Apple on Thursday released patches for tens of vulnerabilities across its products, including three flaws that are actively exploited in attacks.
Hi, what are you looking for?
Apple on Thursday released patches for tens of vulnerabilities across its products, including three flaws that are actively exploited in attacks.
A Russian-speaking threat actor has been targeting hundreds of industrial enterprises for more than two years, Kaspersky’s security researchers report.
A Chinese threat actor is leveraging DLL side-loading for the execution of malicious code in attacks targeting organizations in Myanmar, Sophos security researchers reveal.
Florida-based private prison operator GEO Group this week revealed that it was recently targeted in a cyberattack that involved ransomware and which may have resulted in the theft of sensitive information.
The United States this week announced that it seized 27 domain names that were employed by Iran’s Islamic Revolutionary Guard Corps (IRGC) to spread disinformation.All of the domains, seizure documents reveal, were violating U.S. sanctions against the government of Iran and the IRGC. Twenty-three of the domains were targeting audiences abroad.
FireEye Mandiant has published detailed information on an Oracle Solaris vulnerability that has been exploited in attacks by a sophisticated threat actor.
Republican Gov. Phil Scott said Wednesday that he has called in the Vermont Army National Guard’s Combined Cyber Response Team to help the University of Vermont Health Network respond to last week’s cyberattack that officials said caused significant network problems affecting six hospitals in Vermont and New York.
A threat actor specializing in business email compromise (BEC) attacks has been observed exploiting a vulnerability to spoof the domains of Rackspace customers as part of its operations.
Organizations have historically always had to make a trade-off between network functionality and security. A line of business wants to do “X”, but the security teams says they can only do “Y”. Business applications that run fine in trials slow down dramatically when run through edge firewalls for inspection. A fairly new strategy, known as security-driven networking, is about to change all of that.
Cisco informed customers on Wednesday that it’s working on a patch for a code execution vulnerability affecting its AnyConnect product. The company says a proof-of-concept (PoC) exploit is available.The Cisco AnyConnect Secure Mobility Client is designed to provide secure VPN access for remote workers.
Details on a vulnerability impacting GitHub Actions were made public this week by Google, following a 104-day disclosure deadline.
Trend Micro has patched several vulnerabilities in its InterScan Messaging Security product, including flaws that could have a serious impact.
California voters have backed an initiative expanding a data privacy law criticized by rights watchdogs as having worrying "loopholes" for firms such as Google and Facebook.
The retrial of a former CIA software engineer charged with leaking secrets to WikiLeaks in an espionage case will begin June 7, a judge said Wednesday.
American toy manufacturing giant Mattel this week revealed that it fell victim to a ransomware attack that impacted some of its operations.
PAS Global, a technology company with deep roots in software solutions for process safety and asset reliability for industrial firms, announced on Wednesday that it has agreed to be acquired by Hexagon AB, a provider of sensor, software, and autonomous solutions based in Sweden.
VMware on Wednesday informed customers that it has released new patches for ESXi after learning that a fix made available last month for a critical vulnerability was incomplete.
Swedish insurance company Folksam on Tuesday revealed that data on 1 million customers was inadvertently shared with third-parties.Headquartered in Stockholm, the firm was established over a hundred years ago and is currently one of the largest insurers in Sweden. In 2001, the company sold the English subsidiary Folksam International.
A researcher at cybersecurity services provider IOActive has identified a privilege escalation vulnerability in Windows that can be exploited by abusing games in the Microsoft Store.
The source code for the KPot information stealer was put up for auction, with the REvil ransomware operators apparently being the sole bidders, threat intelligence provider Cyjax reports.