacker named Roman […]


Network security, Security

Survey Provides Takeaways for Security Pros to Operationalize their Remediation Life Cycle

August 29, 2023

Via: The Hacker News

Ask any security professional and they’ll tell you that remediating risks from various siloed security scanning tools requires a tedious and labor-intensive series of steps focused on deduplication, prioritization, and routing of issues to an appropriate “fixer” somewhere in the […]


Data loss, Threats & Malware

London Police Warned to Stay Vigilant Amid Major Data Breach

August 28, 2023

Via: Dark Reading

Greater London’s Metropolitan Police have been warned that their information — names, ranks, ID numbers, vetting levels, and photos — was stolen by hackers in a breach that affects 47,000 officers and staff. The hackers broke into the IT systems […]


Threats & Malware, Vulnerabilities

5 Early Warning Indicators That Are Key to Protecting National Secrets

August 23, 2023

Via: Dark Reading

The US Department of Defense (DoD) will create an insider threat office to monitor employees following a review into the leak of classified Pentagon intelligence on Discord. A June 30 memo signed by the Secretary of Defense calls for the […]


Threats & Malware, Vulnerabilities

CISA Adds Citrix ShareFile Flaw to KEV Catalog Due to In-the-Wild Attacks

August 17, 2023

Via: The Hacker News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security flaw in Citrix ShareFile storage zones controller to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active in-the-wild exploitation. Tracked as CVE-2023-24489 (CVSS score: 9.8), […]


Network security, Security

Why You Need Continuous Network Monitoring?

August 17, 2023

Via: The Hacker News

Changes in the way we work have had significant implications for cybersecurity, not least in network monitoring. Workers no longer sit safely side-by-side on a corporate network, dev teams constantly spin up and tear down systems, exposing services to the […]


Threats & Malware, Vulnerabilities

16 New CODESYS SDK Flaws Expose OT Environments to Remote Attacks

August 11, 2023

Via: The Hacker News

A set of 16 high-severity security flaws have been disclosed in the CODESYS V3 software development kit (SDK) that could result in remote code execution and denial-of-service under specific conditions, posing risks to operational technology (OT) environments. The flaws, tracked […]


Access control, Security

Encryption Flaws in Popular Chinese Language App Put Users’ Typed Data at Risk

August 10, 2023

Via: The Hacker News

A widely used Chinese language input app for Windows and Android has been found vulnerable to serious security flaws that could allow a malicious interloper to decipher the text typed by users. The findings from the University of Toronto’s Citizen […]


Threats & Malware, Vulnerabilities

Microsoft Releases Patches for 74 New Vulnerabilities in August Update

August 9, 2023

Via: The Hacker News

Microsoft has patched a total of 74 flaws in its software as part of the company’s Patch Tuesday updates for August 2023, down from the voluminous 132 vulnerabilities the company fixed last month. This comprises six Critical and 67 Important […]


Threats & Malware, Virus & Malware

New Yashma Ransomware Variant Targets Multiple English-Speaking Countries

August 8, 2023

Via: The Hacker News

An unknown threat actor is using a variant of the Yashma ransomware to target various entities in English-speaking countries, Bulgaria, China, and Vietnam at least since June 4, 2023. Cisco Talos, in a new write-up, attributed the operation with moderate […]


Application security, Security

Major Cybersecurity Agencies Collaborate to Unveil 2022’s Most Exploited Vulnerabilities

August 4, 2023

Via: The Hacker News

A four-year-old critical security flaw impacting Fortinet FortiOS SSL has emerged as one of the most routinely and frequently exploited vulnerabilities in 2022. “In 2022, malicious cyber actors exploited older software vulnerabilities more frequently than recently disclosed vulnerabilities and targeted […]


Application security, Security

Google, Microsoft Take Refuge in Rust Language’s Better Security

August 4, 2023

Via: Dark Reading

When Fortanix launched in 2016, the company made a decision: It would commit to the one-year-old Rust’s programming language to benefit from its security strengths and performance. Seven years later, Fortanix’s commitment to Rust has proved to be a success. […]


Threats & Malware, Vulnerabilities

Industrial Control Systems Vulnerabilities Soar: Over One-Third Unpatched in 2023

August 2, 2023

Via: The Hacker News

About 34% of security vulnerabilities impacting industrial control systems (ICSs) that were reported in the first half of 2023 have no patch or remediation, registering a significant increase from 13% the previous year. According to data compiled by SynSaber, a […]


Network security, Security

Multiple Flaws Found in Ninja Forms Plugin Leave 800,000 Sites Vulnerable

July 31, 2023

Via: The Hacker News

Multiple security vulnerabilities have been disclosed in the Ninja Forms plugin for WordPress that could be exploited by threat actors to escalate privileges and steal sensitive data. The flaws, tracked as CVE-2023-37979, CVE-2023-38386, and CVE-2023-38393, impact versions 3.6.25 and below, […]


Threats & Malware, Vulnerabilities

GameOver(lay): Two Severe Linux Vulnerabilities Impact 40% of Ubuntu Users

July 27, 2023

Via: The Hacker News

Cybersecurity researchers have disclosed two high-severity security flaws in the Ubuntu kernel that could pave the way for local privilege escalation attacks. Cloud security firm Wiz, in a report shared with The Hacker News, said the easy-to-exploit shortcomings have the […]


Editorial

What Is Data Security? A Comprehensive Guide for Businesses

July 27, 2023

Via: Caitlin Simmons

In an interconnected digital world, data security has become paramount for organizations of all sizes. Did you know that in the first quarter of 2023, more than six million information records were breached and exposed worldwide? This concerning statistic provided […]