16 Jan

Patch now: Critical VMware, Atlassian flaws found

VMware and Atlassian today disclosed critical vulnerabilities and, while neither appear to have been exploited by miscreants yet, admins should patch now to avoid disappointment.

Author rabih
16 Jan

Double trouble for VMware and Atlassian admins – critical flaws to fix

VMware and Atlassian today disclosed critical vulnerabilities and, while neither appear to have been exploited by miscreants yet, admins should patch now to avoid disappointment.

Author rabih
16 Jan

More than 178,000 SonicWall firewalls are exposed to old denial of service bugs

More than 178,000 SonicWall firewalls are still vulnerable to years-old vulnerabilities, an infosec reseacher claims. A study by Jon Williams, senior security engineer at Bishop

Author rabih
16 Jan

Ivanti zero-day exploits explode as bevy of attackers get in on the act

There’s a “reasonable chance” that Ivanti Connect Secure (ICS) VPN users are already compromised if they didn’t apply the vulnerability mitigation released last week, experts

Author rabih
16 Jan

The 7 deadly cloud security sins and how SMBs can do things better

Business Security By eliminating these mistakes and blind spots, your organization can take massive strides towards optimizing its use of cloud without exposing itself to

Author rabih
16 Jan

China’s gambling crackdown spawned wave of illegal online casinos and crypto-crime in Asia

Global crime networks have set up shop in autonomous territories run by armed gangs across Southeast Asia, and are using them to host physical and

Author rabih
15 Jan

Thousands of Juniper Networks devices vulnerable to critical RCE bug

More than 11,500 Juniper Networks devices are exposed to a new remote code execution (RCE) vulnerability, and infosec researchers are pressing admins to urgently apply

Author rabih
15 Jan

Patch time: Critical GitLab vulnerability exposes 2FA-less users to account takeovers

GitLab admins should apply the latest batch of security patches pronto given the new critical account-bypass vulnerability just disclosed. Tracked as CVE-2023-7028, the maximum-severity bug

Author rabih
15 Jan

FTC secures first databroker settlement banning sale of sensitive location data

Infosec in brief The US Federal Trade Commission has secured its first data broker settlement agreement, prohibiting X-Mode Social from sharing or selling sensitive location

Author rabih
15 Jan

Honoring Martin Luther King Jr.’s Legacy with McAfee’s African Heritage Community

Today, we celebrate the life and legacy of Dr. Martin Luther King Jr. Dr. King diligently dedicated his life to dismantling systemic racism affecting marginalized

Author rabih
15 Jan

Ransomware protection deconstructed

Sponsored Post Rubrik has combed through its archive to find what it judges to be the top 12 must-see demos of its products available to

Author rabih
15 Jan

China loathes AirDrop so much it’s publicized an old flaw in Apple’s P2P protocol

In June 2023 China made a typically bombastic announcement: operators of short-distance ad hoc networks must ensure they run according to proper socialist principles, and

Author rabih
13 Jan

Number of orgs compromised via Ivanti VPN zero-days grows as Mandiant weighs in

Two zero-day bugs in Ivanti products were likely under attack by cyberspies as early as December, according to Mandiant’s threat intel team. The software biz

Author rabih
13 Jan

Why we update… Data-thief malware exploits SmartScreen on unpatched Windows PCs

Criminals are exploiting a Windows Defender SmartScreen bypass vulnerability to infect PCs with Phemedrone Stealer, a malware strain that scans machines for sensitive information –

Author rabih
12 Jan

Exploit for under-siege SharePoint vuln reportedly in hands of ransomware crew

Security experts claim ransomware criminals have got their hands on a functional exploit for a nearly year-old critical Microsoft SharePoint vulnerability that was this week

Author rabih
12 Jan

Secret multimillion-dollar cryptojacker snared by Ukrainian police

The criminal thought to be behind a multimillion-dollar cryptojacking scheme is in custody following a Europol-led investigation. Supported by the National Police of Ukraine, Europol

Author rabih
12 Jan

Secure network operations for hybrid working

Webinar Remote working has rapidly become the norm for many organizations and isn’t ever going away. But it still needs to be secure if it’s

Author rabih
12 Jan

Lessons from SEC’s X account hack – Week in security with Tony Anscombe

Video The cryptocurrency rollercoaster never fails to provide a thrilling ride – this week it was a drama surrounding the hack of SEC’s X account

Author rabih
Load moreLoadingAll items loaded