Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

A remote code execution (RCE) vulnerability addressed recently in Concrete5 exposed numerous websites to attacks, Edgescan reports.A point and click, open-source content management system, Concrete5 allows users create websites at ease and is used by many high-profile entities worldwide, including BASF, GlobalSign, REC, the U.S. Army, and more.

Google is working on improving the security of Chrome users by alerting them when filling out forms on secure pages that are delivered insecurely.Set to be introduced in Chrome 86, the feature targets the so-called mixed forms (they are found on HTTPS pages that submit over HTTP), which are considered a risk to users’ security and privacy.

Thousands of user accounts for online government services in Canada were recently hacked during cyber attacks, authorities said Saturday.The attacks targeted the GCKey service, used by some 30 federal departments and Canada Revenue Agency accounts, the Treasury Board of Canada Secretariat explained in a press release.

Authorities in Maryland have issued an advisory about an apparent email phishing scam targeting firearms dealers in the state.Maryland State Police said it was issued after the Maryland State Police Licensing Division was notified Tuesday about emails received by at least two firearms dealers.

With $4 million in seed funding, Adaptive Shield this week emerged from stealth mode to automate the security of software-as-a-service (SaaS) applications.The Tel Aviv, Israel-based startup seeks to tackle the issue of incorrect configuration of SaaS applications, which can expose them to cyberattacks, data leaks, and other risks.

Event image poster

The leading global conference series for Operations, Control Systems and IT/OT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

Learn More

Application Security

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Cloud Security

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.