24 Jan

Don’t want your Kubernetes Windows nodes hijacked? Patch this hole now

A now-fixed command-injection bug in Kubernetes can be exploited by a remote attacker to gain code execution with SYSTEM privileges on all Windows endpoints in

Author rabih
24 Jan

North Korean dev who renamed himself ‘Bane’ accused of IT worker fraud scheme

The US is indicting yet another five suspects it believes were involved in North Korea’s long-running, fraudulent remote IT worker scheme – including one who

Author rabih
24 Jan

China and friends claim success in push to stamp out tech support cyber-scam slave camps

A group established by six Asian nations to fight criminal cyber-scam slave camps that infest the region claims it’s made good progress dismantling the operations.

Author rabih
24 Jan

Court rules FISA Section 702 surveillance of US resident was unconstitutional

It was revealed this week a court in New York made a landmark ruling that sided against the warrantless state surveillance of people’s private communications

Author rabih
23 Jan

One of Salt Typhoon’s favorite flaws still wide open on 91% of at-risk Exchange Servers

One of the critical security flaws exploited by China’s Salt Typhoon to breach US telecom and government networks has had a patch available for nearly

Author rabih
23 Jan

Patch now: Cisco fixes critical 9.9-rated, make-me-admin bug in Meeting Management

Cisco has pushed a patch for a critical, 9.9-rated vulnerability in its Meeting Management tool that could allow a remote, authenticated attacker with low privileges

Author rabih
23 Jan

Patch now: Cisco fixes critical 9.9-rated, make-me-admin bug

Cisco has pushed a patch for a critical, 9.9-rated vulnerability in its Meeting Management tool that could allow a remote, authenticated attacker with low privileges

Author rabih
23 Jan

SonicWall flags critical bug likely exploited as zero-day, rolls out hotfix

SonicWall is warning customers of a critical vulnerability that was potentially already exploited as a zero-day. The bug affects SonicWall’s Secure Mobile Access (SMA) line,

Author rabih
23 Jan

Meta’s pay-or-consent model under fire from EU consumer group

Meta has again come under fire for its pay-or-consent model in the EU. The complaint has come from the European Consumer Organisation (BEUC), which has

Author rabih
23 Jan

FortiGate config leaks: Victims’ email addresses published online

Thousands of email addresses included in the Belsen Group’s dump of FortiGate configs last week are now available online, revealing which organizations may have been

Author rabih
23 Jan

Who is DDoSing you? Rivals, probably, or cheesed-off users

In addition to Chinese spies invading organizations’ networks and ransomware crews locking up sensitive files, botnets blasting distributed denial of service (DDoS) attacks can still

Author rabih
23 Jan

The evolving landscape of data privacy: Key trends to shape 2025

Business Security Incoming laws, combined with broader developments on the threat landscape, will create further complexity and urgency for security and compliance teams Phil Muncaster

Author rabih
23 Jan

Biz tax rises, inflation and high interest. Why fewer UK tech firms started in 2024

For the first time since the start of the pandemic, the number of tech firms incorporated in the UK has declined, with a shrinking economy,

Author rabih
23 Jan

Asus lets processor security fix slip out early, AMD confirms patch in progress

AMD has confirmed at least some of its microprocessors suffer a microcode-related security vulnerability, the existence of which accidentally emerged this month after a fix

Author rabih
23 Jan

Oracle emits 603 patches, names one it wants you to worry about soon

Oracle has delivered its regular quarterly collection of patches: 603 in total, 318 for its own products, and another 285 for Linux code it ships.

Author rabih
22 Jan

Trump ‘waved a white flag to Chinese hackers’ as Homeland Security axed cyber advisory boards

The Trump administration gutted key cybersecurity advisory boards in its first days, as expert witnesses warned Congress about the dire risks of cyberattacks by China.

Author rabih
22 Jan

Trump ‘waved a white flag to Chinese hackers’ as DHS axed cyber advisory boards

The Trump Administration gutted key cyber advisory boards in its first days, as expert witnesses warned Congress about dire risks posed by cyberattacks rooted in

Author rabih
22 Jan

Supply chain attack hits Chrome extensions, could expose millions

Cybersecurity outfit Sekoia is warning Chrome users of a supply chain attack targeting browser extension developers that has potentially impacted hundreds of thousands of individuals

Author rabih
Load moreLoadingAll items loaded